Active Directory password synchronization fails from CA Identity Manager
search cancel

Active Directory password synchronization fails from CA Identity Manager

book

Article ID: 195567

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal CA Identity Suite

Issue/Introduction

Active Directory (AD) password management through CA Identity Manager (IM) does not reflect changes as expected. For example, accounts remain active in AD even after three successive incorrect password attempts trigger a lockout in IM, or password expirations do not sync.

Symptoms

  • User accounts show as disabled or locked in CA Identity Manager.
  • Status changes are not reflected on the Active Directory endpoint.
  • Users can still log into physical workstations using AD credentials despite IM account locks.

Environment

  • Release: 14.x, 15.x
  • Component: CA IDENTITY SUITE (VIRTUAL APPLIANCE)

Cause

Password Services tasks in Identity Manager are categorized as "audited" tasks rather than executed tasks. Changes occur only within the Identity Manager user store. This design prevents users who fail an IM login attempt from being locked out of all endpoints simultaneously, such as their physical workstation or Active Directory domain.

Resolution

To ensure consistent password management across environments, implement the following steps:

  1. Synchronize password policies between CA Identity Manager and Active Directory.
  2. Schedule daily Explore and Correlate (E&C) tasks to keep IM in sync with AD, treating Active Directory as the authoritative source.
  3. Utilize the Password Sync Agent (PSA) for real-time synchronization.

Additional Information

  • Subscribe to this article for updates regarding fix status: .
  • For further assistance, see .