<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic nFront has a solution (shows in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820374#M41074</link>
    <description>&lt;P&gt;&lt;A href="http://www.nfrontsecurity.com/products/nfront-password-filter/index.php"&gt;nFront has a solution&lt;/A&gt; (shows up through an easy google-search), there a probably many more.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jan 2016 11:55:43 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2016-01-11T11:55:43Z</dc:date>
    <item>
      <title>Enforce Password Complexity on Microsoft Active Directory</title>
      <link>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820369#M41069</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Given that Microsoft Active Directory has two limitations as follows:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Cannot reject specific word to be used in Password Reset (e.g. company name)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Cannot enforce Special Characters as Mandatory Complexity requirements (i.e. AD can accept the password if user submit on the following complexity "Upper Case, Lower Case, Alphanumeric , Special Characters"&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;Accordingly i need your help if there is solution can modify password policy on the Active Directory&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks a lot in advance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820369#M41069</guid>
      <dc:creator>Mohamed_Abdelbaky1</dc:creator>
      <dc:date>2019-03-11T06:22:48Z</dc:date>
    </item>
    <item>
      <title>Perhaps you better ask in a</title>
      <link>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820370#M41070</link>
      <description>&lt;P&gt;Perhaps you better ask in a Microsoft forum. There you'll probably get more detailed help.&lt;/P&gt;
&lt;P&gt;At least your problem should be possible to solve with the help of &lt;A href="https://msdn.microsoft.com/en-us/library/ms721882(VS.85).aspx"&gt;password-filters&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 09:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820370#M41070</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-01-11T09:46:49Z</dc:date>
    </item>
    <item>
      <title>Thanks Karsten,</title>
      <link>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820371#M41071</link>
      <description>&lt;P&gt;Thanks Karsten,&lt;/P&gt;
&lt;P&gt;I think you got my question wrong as i'm asking if there is Cisco AAA Solution (e.g. ISE, ACS) can do these requirements.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 09:51:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820371#M41071</guid>
      <dc:creator>Mohamed_Abdelbaky1</dc:creator>
      <dc:date>2016-01-11T09:51:42Z</dc:date>
    </item>
    <item>
      <title>Ok, the password policy in</title>
      <link>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820372#M41072</link>
      <description>&lt;P&gt;Ok, the &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20/b_ise_admin_guide_20_chapter_01101.html#concept_E441E6E4FC9D497483613C34E4779EC2"&gt;password policy in ISE could match your needs&lt;/A&gt;, but it's always the policy of the authentication system that enforces the policy. If your users are in AD, then the AD-rules are in place. Only if your users are local to the ISE, these rules are enforced. That's probably not what you want to have.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 10:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820372#M41072</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-01-11T10:00:12Z</dc:date>
    </item>
    <item>
      <title>Unfortunately Yes, Users</title>
      <link>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820373#M41073</link>
      <description>&lt;P&gt;Unfortunately Yes, Users should be kept on AD , i'm wondering if there is Solution can do these requirements while remaining Users Database on AD itself.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 10:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820373#M41073</guid>
      <dc:creator>Mohamed_Abdelbaky1</dc:creator>
      <dc:date>2016-01-11T10:14:32Z</dc:date>
    </item>
    <item>
      <title>nFront has a solution (shows</title>
      <link>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820374#M41074</link>
      <description>&lt;P&gt;&lt;A href="http://www.nfrontsecurity.com/products/nfront-password-filter/index.php"&gt;nFront has a solution&lt;/A&gt; (shows up through an easy google-search), there a probably many more.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 11:55:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820374#M41074</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-01-11T11:55:43Z</dc:date>
    </item>
    <item>
      <title>Thanks again Karsten,</title>
      <link>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820375#M41075</link>
      <description>&lt;P&gt;Thanks again Karsten,&lt;/P&gt;
&lt;P&gt;i'm targeting Cisco Solution , not any software&lt;/P&gt;
&lt;P&gt;your help is appreciated and i will keep looking for another solution&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 12:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820375#M41075</guid>
      <dc:creator>Mohamed_Abdelbaky1</dc:creator>
      <dc:date>2016-01-11T12:50:55Z</dc:date>
    </item>
    <item>
      <title>Hi Mohamed,</title>
      <link>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820376#M41076</link>
      <description>&lt;P&gt;Hi Mohamed,&lt;/P&gt;
&lt;P&gt;From the discussion, I understood that you want the users to be kept on the AD however the password policy defined on AD has few limitations and you want the authentication server to overwrite the password policy for the authentication query while communicating to the AD. Well that would not be possible. The password policy will be checked for the identity store you have selected on ACS/ISE/ 3rd party AAA server. That means if on ACS server you authentication settings have LOCAL database as an identity store then local database password policy will be applied and if you have AD configured then its own password policy. You need to find out if the above 2 password policy requirements can be modified on the AD itself.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards - Jatin&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 13:58:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforce-password-complexity-on-microsoft-active-directory/m-p/2820376#M41076</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-01-11T13:58:42Z</dc:date>
    </item>
  </channel>
</rss>

