Chat now with support
Chat with Support

Password Manager 5.7.1 - Administration Guide

About Password Manager Getting Started Password Manager Architecture
Password Manager Components and Third-Party Solutions Typical Deployment Scenarios Password Manager in Perimeter Network Management Policy Overview Password Policy Overview Secure Password Extension Overview reCAPTCHA Overview User Enrollment Process Overview Questions and Answers Policy Overview Password Change and Reset Process Overview Data Replication Phone-Based Authentication Service Overview
Management Policies
Checklist: Configuring Password Manager Understanding Management Policies Configuring Access to the Administration Site Configuring Access to the Self-Service Site Configuring Access to the Helpdesk Site Configuring Questions and Answers Policy Workflow Overview Custom Workflows Custom Activities Self-Service Workflows Helpdesk Workflows Notification Activities User Enforcement Rules
General Settings Upgrading Password Manager Secure Password Extension Password Policies Reporting Password Manager Integration Appendixes Glossary About us

Disallowed Characters Rule

Disallowed Characters Rule

The disallowed characters rule rejects passwords that contain certain character categories.

The categories include digits from 0-9 and special characters such as “#$%”. If you specify that special characters must not appear in the beginning of a password, then the password “@work” will be rejected.

To configure the disallowed characters rule

  1. Follow the steps outlined in Configuring Password Policy Rules.
  2. On the Policy Rules tab, click Disallowed Characters Rule to expand the rule settings.
  3. Under Disallowed Characters Rule, select the Password must not contain check box, and then specify the following options as required:
Table 25:

 

Option

Description

Digits (0-9)

Specify whether the rule will reject passwords containing digits.

Select the In positions check box, and then type the numbers of positions within a password where digits must not appear. For example, 1,3,5-10.

Select the Number of ending characters check box, and then specify how many digits there must not be in the end of a password.

Special characters

Specify whether the rule will reject passwords containing special characters.

Select the In positions check box, and then type the numbers of positions within a password where special characters must not appear. For example, 1,3,5-10.

Select the Number of ending characters check box, and then specify how many special characters there must not be in the end of a password.

Special characters include the following characters:
!"#$%&'()*+,-./:;<=>?@[\\]^_`{}~

 

NOTE: By default, the table of special characters is taken from the locale settings of the domain controller where the Password Policy Manager is installed. To view the locale settings, select Start | Settings | Control Panel | Regional Options and click the General tab.

Sequence Rule

Sequence Rule

The sequence rule rejects passwords that contain more repeated characters than it is allowed.

Repeated characters can appear in succession or in different positions in a password. This policy also includes characters typed in direct or inverse numerical or alphabetical order. For example, if you set the maximum number of same characters that appear in succession to three, then the password “eagle” will be rejected.

To configure the sequence rule

  1. Follow the steps outlined in Configuring Password Policy Rules.
  2. On the Policy Rules tab, click Sequence Rule to expand the rule settings.
  3. Under Sequence Rule, select the Password must not contain more than check box, and then specify the following options:
Table 26:

 

Option

Description

Number of characters repeated in succession (AAAB)

Set the maximum number of same characters in a row that the policy will tolerate before rejecting a password.

Number of identical characters (ABCA)

Set the maximum number of same characters typed in different positions of password that the policy will tolerate before rejecting a password.

Number of characters in direct or inverse numerical or alphabetical order (ABC_321)

Set the maximum number of characters typed in direct or inverse numerical or alphabetical order that the policy will tolerate before rejecting a password.

Case sensitive

Select this check box to require case sensitivity for this rule.

User Properties Rule

User Properties Rule

The user properties rule rejects passwords that contain part of a user account property value.

This rule splits the user account property value by non-alphanumeric characters (for example, “_”), and then checks if any part of the value is available in the password. For example, if user’s name is “Peter_US”, Password Manager splits the property into: “Peter” and “US”, and checks if any part can be found in the password. For example, the password “US_US” will be rejected.

To configure the user properties rule

  1. Follow the steps outlined in Configuring Password Policy Rules.
  2. On the Policy Rules tab, click User Properties Rule to expand the rule settings.
  3. Under User Properties Rule, select the Prevent users from using account properties as part of passwords check box, and then specify the following options:
Table 27:

 

 

 

Beginning characters of a user property value

Set the maximum number of beginning characters from a user property value that users are allowed to use as part of their passwords.

For example, if a user's full name is “Anna Fairweather”, and the option value is set to 3, then the user is allowed to type the strings “Ann” and “Fai” as part of her password. The password will be rejected if it contains “Anna” or “Fair”.

You can select from the following user account properties:

  • displayNamePrintable
  • mailNickname
  • userPrincipalName
  • displayName
  • title
  • sn
  • samAccountName
  • personalTitle
  • middleName
  • mail
  • givenName
  • employeeID
  • cn

The entire value of a user property

Select to reject passwords containing the entire value of a user property.

You can select any of the user account properties listed in the description of the Beginning characters of a user property value option above.

Case sensitive

Select this check box to require case sensitivity for this rule.

Enable bi-directional analysis

Select to reject passwords containing the entire value of a user property or its part (depending on which of the two previous options you have selected), if read backwards.

Dictionary Rule

Dictionary Rule

The dictionary rule rejects passwords that match dictionary words or their parts.

The dictionary rule compares user passwords against a list of words stored in the QPMDictionary.txt text file (this file must use UTF-8 encoding). Depending on how you configure the rule settings, user passwords that partially or fully match dictionary words are rejected by Password Manager.

The QPMDictionary.txt (dictionary file) is located in the following folder: '\\<Domain Controller>\SYSVOL\<Domain>\31EB75A4-CD1A-4F67-94DA-9F8F5DF1F5C1', is deployed when user installs Password Policy Manager (PPM).

The dictionary file is never cached. During each password validity check, the dictionary file is read from the Password Manager server, or from the user's domain controller.

On the Policy Rules tab, click Dictionary Rule to expand the rule settings. Click Edit Dictionary File to edit or add new words to dictionary. After editing the file, click Save to save the changes. When user edits the dictionary file, the changes are saved in QPMDictionary.txt file which is in SYSVOL folder in Domain Controller. Service accounts must have access to this file from machines, where Password Manager is installed. When modifying the dictionary file, ensure that you begin every new word on a new line. It is recommended to maintain alphabetical order.

The dictionary rule is not case-sensitive which means that, on the one side, you can use either uppercase or lowercase when adding or modifying dictionary entries; and, on the other side, user input will undergo validity check irrespective of whether users use capitals or small letters in their passwords.

  1. To configure the dictionary rule
  2. Follow the steps outlined in Configuring Password Policy Rules.
  3. On the Policy Rules tab, click Dictionary Rule to expand the rule settings.
  4. Under Dictionary Rule, select the Enable dictionary lookup to reject passwords that contain check box. This enables administrators to control a set of rules using the Dictionary Rule feature. These rules can be modified as follows:
Table 28:

 

Option

Description

Beginning characters of a dictionary word

Specify number of characters in the password to match with the beginning of a word in dictionary before rejecting it. The characters in the password must be more than the specified number, for this option to work efficiently.

A complete word from the dictionary (QPMDictionary.txt)

Select this check box to reject passwords that represent an entire word stored in the dictionary.

Detect inclusion of non-alpha characters (pas7swo%rd)

Select this check box to remove non-alphabetic characters during analysis.

Enable bi-directional analysis

Select to reject passwords containing an entire dictionary word or its part (depending on which of the other three options you have selected), if read backwards.

NOTE: Password Policy Manager installation is not necessary, if Password Manager is installed on Domain Controller, and user wants to enable only dictionary rule.
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating