Installing a Password Filter for Active Directory

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Password filters enforce password policies configured via the Microsoft Password Filter API. Third-party applications that synchronize passwords from Active Directory to foreign accounts use the Password Filter API to capture password changes. You can install a password filter on a device to enforce password policies and synchronize password changes to RapidIdentity.

  1. Download the Password Filter Installer file: Password_Filter_v_26.4.15.0.msi.zip.
  2. Run the installer as an administrator.
    Note:

    The account running the installer must belong to both the Schema Admins and Domain Admins groups in Active Directory. Perform this part on one domain controller only.

  3. In the installer, click Next.
  4. Select the installation folder, then click Next.
  5. Click Next to confirm the installation.
  6. Click Yes to allow the app to make changes to your device.
  7. Click Install Schema.
  8. Click Install RapidIdentity Public Key.
    Note:

    The public key encrypts captured passwords so that only this key can decrypt them. This step is required once per domain.

  9. Enter your RapidIdentity tenant URL, then click OK.
  10. Click Close to dismiss the RapidIdentity Password Filter for Active Directory Configuration dialog.
  11. Click Close to exit the installer.
  12. Click Yes when prompted to restart your system.
  13. Run the .msi file on each writeable domain controller, then follow the installation wizard and accept the default values.
    Note:Install the software on writeable domain controllers only; read-only domain controllers are not supported. The installation wizard pre-populates existing default values, which you can change if needed. The Install Schema option is unavailable during this step because the schema was already extended.
  14. Reboot the domain controller for the changes to take effect.