Endpoint Account Password Propagation Behavior in Identity Manager
search cancel

Endpoint Account Password Propagation Behavior in Identity Manager

book

Article ID: 44571

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal CA Identity Suite

Issue/Introduction

This article explains how endpoint account passwords are updated when a global user password change occurs in Identity Manager. It clarifies the role of account templates and the interaction with strong/weak synchronization settings.

Environment

Identity Manager

Cause

This is the default architectural behavior of Identity Manager for password propagation. The propagation logic functions independently of account templates or synchronization types.

Resolution

When a provisioning global user password change occurs, the new password propagates to associated endpoint accounts based on the following conditions:

  • Synchronization: Propagation occurs assuming the user chooses to sync with accounts and the endpoint does not have password propagation disabled.
  • Account Templates: The %P% rule string in an Account Template is utilized only during initial account creation and does not affect ongoing password propagation.
  • Independence: Password propagation occurs regardless of whether "strong" or "weak" synchronization is enabled, and even if no account template is applied to the user.
  • Default Fields: The "Password" and "Status" fields are automatically propagated, even in the absence of an account template.