Password policy enforcement when using 3rd party authentication in Identity Manager
search cancel

Password policy enforcement when using 3rd party authentication in Identity Manager

book

Article ID: 231704

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

When integrating Identity Manager with a third-party Identity Provider (IdP) for authentication, you may notice that Identity Manager password policies do not trigger for expired credentials.

This article clarifies the expected behavior and management responsibility for password policies in such integrated environments.

Environment

Identity Manager 14.5

Cause

When an Identity Provider (IdP) is configured for user authentication, the credential management (including validation, password expiration, and reset workflows) is delegated to the IdP. Identity Manager no longer maintains control over the authentication lifecycle, meaning it cannot force password changes or redirect expired accounts as it would under native Identity Manager authentication.

Resolution

In an integrated IdP environment, Identity Manager is not responsible for password policy enforcement. The expected behavior is as follows:

  1. Delegation of Authority: The Identity Provider (IdP) must maintain the credentials, handle password validation, and manage password reset conditions.
  2. Configuration: Configure all password expiry notifications, password complexity requirements, and account lock-out policies directly within the IdP management console.
  3. Troubleshooting: If password policies are not triggering, verify the configuration settings within your specific IdP (e.g., Okta, PingFederate, Azure AD) rather than within the Identity Manager User Store settings.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.