AD Domain Controllers & Password Filters

From: Jason Garms [MS] (jasong@microsoft.com)
Date: 11/08/02


From: "Jason Garms [MS]" <jasong@microsoft.com>
Date: Fri, 8 Nov 2002 12:43:38 -0800


Hi Kent,

In an AD environment, you must install the same password
filter on all domain controllers, otherwise you'll end up
with weird results, since there is no communication
between DCs on this. What happens is when the client sends
a password change to its DC, that DC will allow/deny the
password change based on the filter installed on that DC.
If the password change is approved on that DC, the DC then
pushes out the modified object through normal AD
replication. Incoming replication from another DC does not
trigger password filters. The only thing that triggers the
filter is a password change, or password set done directly
against that DC.

Best,
-jasong

>-----Original Message-----
>Hi!
>
>I need to know if a password filter triggered on one AD
domain controller by
>a password change/set will trigger the password filter
installed on another
>AD domain controller in the same domain but in a
different site?
>Specifically, I am interested in determining if a
password change can
>trigger the password filters on more than one domain
controller in AD.
>
>Thanks,
>
>-Kent
>.
>



Relevant Pages

  • Re: Custom PASSFILT.DLL and Complexity in GP
    ... Password filters apply to all accounts in the local database, ... disable the builtin complexity unless you want the builtin ... > policy (not the default domain policy or default domain controller policy) ...
    (microsoft.public.security)
  • AD Domain Controllers & Password Filters
    ... password change based on the filter installed on that DC. ... trigger password filters. ...
    (microsoft.public.win2000.security)
  • Re: Audiences and AD Groups
    ... Is it using a basic filter for its searches and can it be customized ... > when I try to create an audience using the add audience rule using the ... > running SPS03, only on that network, the domain controller is running ...
    (microsoft.public.sharepoint.portalserver)
  • Re: Password change notifications on Domain controllers
    ... Not sure what you are seeing but I can assure you the password change notification filter is not fired on replication. ... Even if it were fired on the replication, you wouldn't get a clear text password because that isn't what is replicated. ... My 'PasswordChangeNotify' routine of the password filter DLL was invoked. ...
    (microsoft.public.platformsdk.security)
  • Re: virtual device for data acquisition
    ... If you're just looking for threshold analysis, ... See the demo "Measuring a Noise Floor Using Custom Trigger ... Conditions " under Applications on the Data Acquisition Toolbox demo page at ... that I apply after the filter. ...
    (comp.soft-sys.matlab)