When Identity Governance security is enabled, users may still be able to authenticate in the Identity Portal using any password, appearing as though password enforcement is inactive. This behavior is expected when the application operates in trial or demonstration mode without an integrated external authentication source.
Identity Governance
Identity Governance is designed to operate with reduced security enforcement in trial or demo environments when no external authentication source (e.g., AD, LDAP, or Identity Manager) is configured. Consequently, the portal does not verify password contents. In production environments, full enforcement requires an active external authentication source to manage user credentials.
To enforce password validation for all users, you must configure an external authentication source. Follow these steps to ensure secure authentication:
Configure External Authentication: Ensure one of the following external authentication sources is configured for your environment:
Enable IM Authentication Flag: To explicitly trigger password verification for AD/EAdmin and SSO users, modify the configuration settings:
false: sage.security.disable.IMAuthentication=falseVerify Configuration:
eurekify.log to confirm the status of the security enforcement.