AD Attributes

Active Directory Attributes » Active Directory password attribute: ms-DS-Password-Complexity-Enabled

Active Directory password attribute: ms-DS-Password-Complexity-Enabled

This attribute shows whether the password complexity setting is enabled or not. The Password must meet complexity requirements security policy setting checks whether the password:

  • Does not contain a user’s sAMAccountName or displayName.
  • Is at least 6 characters in length.
  • Contains characters from three of the following five categories:
    • Uppercase letters (A-Z)
    • Lowercase letters (a-z)
    • Base 10 digits (0-9)
    • Special characters (~!@#$%^&*_-+=`|\(){}[]:;"'<>,.?/)
CN ms-DS-Password-Complexity-Enabled
Ldap-Display-Name msDS-PasswordComplexityEnabled
Attribute-Id 1.2.840.113556.1.4.2015
System-Id-Guid db68054b-c9c3-4bf0-b15b-0fb52552a610

For more details about this attribute, refer to this Microsoft document.

Did you know that the default Active Directory password policy hasn’t changed much since it was introduced in the early 2000s? Users can easily workaround the complexity rules and create passwords that can be easily exploited by attackers.

ADSelfService Plus, an integrated Active Directory self-service password management and single sign-on solution, helps implement strong password complexity rules and multi-factor authentication (MFA) for endpoints, thus ensuring improved security against common credential-based attacks. Some of the highlights of ADSelfService Plus include:

  1. Custom password policy enforcer: Prevent users from setting weak and breached passwords for their accounts through an advanced password policy that bans dictionary words, keyboard sequence and supports Have I Been Pwned? Integration.
  2. OU and group-based password policies: Create multiple password policies based on users’ privileges and assign them based on OUs and groups.
  3. Endpoint MFA: Add an extra layer of security to user accounts by enabling YubiKey, biometric, Google Authenticator, and other strong authentication methods for local and remote desktop logons to Windows, Linux, and Mac endpoints.
  4. Self-service password management: Allow users to reset passwords and unlock accounts on their own; reduces help desk tickets and improves employee productivity.

Simplify password management with ADSelfService Plus.

Self-service password management and single sign-on solution

ManageEngine ADSelfService Plus is an integrated self-service password management and single sign-on solution for Active Directory and cloud apps. Ensure endpoint security with stringent authentication controls including biometrics and advanced password policy controls.