Forum Discussion
PHS remote users change password
Skipster311-1 As PHS was enabled before the EnforceCloudPasswordPolicyForPasswordSyncedUsers shouldn't forcing a password change solve this scenario considering you already have (1) enabled password writeback in Azure AD Connect and (2) password writeback for SSPR and (3) enabled the EnforceCloudPasswordPolicyForPasswordSyncedUsers (they now comply with Azure AD password expiration policy). When you enable SSPR to use password writeback, users who change or reset their password have that updated password synchronized back to the on-premises AD DS environment as well. Hence the DisablePasswordExpiration value [should] be removed from PasswordPolicies during the next password hash sync.
Just thinking out loud here, haven't used PHS..
Thijs Lecomte Any input here?
- BilalelHaddAug 16, 2021Iron ContributorHi Skip,
I have written a blogpost in the past about this feature, let me know if you still have some questions after reading the blog article: https://www.bilalelhaddouchi.nl/index.php/2020/09/24/comply-your-ad-password-expiration-policy-with-azure-ad/