Version Affected: All
Overview
A realm is configured to use Enforce Password Change Requirements, and Active Directory's Enforce password history policy is set to remember a user's last few passwords — for example, the last 3. Despite this, users are able to reuse recent passwords, such as the 2nd or 3rd most recent one, that Active Directory should still be blocking.
Cause
When Enforce Password Change Requirements is used, the SecureAuth appliance sets a randomized password in Active Directory before it sets the user's actual new password. This means the user's password is effectively changed twice for every single password reset they perform — once by the appliance's randomized intermediate change, and once by their real new password.
This has the same underlying cause as the double password change described in How To: Configure Enforce Password Change with a Minimum Password Age Requirement, just affecting Active Directory's password history count instead of its minimum password age.
Resolution
Set Active Directory's Enforce password history value to twice the number of passwords you actually want remembered. For example, if you want the last 3 passwords remembered, set the Active Directory value to 6 — 3 for the user's own password changes, plus 3 more to account for the appliance's own randomized intermediate changes.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.