Documentation Link: Active Directory authentication module - password reset unexpectedly
search cancel

Documentation Link: Active Directory authentication module - password reset unexpectedly

book

Article ID: 229206

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

The Active Directory (AD) authentication module propagates password resets to both the Identity Manager User Store and the Active Directory server when a password reset is performed on a user, even if the user is not correlated to AD. This occurs if the login matches an AD account.

Environment

Release : 14.x, 15.x

Component : Identity Manager

Cause

The AD authentication module relies on users having an account in AD for authentication. When the Active Directory authentication model is configured, user password sets from the "Forgotten Password" or "Reset Password" tasks automatically propagate to both the Identity Manager User Store and the Active Directory server. Password status changes are detected during authentication.

Identity Manager searches for the username entered on the login screen in the Identity Manager User Console by the attribute defined in the Management Console. The authentication attempt is performed directly against Active Directory without attempting to verify account association in the Provisioning layer. Consequently, the password change occurs directly at the account level.

 

Resolution

 If this behavior is not desired, configure the DisableADPasswordPropagation property to prevent Identity Manager from propagating password changes to the Active Directory directory, ensuring only password validation occurs.

Note: This is a global property that applies to all users.

  1. Navigate to Environments > Advanced Settings > Miscellaneous.
  2. Enter the property name DisableADPasswordPropagation in the Property field.
  3. Set the value to true in the Value field.
  4. Click Add to save the configuration.

Additional Information

For further details on managing authentication module properties, see the Identity Manager 15.x Documentation.

To speak with a customer representative or a Support Engineer, see Contact Support. Scroll to the bottom of the page and click on your respective reg