Configuring Password Sync Agent to Disallow Active Directory Changes - Identity Manager
search cancel

Configuring Password Sync Agent to Disallow Active Directory Changes - Identity Manager

book

Article ID: 33550

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

This guide provides the steps to modify the Password Sync Agent configuration. By adjusting these settings, you can prevent users from updating their Active Directory passwords when the Identity Manager Provisioning Server is unreachable.

This configuration enhances security and ensures synchronization consistency within your environment.

Environment

Identity Manager 14.x

Resolution

  1. Navigate to the Password Sync Agent installation directory on the host system. The default path is: C:\Program Files\CA\eTrust Admin Password Sync Agent\data
  2. Open the eta_pwdsync.conf file using a standard text editor, such as Notepad.
  3. Locate the out_of_sync variable in the file.
  4. Modify the setting to no. The resulting line should appear as follows: out_of_sync=no
  5. Save the configuration file and repeat this procedure for every Domain Controller in your network to ensure consistent enforcement.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.