Enforce Password History During Password Reset
By design, Active Directory does not permit password history check during password reset. However, you can enforce password history settings for password reset in ADSelfService Plus. You can enable this option and prevent users from abusing the password reset option to reuse their old password.
This is how it works:
- After successful identity verification, ADSelfService Plus resets the user password using a randomly generated temporary password.
- ADSelfService Plus now attempts to change the temporary password (old password) of the user account using the user provided password (new password).
- Active Directory performs the password history check for the user provided password since it is a change password operation.
Note: To make this feature work, you need disable the user cannot change password option in Active Directory.
Here's how you can enable this feature in ADSelfService Plus:
- Navigate to Configuration → Self-Service → Password Policy Enforcer.
- Select an appropriate policy from the drop-down list.
: To create or edit a policy, navigate to the Configuration tab → Self-Service → Policy Configuration
. You can either create a new self-service policy by clicking the +Add New Policy button
, or edit the existing default policy. For detailed steps, click here
- Check the Enforce Custom Password Policy checkbox.
- Click Restrict Repetition.
- Check the Number of old passwords to be restricted during password reset checkbox and select a number. ADSelfService Plus provides a range of one to 24 passwords.
- Click Save.
Need further assistance? Fill this form, and we'll contact you rightaway.
Free Active Directory users from attending lengthy help desk calls by allowing them to self-service their password resets/ account unlock tasks. Hassle-free password change for Active Directory users with ADSelfService Plus ‘Change Password’ console.
Get seamless one-click access to 100+ cloud applications. With enterprise single sign-on, users can access all their cloud applications with their Active Directory credentials. Thanks to ADSelfService Plus!
Intimate Active Directory users of their impending password/account expiry by mailing them these password/account expiry notifications.
Synchronize Windows Active Directory user password/account changes across multiple systems, automatically, including Office 365, G Suite, IBM iSeries and more.
Ensure strong user passwords that resist various hacking threats with ADSelfService Plus by enforcing Active Directory users to adhere to compliant passwords via displaying password complexity requirements.
Portal that lets Active Directory users update their latest information and a quick search facility to scout for information about peers by using search keys, like contact number, of the personality being searched.