Active Directory (AD) password management through CA Identity Manager (IM) does not reflect changes as expected. For example, accounts remain active in AD even after three successive incorrect password attempts trigger a lockout in IM, or password expirations do not sync.
Password Services tasks in Identity Manager are categorized as "audited" tasks rather than executed tasks. Changes occur only within the Identity Manager user store. This design prevents users who fail an IM login attempt from being locked out of all endpoints simultaneously, such as their physical workstation or Active Directory domain.
To ensure consistent password management across environments, implement the following steps: