ADSelfService Plus' Password Policy Enforcer enables admins to utilize advanced password policy controls like banning weak passwords and keyboard sequences for users' on-premises AD accounts and cloud accounts, including Microsoft 365 and Google Workspace. Moreover, admins can enforce different sets of password policy controls for different users based on their OU and group membership.
What is the Password Sync Agent?
ADSelfService Plus' Password Sync Agent, when installed on the domain controllers in your domain, tracks native password changes via the Ctrl+Alt+Del screen and password resets by admins in the ADUC console, encrypts the new passwords, and automatically synchronizes them with multiple systems and applications.
This document outlines the steps to enforce a custom password policy via ADSelfService Plus for password changes made through the Ctrl+Alt+Del screen and the ADUC console, ensuring the creation of strong passwords.
Configuring the Password Sync Agent
Install the Password Sync Agent (location: <installation_folder>\bin\) using the Command Prompt with admin credentials. In the installation wizard that appears, click Next.
Select the Protocol (HTTP or HTTPS) used in ADSelfService Plus.
Fig. 1: ADSelfService Plus Password Sync Agent installation wizard
Enter the IP address and port number of the server on which ADSelfService Plus is installed, then click Next.
In the Access key field, paste the access key provided in the ADSelfService Plus portal. You can obtain the access key from Configuration > Administrative tools > GINA/Mac/Linux (Ctrl+Alt+Del) > Password Sync Agent Installation. Click Next.
Fig. 2: Entering configuration details in the ADSelfService Plus Password Sync Agent wizard
Once the installation is complete, you must restart the domain controller for the Password Sync Agent to start working.

Note: By default, the password sync agent will be installed in the following location:
In 64-bit systems: C:\Program Files (x86)\ZOHO Corp\Password Sync Agent
In 32-bit systems: C:\Program Files\ZOHO Corp\Password Sync Agent
Making changes to the Password Sync Agent
In the event that you have given incorrect details during installation, moved ADSelfService Plus to a new server, regenerated the access key, or updated any Password Policy Enforcer settings, then the changes must be reflected in the Password Sync Agent for it to work properly. The details can be changed by following the steps given below:
Right-click the Password Sync Agent icon on the System tray and select Edit Settings. The Edit Settings dialog box will open.
Fig. 3: Editing configuration settings in the ADSelfService Plus Password Sync Agent wizard
Enter the Server Name/IP Address, Port, Protocol (HTTPS/HTTP), and Access key used by ADSelfService Plus.
Click Save.
The new details will now be updated in the Password Sync Agent.
Upgrading or reinstalling the password sync agent
To upgrade the Password Sync Agent to a newer version or to reinstall the agent on an existing machine, follow the steps listed below:
Note: Do not repair the Password Sync Agent directly from the new MSI file.
Steps for creating a custom password policy for native password changes and ADUC password resets
Go to Configuration > Self-Service > Password Policy Enforcer.
From the Select the Policy drop-down menu, choose the policy to which you want to apply the password policy rules.
Enable Enforce Custom Password Policy.
In this section, you can manage:
Fig. 4: Restricting characters with the ADSelfService Plus Password Policy Enforcer
Fig. 5: Restricting character repetition with the ADSelfService Plus Password Policy Enforcer
Fig. 6: Restricting patterns with the ADSelfService Plus Password Policy Enforcer
Fig. 7: Configuring the password length with the ADSelfService Plus Password Policy Enforcer
You can also enable users to bypass complexity requirements when the password length exceeds a predefined limit.
Enter the number of policy settings the users' password must comply with during self-service password reset and password change operations.
Enforce the configured password policy settings during password resets from the ADUC console and the change password screen.
To help users create passwords that comply with the enforced policy settings, you can display the password policy requirement on the reset and change password pages.
You can now use ADSelfService Plus to enforce advanced password policy rules to create stronger, more secure passwords for major cloud-based and on-premises applications, including Salesforce, Zendesk, and ServiceNow.