Chat now with support
Chat with Support

Password Manager 5.14 - Administration Guide

About Password Manager Getting started Password Manager architecture
Password Manager components and third-party applications Typical deployment scenarios Password Manager in a perimeter network Management Policy overview Password policy overview Secure Password Extension overview reCAPTCHA overview User enrollment process overview Questions and Answers policy overview Password change and reset process overview Data replication Phone-based authentication service overview
Management policies
Checklist: Configuring Password Manager Understanding Management Policies Adding or cloning a new Management Policy Configuring access to the Administration Site Configuring access to the Password Manager Self-Service Site Configuring access to the Helpdesk Site Configuring Questions and Answers policy Workflow overview Custom workflows Custom activities Password Manager Self-Service Site workflows Helpdesk workflows Notification activities User enforcement rules
General Settings
General Settings overview Search and logon options Importing and exporting configuration settings Outgoing mail servers Diagnostic logging Scheduled tasks Web Interface customization Instance reinitialization Realm Instances Domain Connections Extensibility features RADIUS Two-Factor Authentication Internal Feedback Customizing help link URL Password Manager components and third-party applications Unregistering users from Password Manager Bulk Force Password Reset Fido2 key management Working with Redistributable Secret Management account Email templates
Upgrading Password Manager Administrative Templates Secure Password Extension Password Policies Enable 2FA for administrators and helpdesk users Reporting Password Manager integration Accounts used in Password Manager Open communication ports for Password Manager Customization options overview Third-party contributions Glossary

Dictionary Rule

The dictionary rule rejects passwords that match dictionary words or their parts.

The dictionary rule compares user passwords against a list of words stored in the QPMDictionary.txt text file (this file must use UTF-8 encoding). Depending on how you configure the rule settings, user passwords that partially or fully match dictionary words are rejected by Password Manager.

The QPMDictionary.txt (dictionary file) is located in the following folder: '\\<Domain Controller>\SYSVOL\<Domain>\31EB75A4-CD1A-4F67-94DA-9F8F5DF1F5C1', is deployed when user installs Password Policy Manager (PPM).

The dictionary file is never cached. During each password validity check, the dictionary file is read from the Password Manager server, or from the user's domain controller.

On the Policy Rules tab, click Dictionary Rule to expand the rule settings. Click Edit Dictionary File to edit or add new words to dictionary. After editing the file, click Save to save the changes. When user edits the dictionary file, the changes are saved in QPMDictionary.txt file, which is in SYSVOL folder in Domain Controller. Service accounts must have access to this file from machines, where Password Manager is installed.

When modifying the dictionary file, ensure that you begin every new word on a new line. It is recommended to maintain alphabetical order.

The dictionary rule is not case-sensitive which means that, on the one side, you can use either uppercase or lowercase when adding or modifying dictionary entries; and, on the other side, user input will undergo validity check irrespective of whether users use capitals or small letters in their passwords.

To configure the dictionary rule

  1. Follow the steps outlined in Configuring Password Policy Rules.

  2. On the Policy Rules tab, click Dictionary Rule to expand the rule settings.

  3. Under Dictionary Rule, select the Enable dictionary lookup to reject passwords that contain check box. This enables administrators to control a set of rules using the Dictionary Rule feature. These rules can be modified as follows:

Table 22: Dictionary rule

Option

Description

Beginning characters of a dictionary word

Specify number of characters in the password to match with the beginning of a word in dictionary before rejecting it. The characters in the password must be more than the specified number, for this option to work efficiently.

A complete word from the dictionary (QPMDictionary.txt)

Select this check box to reject passwords that represent an entire word stored in the dictionary.

Detect inclusion of non-alpha characters (pas7swo%rd)

Select this check box to remove non-alphabetic characters during analysis.

Enable bi-directional analysis

Select to reject passwords containing an entire dictionary word or its part (depending on which of the other three options you have selected), if read backwards.

NOTE: Password Policy Manager installation is not necessary, if Password Manager is installed on Domain Controller, and user wants to enable only dictionary rule.

Symmetry Rule

The symmetry rule ensures that password or its part does not read the same in both directions.

For example, if you enable the Reject passwords that read the same in both directions option, then the password “redivider” will be rejected.

To configure the symmetry rule

  1. Follow the steps outlined in Configuring Password Policy Rules.
  2. On the Policy Rules tab, click Symmetry Rule to expand the rule settings.

  3. Under Symmetry Rule, select the Password must comply with symmetry criteria check box, and then specify the following options:

Table 23: Symmetry criteria

Option

Description

Reject passwords that read the same in both directions (pass8ssap)

Select to reject passwords that are palindromes.

Maximum number of beginning characters that match ending characters of password if read backwards (pas47sap)

Specify the number of beginning characters matching the ending characters of password, if read backwards, which the policy will tolerate before rejecting a password.

Maximum number of consecutive characters within a password, that read the same in both directions (pass4554word)

Specify the number of password characters in a row that read the same in both directions, which the policy will tolerate before rejecting a password.

Case sensitive

Select to define this rule as case sensitive.

Custom Rule

You can use this rule to create your own password policy message to be displayed on the Self-Service Site when users change or reset their passwords. For example, if you want to hide all other policy messages and display your custom message to users, enable this policy rule, enter the message text, and select the Hide messages from other policy rules and display only this message check box. If you do not select this check box, messages from all enabled policy rules will be displayed.

Note, that this rule does not check the password compliance with the configured password policy. Configure this rule to display your custom message instead of or together with other policy messages when users change or reset passwords on the Self-Service Site.

To configure the custom rule

  1. Follow the steps outlined in Configuring Password Policy Rules.

  2. On the Policy Rules tab, click Custom Rule to expand the rule settings.

  3. Under Custom Rule, select the Enable check box to enable this rule.

  4. Select the Hide messages from other policy rules and display only this message check box if you want users to see only the custom password rule message and hide all other password policy messages.

  5. In the text box, enter the rule message in the default language (English). To enter the message in other languages, click the Add new language link, select the language, specify the message and click OK.

    NOTE: Only languages of the user interface of the Self-Service Site are available in the list.

Managing Password Policy scope

This section provides information on how to apply a password policy to groups and Organizational Units in a managed domain.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating