Password Synchronization Agent Disabling and Uninstallation for Identity Manager
search cancel

Password Synchronization Agent Disabling and Uninstallation for Identity Manager

book

Article ID: 144277

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal CA Identity Suite

Issue/Introduction

The Password Synchronization Agent (PSYNC) is used to synchronize password changes from Active Directory to Identity Manager. In environments where this functionality is no longer required or was installed by default, the agent can be safely disabled or removed without affecting password tasks initiated from within Identity Manager.

Symptoms

  • Requirement to remove unused PSYNC agents from Domain Controllers.
  • Need to bypass synchronization during maintenance windows.

Environment

Identity Manager 14.x

Cause

The PSYNC agent is often installed during initial setup but may become redundant if bi-directional synchronization is not utilized or if security policies change.

Resolution

Part 1: Disable the Agent

Disabling the agent allows you to bypass synchronization without performing a full uninstallation. A reboot of the domain controller is typically required for the change to take full effect.

  1. Locate the configuration file: eta_pwdsync.conf.
  2. Open the file in a text editor.
  3. Set the agent status to Disabled.
  4. Save the file and exit.

Part 2: Uninstall the Agent

If the agent is no longer needed, use the standard Windows removal process.

  1. Open Windows Add/Remove Programs (or Programs and Features).
  2. Locate the entry containing PSYNC.
  3. Select Uninstall and follow the on-screen prompts.
  4. Reboot the Domain Controller to complete the removal.