Table of Contents

Active Directory

Authentication Users Password

Presentation

The Active Directory module is based on the LDAP module, with these features:

Configuration

The configuration is the same as the LDAP module.

AD password policy

AD password policy does not follow the LDAP RFC, but Microsoft has implemented its own policy. LemonLDAP::NG implements partially the policy:

Note: since AD 2012, each user can have a specific password expiration policy. Then, the "maximum password age" can have different values. This is currently unsupported in LemonLDAP::NG because every policy must be computed with their precedence to know which maximum password age to apply.

To configure warning before password expiration, you must set two variables in Active Directory parameters in Manager: