When integrating SiteMinder (SM) and Identity Manager (IM), password policy failures may occur if the environment uses separate directories for authentication and authorization.
This document explains why password services may fail to apply correctly and provides remediation options.
Identity Manager 14.x
Identity Manager defines and manages password policies for users located in its configured corporate store (the authorization directory). However, SiteMinder can be configured to authenticate users against a different directory.
Because IM processes password policy checks prior to authentication, it attempts to verify password reset status and policy validity against the authorization store. Since the actual user credentials reside in the separate SiteMinder authentication store—which is unknown to Identity Manager— the policies cannot be verified or applied correctly.
To resolve password policy failures in a split-directory configuration, choose one of the following methods: