We are currently using sync groups in ISC to manage passwords in 2 different AD directories, but we have a requirement to also have multiple password policies, how do we accomplish this?
Has anyone else encountered this when managing 2 or more directories?
You’ll run into a limitation here—password sync groups in ISC only support a single password policy across all included sources.
When you group multiple AD directories, you must pick one common policy that applies to all of them, and exceptions aren’t supported in a sync group.
While ISC does allow multiple password policies per source (even with filters), that only works when sources are managed independently.
So you essentially have two choices: either standardize both ADs to a single compatible policy and keep the sync group, or split them and manage policies separately (losing password sync).
Most teams end up normalizing to the strictest shared policy to keep synchronization intact.
Bottom line: multiple policies + password sync across directories isn’t supported together in ISC today.