Reset Password Identity with PTA Active (AD) not working

Hello,
I have this scenario.

A new Identity created in Sailpoint will have automatically the AD Account.
REQUIREMENT: I want that the Identity will set the password of AD without knowing the first random password assigned by Sailpoint.

A suggested solution is to use the invitation method of Sailpoint and the PTA (pass through authentication) to propagate the password towards AD.

I have 2 tenant to test this. Our tenant lab and the tenant of Client test. I have different behavior for different tenant and I would like to know if the problem is that the module of Password Management is not present in tenant Client Test.

This is what I’m testing:

  1. On the Identity Profile I have set Sign-in Method Directory Connection - Active Directory
  2. I create a new Identity
  3. I create the AD Account to the user
  4. I invite the user or I go to the link https://{tenant}.identitynow.com/login/login/?prompt=true&brand=default (we must use this special link because is active the SSO with EntraID)
  5. I click Problem Signing in ?
  6. I click Reset Password
  7. I insert the username that I received in the invitation mail
  8. I select mail to recovery the password
  9. I insert the code that I received by mail
  10. If I’m on LAB tenant in this step I can see the Reset Password section and if I set the new password this is propagated towars AD.
    If I’m on Client test tenant I have error “Please Contact the Administrator”

Why I have this different behavior ?

For ISC to pass a password to other system the Password Management Module is required. By default ISC does not keep a record of the password. Once it is set the password is released from memory and can not be accessed again. The Password Module allows for that password to remain in memory until it can pass that information to the down stream systems. Then it will release the password from memory. (This is my understanding of how Password Management module works).

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.