AD Attributes

Active Directory Attributes » Active Directory password attribute: ms-PKI-Credential-Roaming-Tokens

Active Directory password attribute: ms-PKI-Credential-Roaming-Tokens

This attribute stores the encrypted user credential token BLOBs for roaming.

CN ms-PKI-Credential-Roaming-Tokens
Ldap-Display-Name ms-PKI-Credential-Roaming-Tokens
Attribute-Id 1.2.840.113556.1.4.2050
System-Id-Guid b7ff5a38-0818-42b0-8110-d3d154c97f24

For more details about this attribute, refer to this Microsoft document.

Do you have roaming users in your organization? If you receive a lot of password-related help desk calls from remote users, try ADSelfService Plus for free and enable self-service password reset for them. Some of the highlights of ADSelfService Plus include:

  1. Self-service password reset for remote users: Allows remote users to reset their passwords on their own right from the login screen of their Windows, Linux, and Mac clients, and automatically updates the cached credentials as well.
  2. Multi-factor authentication (MFA) for remote desktop logons: Adds an extra layer of security by enabling MFA through YubiKey, biometric, Google Authenticator, etc., for local and remote desktop logons.

Simplify password management with ADSelfService Plus.

Self-service password management and single sign-on solution

ManageEngine ADSelfService Plus is an integrated self-service password management and single sign-on solution for Active Directory and cloud apps. Ensure endpoint security with stringent authentication controls including biometrics and advanced password policy controls.