Skip to main content

Password policies

Fine-grained password policies (password settings objects, PSOs) give some users and groups a different password and lockout policy from the domain's: for example longer passwords for staff, or no lockout for young pupils. Vertex lists, creates and changes them and chooses whom they apply to. They are for Tenant admins; changes need the password policies write switch and --pso on in the connector's guard.

The domain's functional level must be Windows Server 2008 or higher, and the AD account needs rights on the Password Settings Container (Setting up the domain controller).

The web interface is in development

The API calls are given in brackets (Vertex API).

Settings​

SettingMeaningRange
precedenceWhich policy wins when several apply to a user: the lowest number.1 or more
min_password_lengthMinimum length.0–255
password_history_countRemembered passwords that cannot be reused.0–1,024
complexity_enabledPasswords must meet the complexity rules.yes/no
reversible_encryption_enabledStore passwords with reversible encryption (leave off).yes/no
min_password_age_secondsHow long before a password may be changed again.0 or more
max_password_age_secondsWhen passwords expire; 0 = never.0 or more, at least the minimum age
lockout_thresholdFailed logons before lockout; 0 = never locked out.0–65,535
lockout_duration_secondsHow long a lockout lasts; 0 = until an administrator unlocks.0 or more
lockout_observation_window_secondsTime after which the failed-logon count resets.0 or more, at most the lockout duration

Durations are in seconds: one day is 86400, 90 days 7776000, 30 minutes 1800. When a user has a policy, it replaces the domain's policy for that user entirely (there is no merging).

Listing​

GET /tenants/{tenantID}/password-policies returns every policy with its settings and the DNs of the users and groups it applies to. A user's resulting policy is the user's msDS-ResultantPSO attribute, shown by a live read of the user (Users → One user).

Creating and changing​

  • Create (POST …/password-policies): a name (at most 64 characters), all settings, and optionally whom it applies to (apply_to, up to 500 DNs).
  • Change (PATCH …/password-policies/{objectID}): new settings (all of them), and/or apply_to and unapply to add and remove users and groups. Rename a policy with the object rename (POST …/objects/{objectID}/rename).
  • Delete (DELETE …/objects/{objectID}): the deletes switch and a step-up.

A policy applies to users and global security groups. Every user and group you apply it to must be below a managed OU and not protected; policies for administrators are therefore set on the domain controller, not in Vertex. Policies themselves are in the Password Settings Container, outside the managed OUs, and that is where Vertex creates them.