# Reset AD password when AD is enabled

**URL:** <https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud\
**Created:** [October 12, 2023, 7:19am UTC](https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054 "2023-10-12T07:19:32Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![saikumar39](https://avatars.discourse-cdn.com/v4/letter/s/3bc359/32.png) [@saikumar39](https://developer.sailpoint.com/discuss/u/saikumar39)\
**Post date:** [October 12, 2023, 7:19am UTC](https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054/1 "2023-10-12T07:19:32Z")

</div>

Hi ,

Is there any way to reset AD password when AD is enabled(Rehire) using password policy ?

Thank you,  
saikumar

---

<div class="post-metadata">

**Author:** ![atarodia](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@atarodia](https://developer.sailpoint.com/discuss/u/atarodia)\
**Post date:** [October 12, 2023, 9:13am UTC](https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054/2 "2023-10-12T09:13:58Z")

</div>

Hi @saikumar39,

You can use BeforeProvisioningRule to complete this requirement.  
Upon LCS change, you can choose to scramble password or change password attribute based on your requirement.  
You can use [SailPoint’s Services Standard BeforeProvisioningRule](https://cdck-file-uploads-global.s3.dualstack.us-west-2.amazonaws.com/sailpoint/original/2X/8/8939f8dddee417ecf55262549102a40748115e1a.pdf) to implement the requirement

However, the recommended way is to scramble the password upon disabling the AD account and user follow the reset password mechanism upon rehire.

---

<div class="post-metadata">

**Author:** ![KRM7](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/krm7/32/2685_2.png) [@KRM7](https://developer.sailpoint.com/discuss/u/KRM7)\
**Post date:** [October 12, 2023, 7:39pm UTC](https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054/3 "2023-10-12T19:39:42Z")

</div>

Password policy is just like a validator. For example when you enter password in any web page, you get the password strength and an error message if your password is not matching the standards.

Password policy can be used to Generate random password that meets the standards and validate the password strength when user reset.

Along with that, You can send reminders before password gets expired. For more details

> **[Managing Password Policies - SailPoint Identity Services](https://documentation.sailpoint.com/saas/help/pwd/policies.html#defining-password-expiration-settings)**
>
> SailPoint Identity Services Documentation

But I don’t think Password policy can reset the password in a source on its own. @colin_mckibben could you please confirm.

Thanks  
Krish

---

<div class="post-metadata">

**Author:** ![ajmerasunny1](https://avatars.discourse-cdn.com/v4/letter/a/3be4f8/32.png) [@ajmerasunny1](https://developer.sailpoint.com/discuss/u/ajmerasunny1)\
**Post date:** [October 12, 2023, 7:42pm UTC](https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054/4 "2023-10-12T19:42:06Z")

</div>

I’ll defer to @colin_mckibben for confirmation, but as far as I know, a password policy doesn’t compel password changes; instead, it verifies and enforces the criteria and prerequisites necessary for changing a password.

---

<div class="post-metadata">

**Author:** ![atarodia](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@atarodia](https://developer.sailpoint.com/discuss/u/atarodia)\
**Post date:** [October 13, 2023, 12:42pm UTC](https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054/5 "2023-10-13T12:42:51Z")

</div>

Yes, I second that and in addition to it password policies on IdentityNow does not reflect the actual policies on target system.

For example, target sources may have password history requirements which you can not configure on IdentityNow.

---

<div class="post-metadata">

**Author:** ![colin\_mckibben](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/colin_mckibben/32/37182_2.png) [@colin\_mckibben](https://developer.sailpoint.com/discuss/u/colin_mckibben)\
**Post date:** [October 16, 2023, 3:39pm UTC](https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054/6 "2023-10-16T15:39:29Z")

</div>

Hi @saikumar39. Did any of these replies answer your question? If so, can you please mark the reply that best answered your question as the solution? Thank you!

---

<div class="post-metadata">

**Author:** ![KRM7](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/krm7/32/2685_2.png) [@KRM7](https://developer.sailpoint.com/discuss/u/KRM7)\
**Post date:** [October 16, 2023, 3:52pm UTC](https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054/7 "2023-10-16T15:52:08Z")

</div>

> [@KRM7](#):
>
> But I don’t think Password policy can reset the password in a source on its own. @colin_mckibben could you please confirm

@colin_mckibben could you please confirm on this.

---

<div class="post-metadata">

**Author:** ![colin\_mckibben](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/colin_mckibben/32/37182_2.png) [@colin\_mckibben](https://developer.sailpoint.com/discuss/u/colin_mckibben)\
**Post date:** [October 16, 2023, 7:16pm UTC](https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054/8 "2023-10-16T19:16:32Z")

</div>

I’m not 100% certain, but I believe this to be correct. Password Policy does not initiate password changes, it just dictates the requirements for setting a password. As can be seen in the UI for password policies, there is no indication that you can trigger a password reset.

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/9/9cdf5f387118d36cb23f20708e9f157873c1d403.png)

I believe if you want to delve into password management, like automating the setting of passwords, you should look into [password management](https://developer.sailpoint.com/idn/api/v3/password-management) and [password sync groups](https://developer.sailpoint.com/idn/api/v3/password-sync-groups)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [December 15, 2023, 7:16pm UTC](https://developer.sailpoint.com/discuss/t/reset-ad-password-when-ad-is-enabled/19054/9 "2023-12-15T19:16:57Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
