One of the most common issues when dealing with multiple Active Directory domains is handling different sets of passwords. Whether it's for domain migrations or maintaining separate domains for desktop login and Exchange mailbox access, users are burdened with managing each domain's unique password. This complicates user password management and results in an increase in the number of password-related tickets, eventually affecting overall productivity. To solve this challenge, admins can synchronize user password changes across multiple domains.
ADSelfService Plus' password synchronization feature replicates changes made to a domain user's password to their user accounts in other Active Directory domains and even in enterprise applications like Google Workspace and Microsoft 365. ADSelfService Plus' Password Sync Agent goes a step further, synchronizing the native password changes made through the Ctrl+Alt+Del screen and password resets made by administrators using the Active Directory Users and Computers console. Follow the steps below to configure password synchronization using ADSelfService Plus.
Note: You can also find Active Directory using the search bar on the left pane or by selecting the first letter of the application in the right pane.
Note: You can create multiple OU- and group-based policies in ADSelfService Plus that define the self-service features accessible to different users.
Linking user accounts between domains is essential for Active Directory password synchronization to work. By default, user accounts will be automatically linked based on the sAMAccountName Active Directory attribute. ADSelfService Plus also allows you to link user accounts based on any attribute of your choice.
To link accounts automatically, you have to specify a source attribute, which is composed of one or more attributes in AD, and a target attribute from the enterprise application. When a user resets or changes a password, the modification is synchronized only when the target attribute value matches the source attribute value.
Steps to link user accounts automatically:
Note: Say you want to use both sAMAccountName and initials as source Active Directory attributes. You select sAMAccountName from the Source Attribute section, click the plus button + next to the field, and select initials from the second drop-down that appears. Make sure that the combined value of the Active Directory source attribute matches the corresponding target attribute in the enterprise application. For example, if a user account's samAccountName value is John and their initial value is A, then their target attribute value should be JohnA.
Note:
If manual linking is enabled, users can link their Active Directory domain accounts themselves by entering the credentials of the domain account with which they want to link their primary domain account. For example, if they want to sync passwords from their user account in Domain A to their account in Domain B, they need to:
Steps to enable manual account linking:
Once the user accounts between the two domains are successfully linked, when a user accesses ADSelfService Plus for the first time, only their user account in the domain that initiates the password synchronization will consume an ADSelfService Plus license. Their linked user account in the other domain to which the passwords are synchronized will not consume a license. For example, consider Domain A with 1,000 user accounts that are linked to 1,000 user accounts in Domain B for password synchronization. When users from Domain A reset or change their passwords, and the new passwords are synchronized with Domain B, only the user accounts in Domain A will consume a license. Domain B accounts will not consume any licenses.
Note: If a user performs self-service actions using both their accounts in Domain A and Domain B, then licenses will be consumed for both accounts.
As Microsoft doesn't offer a native, built-in solution to directly sync passwords, users have to use PowerShell scripts. ADSelfService Plus offers password synchronization with zero scripting. By configuring the domains and user accounts, ADSelfService Plus will replicate your Active Directory password changes to another domain or other enterprise applications like Google Workspace and Microsoft 365.
ADSelfService Plus is a tool that lets you replicate domain users' password changes to their accounts in other Active Directory domains via the password synchronization feature.
Need further assistance? Fill this form, and we'll contact you rightaway.
Allow Active Directory users to self-service their password resets and account unlock tasks, freeing them from lengthy help desk calls.
Get seamless one-click access to 100+ cloud applications. With enterprise single sign-on, users can access all their cloud applications using their Active Directory credentials.
Intimate Active Directory users of their impending password and account expiry via email and SMS notifications.
Synchronize Windows Active Directory user passwords and account changes across multiple systems automatically, including Microsoft 365, Google Workspace, IBM iSeries, and more.
Strong passwords resist various hacking threats. Enforce Active Directory users to adhere to compliant passwords by displaying password complexity requirements.
Enable Active Directory users to update their latest information themselves. Quick search features help admins scout for information using search keys like contact numbers.