Password expiring warning with AD

Douglas E Engert deengert at gmail.com
Tue Feb 16 12:48:30 EST 2016


Unless I missed something, could the AD attribute msDS-UserPasswordExpiryTimeComputed be used?

Its in AD 2008 and above:

https://msdn.microsoft.com/en-us/library/cc223410.aspx/
https://msdn.microsoft.com/en-us/library/windows/desktop/ms677839(v=vs.85).aspx

It lest AD do the calculation. So the warning could be produced if the attribute
is less then some selected time like a week.


On 2/16/2016 9:31 AM, Cantor, Scott wrote:
>> Without customization on the flow, one has to click the password-changing
>> link on the expiring warning page to go to the password-changing page,
>> perhaps on another server.
>
> I would say that's the very common case, yes. Most IDM teams have that sort of thing deployed separately.
>
>> If the original URL for the "proceed" state cannot be preserved for use here,
>> the user has to access the original service provider to login again.
>
> The URL you're on is usable by some other system as a redirect back to return you to the state of the flow, if that's what you mean. It would in fact resume. So maybe that works for you?
>
>> Assuming the password changing is easy enough to be implemented in the
>> IdP service
>
> I would say that's in fact not easy at all. Certainly not generically.
>
>> This may need some sort of flow customization, but the interceptor is
>> defined in the system folder.
>
> You aren't really meant to customize, but to copy them as examples for your own use.
>
> -- Scott
>

-- 

  Douglas E. Engert  <DEEngert at gmail.com>



More information about the users mailing list