ADSelfService Plus' Password Sync Agent, when installed on the domain controllers in your domain, intercepts native password changes via the Ctrl+Alt+Del screen and password reset by admins in the ADUC console, encrypts the new passwords, and automatically synchronizes them with multiple systems and applications.
Below are the steps to enforce a custom password policy via ADSelfService Plus to ensure users use strong passwords.
Install the password sync agent (Location: <installation_folder>\bin\ ) using the command prompt with admin credentials. Click Next.
Select the Protocol (HTTP or HTTPS) used in ADSelfService Plus.
Enter the IP address and Port Number of the server on which ADSelfService Plus is installed, then click Next.
Once the installation is complete, you must restart the domain controller for the Password Sync Agent to start working.
Note: By default, the password sync agent will be installed in the following location:
In 64-bit systems - C:\Program Files (x86)\ZOHO Corp\Password Sync Agent
In 32-bit systems - C:\Program Files\ZOHO Corp\Password Sync Agent
Enter the Server Name/IP Address, Port Number, and the Protocol (HTTPS/HTTP) used by ADSelfService Plus.
Click Save.
The new details will now be updated in Password Sync Agent.
To upgrade the password sync agent to a newer version or to reinstall the agent on an existing machine, follow the steps listed below:
Uninstall the password sync agent from the control panel.
Install the password sync agent from the new MSI.
Enable Enforce Custom Password Policy.
In this section, you can manage:
Characters: Restrict the number of special characters, numbers, and Unicode characters used in passwords.
Repetition: Enforce a password history check during password reset, and restrict the consecutive repetition of a specific character from the username (e.g. “aaaaa” or “user01”).
Patterns: Restrict keyboard sequences, dictionary words, and palindromes.
Length: Specify the minimum and maximum password length.
You can also enable users to bypass complexity requirements when the password length exceeds a predefined limit.
Enter the number of policy settings the users' password must comply with during self-service password reset and password change operations.
Enforce the configured password policy settings during password resets from the ADUC console and the change password screen.
To help users create passwords that comply with the enforced policy settings, you can display the password policy requirement on the reset and change password pages.