Password filters enforce password policies configured via the Microsoft Password Filter API. Third-party applications that synchronize passwords from Active Directory to foreign accounts use the Password Filter API to capture password changes. You can install a password filter on a device to enforce password policies and synchronize password changes to RapidIdentity.
- Download the Password Filter Installer file: Password_Filter_v_26.4.15.0.msi.zip.
- Run the installer as an administrator.
Note:The account running the installer must belong to both the Schema Admins and Domain Admins groups in Active Directory. Perform this part on one domain controller only.
- In the installer, click Next.
- Select the installation folder, then click Next.
- Click Next to confirm the installation.
- Click Yes to allow the app to make changes to your device.
- Click Install Schema.
- Click Install RapidIdentity Public Key.
Note:The public key encrypts captured passwords so that only this key can decrypt them. This step is required once per domain.
- Enter your RapidIdentity tenant URL, then click OK.
- Click Close to dismiss the RapidIdentity Password Filter for Active Directory Configuration dialog.
- Click Close to exit the installer.
- Click Yes when prompted to restart your system.
- Run the .msi file on each writeable domain controller, then follow the installation wizard and accept the default values.
Note:Install the software on writeable domain controllers only; read-only domain controllers are not supported. The installation wizard pre-populates existing default values, which you can change if needed. The Install Schema option is unavailable during this step because the schema was already extended.
- Reboot the domain controller for the changes to take effect.