When integrating Identity Manager with a third-party Identity Provider (IdP) for authentication, you may notice that Identity Manager password policies do not trigger for expired credentials.
This article clarifies the expected behavior and management responsibility for password policies in such integrated environments.
Identity Manager 14.5
When an Identity Provider (IdP) is configured for user authentication, the credential management (including validation, password expiration, and reset workflows) is delegated to the IdP. Identity Manager no longer maintains control over the authentication lifecycle, meaning it cannot force password changes or redirect expired accounts as it would under native Identity Manager authentication.
In an integrated IdP environment, Identity Manager is not responsible for password policy enforcement. The expected behavior is as follows:
To speak with a customer representative or a Support Engineer see . Scroll to the bottom of the page and click on your respective region.