Active Directory Lightweight Directory Services (AD LDS) is a standalone service that operates independently of Active Directory domains and forests. It shares a similar infrastructure as Active Directory but with fewer features. AD LDS doesn’t require domain membership and can be used by external applications or clients, even if they're not part of the internal Active Directory domain. It also allows organizations to define and manage their own schema, which can be modified independently without disrupting the broader Active Directory schema. AD LDS serves as a great choice for organizations who need directory services but without the full-blown features and complexity of Active Directory.
A password policy is a set of rules and restrictions administrators can apply to dictate how passwords should be created, managed, and used within an organization. AD LDS does not have a password policy by default and will use the existing local or domain policy to which the instance belongs. If AD LDS is running on a server that belongs to a workgroup, the server's policy settings will be used.
Say an organization has its AD LDS instance running on a server within an Active Directory domain. AD LDS will enforce that domain's password policy , comprising of the following settings.
The organization might require their users to increase the length and use special characters to improve password security. To do this, a password policy can be configured to require a minimum character length, a mix of uppercase and lowercase letters, and so on, ensuring that users only create passwords that meet these requirements.
ADSelfService Plus is an identity security solution that goes beyond Active Directory's password policy with the Password Policy Enforcer. This enables you to set more stringent password rules to prevent risks from weak or compromised passwords. ADSelfService Plus automatically synchronizes the users' passwords between Active Directory and AD LDS, while enforcing a stronger, universal password policy. This ensures that your users' passwords in both Active Directory and AD LDS are protected from common password attacks.
ADSelfService Plus provides self-service password management to help organizations implement and protect their Active Directory password policy. It also tracks users' password history, manages account lockouts, sends password expiration notifications, and offers audit and reporting capabilities. In addition to these features, ADSelfService Plus provides adaptive MFA with support for a wide range of authenticators. It offers MFA for endpoints, cloud, and on-premises applications; VPNs; and Outlook on the web.