Password Sync

Password Sync is a software module that synchronizes Active Directory user passwords with the IIJ ID Service.

Using Password Sync automatically synchronizes user passwords with the IIJ ID Service whenever Active Directory users change their passwords.

Differences between Password Sync and Directory Sync

The differences between Password Sync and Directory Sync are as follows.

OptionDirectory Sync (Windows version)Password Sync
OverviewSynchronizes Active Directory users and groups with the IIJ ID ServiceSynchronizes Active Directory user passwords with the IIJ ID Service when they have changed their passwords
Synchronization targets"Users" and "Groups""Passwords" of users
Module installation destination

Environment in which LDAP communication can be established with respect to Active Directory

It does not have to be a terminal with domain participation.

All Active Directory domain controllers
OSWindows Server environment
Users who execute the module

Users who satisfy all of the following conditions:

  • Granted the "Log on as a batch job" privilege
  • Given authority to read and write data with respect to the drive in which Directory Sync is installed
  • Given authority to read and write data with respect to the Directory Sync Installation Folder
Not specified (cannot be specified) because Password Sync is executed by the LSA process
Connection users to AD

Users who satisfy all of the following conditions:

  • Given authority to view "users" and "groups" to be synchronized in Active Directory
  • Does not update passwords (to the extent possible)

Users who satisfy all of the following conditions:

  • Given authority to view users to be synchronized in Active Directory
  • Does not update passwords
Connection users to IIJ IDID Administrator of the IIJ ID Service
Synchronization intervalOS Task Scheduler function
Synchronization methodExtraction of changes (differential data)Capture of raw passwords using the Password Filter mechanism for Active Directory
Communication methodHTTPS/443 communication to the IIJ ID Service
LogsWriting data in Windows event logs