Password Policy Manager is an independently deployed component of Password Manager. Password Policy Manager is required to enforce Password Manager password policies when users change their passwords using tools other than Password Manager. To enforce Password Manager password policies, you must deploy Password Policy Manager on all Domain Controllers (DC) of your managed domain.
When a user changes their password in Password Manager, the new password is checked right away. If it complies with password policies configured in Password Manager, the new password is accepted.
However, when a user changes their password outside of Password Manager (for example, within the operating system by pressing Ctrl+Alt+Delete), Password Manager can not check the new password immediately. Instead, the compliance of the new password to the password policy rules is checked on a DC of the managed domain where Password Policy Manager is installed. If PPM is not installed on the DCs of the managed domain, then new passwords set outside Password Manager will not be checked against the password policies configured in Password Manager.
As such, Password Policy Manager extends the default password policy settings and allows administrators to configure policy scopes for each policy, so that only specified organizational units and groups are affected by the policy.
Password policy settings are stored as Group Policy Objects (GPOs). Password Policy Manager can only create new GPOs: it does not change any existing GPOs.
The installer of the Password Policy Manager component is located at the following subfolder of the Password Manager ISO image or extracted installation archive:
/Password Manager/Setup/PasswordPolicyManager_x64.msi
Password Manager uses a set of powerful and flexible rules to define requirements for domain passwords. Each password policy has rules that are configured independently of the rules in other policies.
The following rules duplicate and extend system password policy rules: Password Age rule, Length rule, Complexity rule, and User Properties rule.
For information on how to create and configure a password policy, see Creating and Configuring a Password Policy.
To display the properties of a password policy
- On the home page of the Administration site, click the Password Policies tab.
- Click the <N> One Identity Password Policieslink under the domain that you want to manage.
- On the One Identity Password Policiesfor Domain<DomainName> page, click Edit under the policy whose properties you want to view or modify.
To install the Password Policy Manager component in your managed domain, you must deploy it on all Domain Controllers (DC) via a Group Policy. You can create a new Group Policy Object (GPO), or use an existing one, to assign the Password Manager installation package with Password Policy Manager to the destination computers. Password Policy Manager is then installed on the computers to which the GPO applies.
The installer of the Password Policy Manager component is located at the following subfolder of the Password Manager ISO image or extracted installation archive:
/Password Manager/Setup/PasswordPolicyManager_x64.msi
To install Password Policy Manager on a single DC
- Run the PasswordPolicyManager_x64.msi installation package.
- Restart the computer once the installation is completed.
To deploy Password Policy Manager on multiple domain controllers
- Copy the PasswordPolicyManager_x64.msi installation package to a network share accessible from all DCs in the managed domain.
- Create a GPO and link it to all DCs in your managed domain. You may also choose an existing GPO to deploy Password Policy Manager.
- Under the selected GPO, open Computer Configuration > Software Settings.
- Right-click Software installation, then select New > Package.
- Select the PasswordPolicyManager_x64.msi installation package.
- Click Open.
- Select the deployment method and click OK.
- Verify and configure the installation properties, if needed.
To uninstall Password Policy Manager, remove it from all Domain Controllers (DC) in your managed domain.
To uninstall Password Policy Manager
- Remove Password Policy Manager from the DC of the managed domain.
- Restart the computer when prompted.
- Repeat the previous steps for all remaining DCs in the managed domain.
If you have deployed Password Policy Manager via a Group Policy, then uninstall Password Policy Manager by removing the PasswordPolicyManager_x64.msi installation package from the Software installation list.
To remove the Password Policy Manager installation package from a Group Policy
- Start the Group Policy Management snap-in. To do so, click Start, and navigate to Programs > Administrative Tools > Group Policy Management.
- In the console tree, click the group policy object that you used to deploy the package, and click Edit.
- Expand the Software Settings container that contains the Software installation item that you used to deploy the package.
- Click the Software installation container that contains the PasswordPolicyManager_x64.msi package.
- In the right pane of the Group Policy window, right-click the PasswordPolicyManager_x64.msi package, point to All Tasks, and then click Remove.
- Click Immediately uninstall the software from users and computers, and then click OK.
- Quit the Group Policy Object Editor snap-in, and then quit the Group Policy Management snap-in.
|
IMPORTANT: If you uninstall Password Manager, but do not remove Password Policy Manager from DCs in a managed domain, configured password policies will still be enforced. To stop the enforcement of password policies configured in Password Manager, uninstall Password Policy Manager from all DCs in the managed domain. |