Enter the password data for the system user ID.
NOTE: password policies, global account policy settings for the Active Directory domain, and Active Directory account policies are all taken into account when verifying user passwords.
NOTE: The TargetSystem | ADS | Accounts | NotRequirePassword configuration parameter specifies whether a password is required when creating new Active Directory user accounts in One Identity Manager. If the configuration parameter is not set, entry of a password that meets the defined password guidelines is requested when a new Active Directory user account is created. If the configuration parameter is set, it is not necessary to specify a password when creating new Active Directory user accounts. In the Designer, you can edit the configuration parameter as required.
Property |
Description |
---|---|
Password |
Password for the user account. The identity’s central password can be mapped to the user account password. For more information about an identity’s central password, see One Identity Manager Identity Management Base Module Administration Guide. If you use a random generated initial password for the user accounts, it is automatically entered when a user account is created. The password is deleted from the database after publishing to the target system. |
Password confirmation |
Reconfirm password. |
Password last changed |
Date of last password change. The date is read in from the Active Directory system and cannot be changed. |
Password never expires |
Specifies whether the password expires. This option is usually used for service accounts. It overwrites the maximum lifetime of a password and the Change password at next logon option. |
Cannot change password |
Specifies whether the password can be changed. This option is normally set for user accounts that are used by several users. |
Change password at next login |
Specifies whether the user must change their password the next time they log in. TIP: To enable this option every time new user accounts are created, set the TargetSystem | ADS | Accounts | UserMustChangePassword configuration parameter. |
Save passwords with reversible encryption |
Details for encrypting the password. By default, passwords that are saved in Active Directory are encrypted. When you use this option, passwords are saved in plain text and can be restored again. |
SmartCard required to log on |
Data required for logging in with a SmartCard. Set this option to save public and private keys, passwords, and other personal information for this Active Directory user account. For the user to be able to log in to the network, the user’s computer must be equipped with a smart card reader and the user must have a personal identification number (PIN). |
Account trusted for delegation purposes |
Data required for delegation. Set this option so that a user can delegate the responsibility for administration and management of a partial domain to another Active Directory user account or another group. |
Cannot delegate account |
Data required for delegation. Set this option when this user account may not be assigned for delegation purposes from another user account. |
Account uses DES encryption |
Data required for encryption. Set this option if you would like to enable Data Encryption Standard (DES) support. |
Kerberos preauthentication not required |
Specifies whether Kerberos pre-authentication is required. Set this option when the user account uses a different implementation of the Kerberos protocol. |
Related topics
- Password policies for Active Directory user accounts
- Initial password for new Active Directory user accounts
- Global account policies for Active Directory domains
- Active Directory account policies for Active Directory domains
- Assigning Active Directory account policies to Active Directory user accounts