Password policies
Fine-grained password policies (password settings objects, PSOs) give
some users and groups a different password and lockout policy from the
domain's: for example longer passwords for staff, or no lockout for young
pupils. Vertex lists, creates and changes them and chooses whom they apply
to. They are for Tenant admins; changes need the password policies
write switch and --pso on in the connector's guard.
The domain's functional level must be Windows Server 2008 or higher, and the AD account needs rights on the Password Settings Container (Setting up the domain controller).
The API calls are given in brackets (Vertex API).
Settings
| Setting | Meaning | Range |
|---|---|---|
precedence | Which policy wins when several apply to a user: the lowest number. | 1 or more |
min_password_length | Minimum length. | 0–255 |
password_history_count | Remembered passwords that cannot be reused. | 0–1,024 |
complexity_enabled | Passwords must meet the complexity rules. | yes/no |
reversible_encryption_enabled | Store passwords with reversible encryption (leave off). | yes/no |
min_password_age_seconds | How long before a password may be changed again. | 0 or more |
max_password_age_seconds | When passwords expire; 0 = never. | 0 or more, at least the minimum age |
lockout_threshold | Failed logons before lockout; 0 = never locked out. | 0–65,535 |
lockout_duration_seconds | How long a lockout lasts; 0 = until an administrator unlocks. | 0 or more |
lockout_observation_window_seconds | Time after which the failed-logon count resets. | 0 or more, at most the lockout duration |
Durations are in seconds: one day is 86400, 90 days 7776000, 30
minutes 1800. When a user has a policy, it replaces the domain's policy
for that user entirely (there is no merging).
Listing
GET /tenants/{tenantID}/password-policies returns every policy with its
settings and the DNs of the users and groups it applies to. A user's
resulting policy is the user's msDS-ResultantPSO attribute, shown by
a live read of the user (Users → One user).
Creating and changing
- Create (
POST …/password-policies): a name (at most 64 characters), all settings, and optionally whom it applies to (apply_to, up to 500 DNs). - Change (
PATCH …/password-policies/{objectID}): newsettings(all of them), and/orapply_toandunapplyto add and remove users and groups. Rename a policy with the object rename (POST …/objects/{objectID}/rename). - Delete (
DELETE …/objects/{objectID}): the deletes switch and a step-up.
A policy applies to users and global security groups. Every user and group you apply it to must be below a managed OU and not protected; policies for administrators are therefore set on the domain controller, not in Vertex. Policies themselves are in the Password Settings Container, outside the managed OUs, and that is where Vertex creates them.