diff --git a/docs/kb/passwordpolicyenforcer/authentication-and-integration/rsa-mfa-bypass-when-password-policy-enforcer-client-is-installed.md b/docs/kb/passwordpolicyenforcer/authentication-and-integration/rsa-mfa-bypass-when-password-policy-enforcer-client-is-installed.md index 2ec46f28b3..1e45d9aaa4 100644 --- a/docs/kb/passwordpolicyenforcer/authentication-and-integration/rsa-mfa-bypass-when-password-policy-enforcer-client-is-installed.md +++ b/docs/kb/passwordpolicyenforcer/authentication-and-integration/rsa-mfa-bypass-when-password-policy-enforcer-client-is-installed.md @@ -43,7 +43,7 @@ Both options achieve the same result: they disable Password Policy Enforcer Clie After applying either option, the username and password fields will no longer appear on the Windows logon screen. Only the authentication method configured for RSA MFA will be available at logon. ### Option 1 — With Group Policy: -> **NOTE:** Install the Password Policy Client administrative template before these steps. For the ADMX template and installation steps, see [Configuring the password policy client](https://docs.netwrix.com/docs/passwordpolicyenforcer/11_2/admin/password-policy-client/configuring_the_password_policy_client). +> **NOTE:** Install the Password Policy Client administrative template before these steps. For the ADMX template and installation steps, see [Configuring the password policy client](https://docs.netwrix.com/docs/passwordpolicyenforcer/admin/password-policy-client/configuring_the_password_policy_client). 1. In Group Policy Management, edit the GPO linked to the affected machines. 2. Expand **Computer Configuration** > **Policies** > **Administrative Templates** > **Netwrix Password Policy Enforcer** > **Netwrix Password Policy Client**. diff --git a/docs/kb/passwordpolicyenforcer/troubleshooting-and-errors/password-policy-client-generic-message-windows-rules.md b/docs/kb/passwordpolicyenforcer/troubleshooting-and-errors/password-policy-client-generic-message-windows-rules.md index d97caf4f2b..07b5e84531 100644 --- a/docs/kb/passwordpolicyenforcer/troubleshooting-and-errors/password-policy-client-generic-message-windows-rules.md +++ b/docs/kb/passwordpolicyenforcer/troubleshooting-and-errors/password-policy-client-generic-message-windows-rules.md @@ -52,7 +52,7 @@ The following steps occur in order when you change your password: maximum age, minimum length, and complexity. - If the password fails any Windows rule, LSASS rejects the change immediately. PPE does not see the password on the domain controller. - If the password passes all Windows rules, LSASS sends it to PPE for additional checks. -3. **Password Policy Server** — On the domain controller, PPE evaluates the password against all its rules except [Similarity](pathname:///docs/passwordpolicyenforcer/11_2/admin/manage-policies/rules/similarity_rule), and accepts or rejects the password. +3. **Password Policy Server** — On the domain controller, PPE evaluates the password against all its rules except [Similarity](pathname:///docs/passwordpolicyenforcer/admin/manage-policies/rules/similarity_rule), and accepts or rejects the password. ### Effect on the Password Policy Client @@ -71,11 +71,11 @@ PPE can only log rejection events if PPE rejects the password, either on the cli To ensure PPE evaluates all passwords and can provide detailed rejection messages, disable the Windows password policy rules. You must then satisfy only the PPE rules. -See [Disable Windows Rules](pathname:///docs/passwordpolicyenforcer/11_2/installation/disable_windows_rules) for instructions. +See [Disable Windows Rules](pathname:///docs/passwordpolicyenforcer/installation/disable_windows_rules) for instructions. > **NOTE:** If your organization requires both Windows and PPE rules, you must satisfy both. A password that passes all client-side PPE rules but fails a Windows rule will always produce a generic rejection message, and PPE logs no event for that rejection. This is expected behavior. ## Related Links -- [Similarity](pathname:///docs/passwordpolicyenforcer/11_2/admin/manage-policies/rules/similarity_rule) -- [Disable Windows Rules](pathname:///docs/passwordpolicyenforcer/11_2/installation/disable_windows_rules) +- [Similarity](pathname:///docs/passwordpolicyenforcer/admin/manage-policies/rules/similarity_rule) +- [Disable Windows Rules](pathname:///docs/passwordpolicyenforcer/installation/disable_windows_rules) diff --git a/docs/kb/passwordpolicyenforcer/troubleshooting-and-errors/password-verification-performed-on-domain-controller-warning.md b/docs/kb/passwordpolicyenforcer/troubleshooting-and-errors/password-verification-performed-on-domain-controller-warning.md index dc800d9314..7b5b86afdc 100644 --- a/docs/kb/passwordpolicyenforcer/troubleshooting-and-errors/password-verification-performed-on-domain-controller-warning.md +++ b/docs/kb/passwordpolicyenforcer/troubleshooting-and-errors/password-verification-performed-on-domain-controller-warning.md @@ -38,7 +38,7 @@ Password verification will be performed on the domain controller %DC_FQDN%. ## Resolutions -- Netwrix Password Policy Enforcer Mailer is required for Compromised Password Checker to operate. If it was not installed previously, refer to the following article for additional information on installation: Administration − Mailer ⸱ v10.2: https://docs.netwrix.com/docs/passwordpolicyenforcer/11_0 +- Netwrix Password Policy Enforcer Mailer is required for Compromised Password Checker to operate. If it was not installed previously, refer to the following article for additional information on installation: Administration − Mailer: https://docs.netwrix.com/docs/passwordpolicyenforcer - Review the FQDN of the domain controller the Netwrix Password Policy Enforcer Mailer was installed to: diff --git a/docs/passwordpolicyenforcer/10.2/administration/_category_.json b/docs/passwordpolicyenforcer/10.2/administration/_category_.json deleted file mode 100644 index 4865c25aab..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Administration", - "position": 20, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "administration_overview" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/administration/administration_overview.md b/docs/passwordpolicyenforcer/10.2/administration/administration_overview.md deleted file mode 100644 index 7d27ee457a..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/administration_overview.md +++ /dev/null @@ -1,30 +0,0 @@ ---- -title: "Administration" -description: "Administration" -sidebar_position: 20 ---- - -# Administration - -Netwrix Password Policy Enforcer helps you to secure your network by ensuring that users choose -strong passwords. When a user chooses a password that doesn't comply with the password policy, -Password Policy Enforcer immediately rejects the password and tells them why their password was -rejected. - -![introduction_2](/images/passwordpolicyenforcer/10.2/evaluation/introduction_3.webp) - -Unlike password cracking products that check passwords after they are accepted by the operating -system, Password Policy Enforcer checks new passwords immediately to ensure that weak passwords do -not jeopardize network security. - -You can also use Password Policy Enforcer to ensure that passwords are compatible with other -systems, and to synchronize passwords with other networks and applications. - -:::note -The -[Evaluation](/docs/passwordpolicyenforcer/10.2/evaluation/evaluation_overview.md) -topic contains step-by-step instructions to help you quickly install, configure, and evaluate -Password Policy Enforcer. Read the Evaluation topic if you are using Password Policy Enforcer for -the first time. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/connecting.md b/docs/passwordpolicyenforcer/10.2/administration/connecting.md deleted file mode 100644 index a01f2575e7..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/connecting.md +++ /dev/null @@ -1,70 +0,0 @@ ---- -title: "Connect to a Configuration" -description: "Connect to a Configuration" -sidebar_position: 60 ---- - -# Connect to a Configuration - -Password Policy Enforcer's configuration settings are stored in Active Directory or the registry. An -Active Directory configuration is called a domain configuration, and it defines the password -policies for domain user accounts. A registry configuration is called a local configuration, and it -defines the password policies for local user accounts. - -## Connecting to a Domain Configuration - -A domain configuration exists on every domain controller. Changes to the configuration replicate to -all the domain controllers in the domain, so you only need to configure one domain controller in -each domain. If you are using Password Policy Enforcer in more than one domain, then you will need -to configure each domain separately. - -Complete the following steps to connect to a domain configuration. - -**Step 1 –** Click the **Netwrix Password Policy Enforcer** item to display the Password Policy -Enforcer view. - -**Step 2 –** Click **Connect To** in the right pane of the management console. - -**Step 3 –** Select the **Domain** option. - -**Step 4 –** Enter the **name** or **IP address** of a domain controller, then click **OK**. - -:::note -You can't make changes to the Password Policy Enforcer configuration while the management -console is connected to a read-only domain controller. -::: - - -## Connecting to a Local Configuration - -A local configuration applies to only one computer, so it doesn't replicate to any other computers. -You can copy a local configuration to another computer by exporting the configuration from the -registry, and then importing it into the registry of the other computer. You can also use Group -Policy to distribute a local configuration to many computers. See the -[Domain and Local Policies](/docs/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.md) -topic for additional information. - -Complete the following steps to connect to a computer's local configuration. - -**Step 1 –** Click the **Netwrix Password Policy Enforcer** item to display the Password Policy -Enforcer view. - -**Step 2 –** Click **Connect To** in the right pane of the management console. - -**Step 3 –** Select the **Local** option, then click **OK**. - -:::note -Domain configurations are stored in the CN=Password Policy Enforcer 10.0,CN=System object. -::: - - -:::note -Local configurations are stored in the HKLM\SOFTWARE\ANIXIS\Password Policy Enforcer 10.0\ -registry key. -::: - - -:::note -Users with write permission to these objects can configure Password Policy Enforcer. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.md b/docs/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.md deleted file mode 100644 index 9cab884e86..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.md +++ /dev/null @@ -1,110 +0,0 @@ ---- -title: "Domain and Local Policies" -description: "Domain and Local Policies" -sidebar_position: 10 ---- - -# Domain and Local Policies - -Netwrix Password Policy Enforcer V7.5 and later can enforce password policies for both domain and -local user accounts. - -Domain user accounts exist in Active Directory. Information about these accounts is kept on the -domain controllers, and changes to the accounts are replicated amongst the domain controllers. - -Local user accounts exist in the SAM database of workstations and servers. The workstations and -servers may be standalone, or domain members. Information about these accounts is only kept on the -host computer, and doesn't replicate to any other computers. - -A typical Windows network has both domain and local user accounts, but you may not want to enforce -Password Policy Enforcer password policies for both account types. If your users normally log on with -a domain account, then you will most likely only use Password Policy Enforcer to enforce password -policies for the domain accounts. - -## Installation Differences - -To enforce password policies for domain user accounts, you should install Password Policy Enforcer -onto all the domain controllers in the domain. If you have read-only domain controllers and aren't -using the -[Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md), -[Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md), -or other software (such as -[Netwrix Password Reset](https://www.netwrix.com/active_directory_password_reset_tool.html)) that -uses the Password Policy Enforcer Client protocol, then you don't need to install Password Policy -Enforcer on the read-only domain controllers. - -To enforce password policies for local user accounts, you should install Password Policy Enforcer -onto the computers containing the user accounts you want to enforce password policies for. These -computers may be workstations or servers, and they may be standalone or domain members. It is -normally not necessary to install Password Policy Enforcer onto all the workstations and servers in -a domain because most users in a domain logon with a domain account. If this is the case, then you -will most likely only need to install Password Policy Enforcer on the domain controllers. - -## Operational Differences - -Most of Password Policy Enforcer's rules and features can be used with both domain and local -policies, but there are some differences. When enforcing the password policy for domain accounts, -Password Policy Enforcer queries Active Directory to get information about the accounts. - -While it is theoretically possible to get most of this information from the SAM database for local -accounts, there is a technical limitation which stops password filters from querying the SAM. There -is also some information, such as the user's OU, which doesn't exist in the SAM. Because of these -limitations, the following rules and features can't be used with local password policies: - -- The Minimum Age and Maximum Age rules (you can use the Windows version of these rules with - Password Policy Enforcer). See the - [Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) - topic for additional information. -- Policy assignments by groups and containers. See the - [Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) - topic for additional information. - -Password Policy Enforcer's configuration is stored in Active Directory for domain password policies, -and in the Windows registry for local password policies. The Connect To page in the Password Policy -Enforcer management console. Use it to choose a configuration source. See the -[Connect to a Configuration](/docs/passwordpolicyenforcer/10.2/administration/connecting.md) -topic for additional information. Changes you make to Password Policy Enforcer's domain -configuration are replicated to all domain controllers in the domain. Changes to a local -configuration are applied only to the local computer. If you want to use the same local -configuration for many computers, export the HKLM\SOFTWARE\ANIXIS\Password Policy Enforcer 10.0\ -registry key from the configured computer, and import it into the other computers. - -You can also use Group Policy to distribute Password Policy Enforcer's local configuration to many -computers in a domain. This is only necessary for local password policies. Domain password policies -automatically replicate to the domain controllers because they are stored in Active Directory. - -Complete the following steps to distribute Password Policy Enforcer's local configuration with Group -Policy. - -**Step 1 –** Start the Group Policy Management Console (gpmc.msc). - -**Step 2 –** Expand the forest and domain items in the left pane. - -**Step 3 –** Right-click the **Group Policy** object that you would like to use to distribute the -configuration, and then click the **Edit...** button. - -**Step 4 –** Expand the Computer Configuration, Preferences, and Windows Settings items in the left -pane. - -**Step 5 –** Right-click the **Registry** item, and then select **New** > **Registry Wizard**. - -![domain_and_local_policies](/images/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.webp) - -**Step 6 –** Select the computer that contains the Password Policy Enforcer local configuration that -you want to distribute, and then click **Next**. - -**Step 7 –** Expand the **HKEY_LOCAL_MACHINE**, **SOFTWARE**, and **ANIXIS** items. - -**Step 8 –** Click the **Password Policy Enforcer 10.0** item, and then select the check boxes -beside each item in the bottom pane of the window. - -![domain_and_local_policies_1](/images/passwordpolicyenforcer/10.2/administration/domain_and_local_policies_1.webp) - -**Step 9 –** Click **Finish**. - -**Step 10 –** Close the Group Policy Management Editor. - -Password Policy Enforcer's local configuration is applied to the target computers in the domain. -This doesn't happen immediately, as Windows takes some time to apply the changes to Group Policy. -You can force an immediate refresh of Group Policy on the local computer with this command: -`gpupdate /target:computer` diff --git a/docs/passwordpolicyenforcer/10.2/administration/hibpupdater.md b/docs/passwordpolicyenforcer/10.2/administration/hibpupdater.md deleted file mode 100644 index 1c73284552..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/hibpupdater.md +++ /dev/null @@ -1,167 +0,0 @@ ---- -title: "HIBP Updater" -description: "HIBP Updater" -sidebar_position: 140 ---- - -# HIBP Updater - -You can configure Password Policy Enforcer to use the Have I Been Pwned (HIBP) database. A copy of -this database is hosted on the Netwrix website. The HIBP database contains a list of the hashes of -known compromised passwords. During password change operations, you can configure the application to -reject passwords with a hash that matches a hash in the HIBP database. The Password -Policy Enforcer Settings window displays current HIBP database information and configuration -options. - -The HIBP database must be initially deployed to a server or workstation with an internet connection -that can retrieve and format the file. After the database is formatted, you can distribute the HIBP -database to your domain controllers so the Password Policy Enforcer server can check passwords -against the HIBP database. - -## Considerations When Deploying the HIBP Database - -Before deploying the HIBP database, consider the pros and cons when choosing its deployment -location. - -- The HIBP database takes up additional space on the machine where it is copied (approximately 13 - GB) -- A network connection to the application server isn't required to check passwords against the HIBP - database - -## Installation and Configuration - -The HIBP Updater is installed when you install the Password Policy Enforcer Management Server. - -:::info -Only run this from one server. -::: - - -**Step 1 –** To access the HIBP Updater, navigate to the installation location: - -**...\Program Files (x86)\Password Policy Enforcer\HIBP\** - -![hibpfolder](/images/passwordpolicyenforcer/10.2/administration/hibpfolder.webp) - -**Step 2 –** Click HIBPWINUpdater. - -### Passwords Hash Database - -Password Policy Enforcer uses the Passwords Hash database to check if users’ new and pending -password (i.e. during a password reset) matches the hash of a compromised password from a data -breach. - -:::note -First-time configuration of this window requires downloading the HIBP database from the -Netwrix website. -::: - - -![passwordhashdatabase](/images/passwordpolicyenforcer/10.2/administration/passwordhashdatabase.webp) - -:::warning -Ensure the initial update of the database occurs during non-office hours. Due to the -size of the hash file, this download takes up a significant amount of CPU and download time. -::: - - -- Passwords Hash Database Folder – Central location of the Pwned database on the application server. - The default path is: - -**…\HIBP\DB** - -- Update Type: - - - Full Download – Download all data from the HIBP database hosted on the Netwrix website - - Incremental Update – Download updates from the HIBP database hosted on the Netwrix website - instead of downloading the full HIBP database. This option is enabled after a full download of - the HIBP database has completed. - - :::note - Only the full HIBP database file obtained from the Netwrix website has version - information. That full HIBP database file can be obtained using the Website option. - Alternately, the HIBP database can be obtained outside of the application by downloading it - directly from the Netwrix website using an FTP connection: - ::: - - - - [https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip](https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip) - - [https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip.sha256.txt](https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip.sha256.txt) - - Then use the File option to enable incremental updates. - -- Location: - - - File – If the application server doesn't have internet access, you can manually download the - HIBP database and select the **File** radio button to browse to your local copy of the - database - - Web Site – This option points to the Netwrix website that hosts a copy of the latest HIBP - database. This is the default option and the preferred method if the application server has - internet access. - -- Apply: - - - If Website is selected, then clicking **Apply** downloads the HIBP database from the Netwrix - website and then processes the database for use by the application - - If File is selected, then clicking **Apply** processes the local copy of the (manually obtained) database for use by the application - -### Hash File Replication - -Password Policy Enforcer doesn't distribute hash file updates to other computers, but you can use -the Windows Distributed File System to ensure that all domain controllers have the latest hash -files. Copy the hash files into the Sysvol share on one domain controller, and the Distributed File -System will copy the files into the Sysvol share of all other domain controllers. Configure the -Compromised rule to read the files from: - -**\\127.0.0.1\sysvol\your.domain\filename.db** - -See the -[Compromised Rule](/docs/passwordpolicyenforcer/10.2/administration/rules/compromised_rule.md) -topic for additional information. - -The preceding path only works if the computer has a Sysvol share. This won't be the case if you are -using a workstation for policy testing, or if you are using Password Policy Enforcer to enforce -local policies. If you are using Password Policy Enforcer for local policies and want all computers -to receive hash file updates, then use the Sysvol share for file replication and a script or -scheduled task to copy the file to a local folder. - -:::warning -%SystemRoot%. hash files should only be read from a local disk. Using shared hash files -degrades performance, and could jeopardize security. -::: - - -## Scheduler - -Password Policy Enforcer administrators can use the Scheduler portion of the HIBP Updater to -automate the tool to retrieve and/or prepare the HIBP dataset. The Scheduler uses Microsoft Task -Scheduler technology to execute the process. - -### How to Schedule a Task - -**Step 1 –** Click **Scheduler** in the HIBP Updater. - -**Step 2 –** Click **Add Schedule**. The Edit Schedule window opens, similar to the HIBP Updater window. - -![editschedule](/images/passwordpolicyenforcer/10.2/administration/editschedule.webp) - -**Step 3 –** Enter the Name and Description of the schedule. - -**Step 4 –** Select **Add Trigger** to add the interval that you want to have the schedule run. - -- You can add as many triggers as you want to a schedule. - -**Step 5 –** Select the Update Type and Location to get the update. - -**Step 6 –** After you have set up your schedule, click **OK** to save the schedule. - -The HIBP Updater updates the database according to the schedule. - -### Schedule List - -The Schedule List window shows the names, run times, next run times, and whether the schedule is -enabled or not. - -![schedulelist](/images/passwordpolicyenforcer/10.2/administration/schedulelist.webp) - -Use this window to Add, Edit, or Delete schedules for the HIBP Updater. diff --git a/docs/passwordpolicyenforcer/10.2/administration/installation/_category_.json b/docs/passwordpolicyenforcer/10.2/administration/installation/_category_.json deleted file mode 100644 index 64ab617b78..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/installation/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Installation", - "position": 20, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "installation" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/administration/installation/automated_installation.md b/docs/passwordpolicyenforcer/10.2/administration/installation/automated_installation.md deleted file mode 100644 index ffe8947344..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/installation/automated_installation.md +++ /dev/null @@ -1,94 +0,0 @@ ---- -title: "Automated Installation (Advanced Setup)" -description: "Automated Installation (Advanced Setup)" -sidebar_position: 10 ---- - -# Automated Installation (Advanced Setup) - -An automated installation uses Group Policy to distribute Password Policy Enforcer. This type of -installation is recommended when you need to install Password Policy Enforcer on many computers. -This section shows you how to install Password Policy Enforcer on domain controllers to enforce -domain policies, but you can also use Group Policy to target member servers and workstations if you -need to enforce local policies. See the -[Domain and Local Policies](/docs/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.md) -topic for additional information. - -## Create a Distribution Point - -A distribution point can either be a UNC path to a server share, or a DFS (Distributed File System) -path. To create a Password Policy Enforcer distribution point: - -**Step 1 –** Log on to a server as an administrator. - -**Step 2 –** Create a shared network folder to distribute the files from. - -**Step 3 –** Give the **Domain Controllers** security group read access to the share, and limit -write access to authorized personnel only. - -### Copy PPE10.1.msi into the Distribution Point - -**Step 1 –** Start the Password Policy Enforcer installer (PPE10.1.exe). - -**Step 2 –** Read the license agreement, and then click **Yes** if you accept all the license terms -and conditions. - -**Step 3 –** Select the **Advanced** option, and then click **Next**. - -**Step 4 –** Right-click the **PPE10.1.msi** icon, click **Copy**, and then paste the file into the -distribution point. - -![installing_ppe](/images/passwordpolicyenforcer/10.2/administration/installing_ppe.webp) - -**Step 5 –** Give the **Domain Controllers** security group read access to the PPE10.1.msi file in -the distribution point. - -**Step 6 –** Click **Finish**. - -## Create a Group Policy Object - -**Step 1 –** Start the Group Policy Management Console (gpmc.msc). - -**Step 2 –** Expand the forest and domain items in the left pane. - -**Step 3 –** Right-click the **Domain Controllers OU** in the left pane, and then click **Create a -GPO in this domain, and Link it here...** - -![installing_ppe_1](/images/passwordpolicyenforcer/10.2/administration/installing_ppe_1.webp) - -**Step 4 –** Enter **Password Policy Enforcer** in the provided field, and then press **Enter**. - -## Edit the Group Policy Object - -**Step 1 –** Right-click the **Password Policy Enforcer GPO**, and then click the **Edit...** -button. - -**Step 2 –** Expand the **Computer Configuration**, **Policies**, and **Software Settings** items. - -**Step 3 –** Right-click the **Software installation** item, and then select **New** > -**Package...** - -**Step 4 –** Enter the full **UNC path to PPE10.1.msi** in the Open dialog box. - -:::note -You must enter a UNC path so that other computers can access this file over the network. -For example: \\file server\distribution point share\PPE10.1.msi -::: - - -**Step 5 –** Click **Open**. - -![installing_ppe_2](/images/passwordpolicyenforcer/10.2/administration/installing_ppe_2.webp) - -**Step 6 –** Select the **Assigned deployment method**, and then click **OK**. - -**Step 7 –** Close the Group Policy Management Editor. - -## Complete the Installation - -Restart each domain controller to complete the installation. Windows installs Password Policy -Enforcer during startup, and then immediately restarts the computer a second time to complete the -installation. - -Password Policy Enforcer won't enforce a password policy at this time because no policies are -defined. Users can still change their password, and must comply only with the Windows password policy rules (if enabled). diff --git a/docs/passwordpolicyenforcer/10.2/administration/installation/disable_windows_rules.md b/docs/passwordpolicyenforcer/10.2/administration/installation/disable_windows_rules.md deleted file mode 100644 index 4dddc41284..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/installation/disable_windows_rules.md +++ /dev/null @@ -1,53 +0,0 @@ ---- -title: "Disable Windows Rules" -description: "Disable Windows Rules" -sidebar_position: 30 ---- - -# Disable Windows Rules - -The Windows password policy rules can place restrictions on password history, age, length, and -complexity. If you enable the Password Policy Enforcer rules and the Windows rules, then users will -have to comply with both sets of rules. - -Password Policy Enforcer has its own history, minimum age, maximum age, length, and complexity rules. -See the -[Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) -topic for additional information. You can use the Password Policy Enforcer and Windows rules -together. A password is only accepted if it complies with the Windows and Password Policy Enforcer -password policies. - -Complete the following steps to disable the Windows password policy rules: - -**Step 1 –** Start the Group Policy Management Console (gpmc.msc). - -**Step 2 –** Expand the forest and domain items in the left pane. - -**Step 3 –** Right-click the **Default Domain Policy GPO** (or whichever GPO you use to set your -domain password policy), then click **Edit...** - -**Step 4 –** Expand the **Computer Configuration**, **Policies**, **Windows Settings**, **Security -Settings**, **Account Policies**, and **Password Policy** items. - -**Step 5 –** Double-click **Enforce password history** in the right pane of the GPO Editor. - -**Step 6 –** Enter **0** in the text box, then click **OK**. - -**Step 7 –** Repeat the preceding step for the **Maximum password age**, **Minimum password age**, and -**Minimum password length** policies. - -**Step 8 –** Double-click **Password must meet complexity requirements** in the right pane. - -**Step 9 –** Select the **Disabled** option, and then click **OK**. - -**Step 10 –** Close the Group Policy Management Editor. - -![installing_ppe_3](/images/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer.webp) - -:::note -You don't have to disable all the Windows password policy rules to use Password Policy -Enforcer. You can use a combination of Password Policy Enforcer and Windows rules together if you -like. Just remember that a password is only accepted if it complies with the rules enforced by both -Windows and Password Policy Enforcer. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/installation/installation.md b/docs/passwordpolicyenforcer/10.2/administration/installation/installation.md deleted file mode 100644 index 9483cd289d..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/installation/installation.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "Installation" -description: "Installation" -sidebar_position: 20 ---- - -# Installation - -Netwrix Password Policy Enforcer 10.2 is compatible with Windows Servers 2016, 2019, and 2022. It -can also be installed on Windows 8, 10, and 11 workstations to enforce local polices. See the -[Domain and Local Policies](/docs/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.md) -topic for additional information. - -## Windows 2016, 2019, or 2022 - -- Windows 8, 8.1, 10, or 11 -- Fifteen megabytes free disk space -- Eight megabytes free RAM (72 megabytes if using Argon2 hashes) - -:::note -Users don't have to change their password immediately after Password Policy Enforcer is -installed. They can continue using their current password until it expires, even if their current -password doesn't comply with the password policy. Installing Password Policy Enforcer doesn't -extend the Active Directory schema. -::: - - -## Installation Types - -Password Policy Enforcer should be installed onto every domain controller to enforce the password -policy for domain user accounts, or onto individual servers and workstations to enforce the password -policy for local user accounts. - -If your domain contains some read-only domain controllers, then installation of Password Policy -Enforcer on these servers is only necessary if you are using the following features: - -- [Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) -- [Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) -- [Netwrix Password Reset](https://helpcenter.netwrix.com/category/passwordreset) -- [Password Reset](/docs/passwordpolicyenforcer/10.2/administration/password_reset.md) -- [Web](/docs/passwordpolicyenforcer/10.2/web/web_overview.md) - -You can install Password Policy Enforcer manually if you only need to install it on a few computers. -See the -[Manual Installation (Express Setup)](/docs/passwordpolicyenforcer/10.2/administration/installation/manual_installation.md) -topic for additional information. - -It is recommended to perform an automated installation with Group Policy if you need to install it -on many computers in a domain. See the -[Automated Installation (Advanced Setup)](/docs/passwordpolicyenforcer/10.2/administration/installation/automated_installation.md) -topic for additional information. diff --git a/docs/passwordpolicyenforcer/10.2/administration/installation/manual_installation.md b/docs/passwordpolicyenforcer/10.2/administration/installation/manual_installation.md deleted file mode 100644 index 30f11a6aae..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/installation/manual_installation.md +++ /dev/null @@ -1,29 +0,0 @@ ---- -title: "Manual Installation (Express Setup)" -description: "Manual Installation (Express Setup)" -sidebar_position: 20 ---- - -# Manual Installation (Express Setup) - -Manual installation is recommended for small to medium networks. You need to repeat the installation -procedure on every computer that should enforce the password policy. To install Password -Policy Enforcer onto a computer: - -**Step 1 –** Start the Password Policy Enforcer installer (PPE10.2.exe). - -**Step 2 –** Read the license agreement, and then click **Yes** if you accept all the license terms -and conditions. - -**Step 3 –** Select the Express option, and then click **Next**. - -**Step 4 –** Select the **Password Policy Server** checkbox if it isn't selected. - -**Step 5 –** Click **Next** to install Password Policy Enforcer. - -**Step 6 –** Click **Yes** when asked to restart the computer. - -Password Policy Enforcer has its own password rules, so you may want to disable the Windows password -policy rules before configuring Password Policy Enforcer. See the -[Disable Windows Rules](/docs/passwordpolicyenforcer/10.2/administration/installation/disable_windows_rules.md) -topic for additional information. diff --git a/docs/passwordpolicyenforcer/10.2/administration/installation/writeback.md b/docs/passwordpolicyenforcer/10.2/administration/installation/writeback.md deleted file mode 100644 index 63bf099970..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/installation/writeback.md +++ /dev/null @@ -1,19 +0,0 @@ ---- -title: "Enforce Password Reset with Azure Password Writeback" -description: "Enforce Password Reset with Azure Password Writeback" -sidebar_position: 40 ---- - -# Enforce Password Reset with Azure Password Writeback - -You can use Password Policy Enforcer to enforce password policies for passwords reset from Microsoft -Entra ID and O365 by enabling password writeback in Microsoft Entra ID. See the -[How does self-service password reset writeback work in Microsoft Entra ID?](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-writeback) -Microsoft knowledge base article for additional information on password writeback in Microsoft Entra -ID. Password writeback sends all new passwords from Microsoft Entra ID to an available, on-premises -domain controller to check with Password Policy Enforcer. This happens while the user is resetting -their password. See the -[Tutorial: Enable Microsoft Entra self-service password reset writeback to an on-premises environment](https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr-writeback) -and -[How it works: Microsoft Entra self-service password reset](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks#how-it-works-microsoft-entra-self-service-password-reset) Microsoft -knowledge base articles for additional information on password writeback for Microsoft Entra ID. diff --git a/docs/passwordpolicyenforcer/10.2/administration/mailer/_category_.json b/docs/passwordpolicyenforcer/10.2/administration/mailer/_category_.json deleted file mode 100644 index e1bc438e6c..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/mailer/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Mailer", - "position": 120, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "mailer" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/administration/mailer/command_line_interface.md b/docs/passwordpolicyenforcer/10.2/administration/mailer/command_line_interface.md deleted file mode 100644 index c5272bc18a..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/mailer/command_line_interface.md +++ /dev/null @@ -1,24 +0,0 @@ ---- -title: "Command Line Interface" -description: "Command Line Interface" -sidebar_position: 30 ---- - -# Command Line Interface - -You can run the Password Policy Enforcer Mailer from the command line to deliver email immediately, -or to troubleshoot problems. PPEMail.exe is copied into the \Program Files (x86) - -\Password Policy Enforcer\ folder when the Password Policy Enforcer Mailer is installed. - -PPEMail.exe starts a simulation when run without any parameters. It finds users whose password will -expire soon, but no email is sent or saved to the pickup folder. Use the simulation mode to find -common configuration errors that may stop the Password Policy Enforcer Mailer from delivering email. - -Running PPEMail.exe with the /send parameter disables simulation mode. Any emails that are due to be -sent today are sent immediately. PPEMail.exe can identify a wider range of configuration errors when -run in this mode. Use the /send parameter judiciously to avoid sending duplicate emails to users. - -To test email delivery options without sending any emails to users, run PPEMail.exe with the /test -parameter followed by your email address. For example, PPEMail.exe /test johnsmith@netwrix.com. This -sends one test email to your mail server or pickup folder. diff --git a/docs/passwordpolicyenforcer/10.2/administration/mailer/email_delivery_options.md b/docs/passwordpolicyenforcer/10.2/administration/mailer/email_delivery_options.md deleted file mode 100644 index e3363f42f3..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/mailer/email_delivery_options.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Email Delivery Options" -description: "Email Delivery Options" -sidebar_position: 10 ---- - -# Email Delivery Options - -You must configure the email delivery options in the PPS Properties page before the Password Policy -Enforcer Mailer can send email notifications to users. - -Complete the following steps to configure the email delivery options. - -**Step 1 –** Click the **Password Policy Server** item to display the Password Policy Server view. - -**Step 2 –** Click **PPS Properties** in the right pane of the management console. - -**Step 3 –** Click the **Email** tab. - -![the_ppe_mailer](/images/passwordpolicyenforcer/10.2/administration/the_ppe_mailer.webp) - -**Step 4 –** Select the **Disable email reminders** option to disable email delivery. - -Select the **Send email to an SMTP server** option to have the Password Policy Enforcer Mailer send -email notification directly to an SMTP server. Enter the name or IP address of an SMTP server in the -**Server** text box, and the SMTP port number in the **Port** text box. Enter credentials for the -SMTP server in the Username and Password fields. - -Select the **Use TLS** checkbox to enable TLS encryption when using SMTP for email notification -delivery. - -Select the **Save email to a pickup folder** option to have the Password Policy Enforcer Mailer save -emails to a folder for later delivery by a mail server. Click the **Browse** button to select a -folder. The mail server must monitor this folder for new email. - -:::note -Saving email to a pickup folder is the fastest and most reliable delivery method. Use this -option if your mail server supports pickup folders. -::: - - -The Password Policy Enforcer Mailer sends emails at 2:00 AM every day. Check the Windows Application -Event Log to monitor its progress. You can also run the Password Policy Enforcer Mailer from the -command line to send email immediately, or to troubleshoot problems. diff --git a/docs/passwordpolicyenforcer/10.2/administration/mailer/email_message_options.md b/docs/passwordpolicyenforcer/10.2/administration/mailer/email_message_options.md deleted file mode 100644 index 9a1e52615b..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/mailer/email_message_options.md +++ /dev/null @@ -1,61 +0,0 @@ ---- -title: "Email Message Options" -description: "Email Message Options" -sidebar_position: 20 ---- - -# Email Message Options - -Email message options are set for each password policy from the -[Maximum Age Rule](/docs/passwordpolicyenforcer/10.2/administration/rules/maximum_age_rule.md) -rule properties page. Complete the following steps to configure the email message options for a policy. - -**Step 1 –** Click the **Polices** item to display the Polices view. - -**Step 2 –** Double-click the policy you want in the right pane of the management console. - -**Step 3 –** Double-click the **Age (Max)** rule. - -**Step 4 –** Select the **Enabled** checkbox to enable the Maximum Age rule. - -**Step 5 –** Choose a value from the Days and Mode dropdown lists. - -**Step 6 –** Click the **Email** tab. - -![the_ppe_mailer_1](/images/passwordpolicyenforcer/10.2/administration/the_ppe_mailer_1.webp) - -Choose values from the days dropdown lists to specify when to send emails. By default, emails -are sent 14, 7, and 2 days before a user's password expires. - -Choose the first item in a list (blank) to send fewer than three emails. - -Enter the name and email address you want to appear in the email's From field in the **From** text -box. The correct format is `"Display Name" ` - -Enter the text for the email's Subject field in the **Subject** text box. - -Enter the body of the email in the large text box. The email is sent as plain text unless the body -includes the `` tag. If sending email as HTML, you must include the complete HTML document -starting with `` and ending with ``. If the body is too long to fit in the text box, -enter a path to a file like this: - -`file:C:\path\filename.ext` - -The path can contain environment variables like %SystemRoot%. Don't use quotes for long filenames -and don't include any other text. The Password Policy Enforcer Mailer reads the email body from the specified file. - -The email's subject and body can contain various macros. Use these macros to personalize the email. - -| Macro | Replaced with | -| ------------------- | ------------------------------------- | -| [LOGON_NAME] | User's logon name | -| [FIRST_NAME] | User's first name | -| [LAST_NAME] | User's last name | -| [DAYS_TO_EXPIRY] | Days until password expires | -| [EXPIRY_DATE] | Expiry date in short format | -| [EXPIRY_DATE_LONG] | Expiry date in long format | -| [EXPIRY_DAY] | Expiry day (1 to 31) | -| [EXPIRY_DAY_NAME] | Expiry day (Monday, Tuesday, ...) | -| [EXPIRY_MONTH] | Expiry month (1 to 12) | -| [EXPIRY_MONTH_NAME] | Expiry month (January, February, ...) | -| [EXPIRY_YEAR] | Expiry year (2021, 2022, ...) | diff --git a/docs/passwordpolicyenforcer/10.2/administration/mailer/mailer.md b/docs/passwordpolicyenforcer/10.2/administration/mailer/mailer.md deleted file mode 100644 index 6806e2e2e8..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/mailer/mailer.md +++ /dev/null @@ -1,61 +0,0 @@ ---- -title: "Mailer" -description: "Mailer" -sidebar_position: 120 ---- - -# Mailer - -Netwrix Password Policy Enforcer can send email reminders to domain users before their passwords -expire. This is especially useful for users who log on infrequently, and for remote users who access -the network without logging on to the domain. You must install the Password Policy Enforcer Mailer -and configure the email delivery and email message options to send email reminders to users. - -Add your email address to a service account, and the Password Policy Enforcer Mailer will remind you -to change the service account password before it expires. - -## Installing the Mailer - -The Password Policy Enforcer Mailer isn't installed by default. Only install it on one server in -each domain. The Password Policy Enforcer Mailer can be installed on any server, including a domain -controller. - -Complete the following steps to install the Password Policy Enforcer Mailer: - -**Step 1 –** Start the Password Policy Enforcer Installer (PPE10.2.exe). - -**Step 2 –** Read the license agreement, then click **Yes** if you accept all the license terms and -conditions. - -**Step 3 –** Select the **Advanced** option, then click **Next**. - -**Step 4 –** Double-click the **PPE10.2.msi** file. - -**Step 5 –** If you are prompted to Modify, Repair, or Remove the installation, select **Modify**, -then click **Next**. Proceed to step 11. Don't disable the other features as described in the following steps. - -:::warning -If prompted to Modify, Repair, or Remove, don't modify any settings or disable any -features as described in steps 6 - 10. -::: - - -**Step 6 –** Click **Next** when the Password Policy Enforcer Installation Wizard opens. - -**Step 7 –** Select **I accept the license agreement**, then click **Next**. - -**Step 8 –** Select the **Custom** option, then click **Next**. - -**Step 9 –** Click the **icon** beside the Password Policy Server feature, then click the **Entire -feature will be unavailable** button. - -**Step 10 –** Repeat the previous step for the **Management Console**, **Documentation**, and -**Dictionaries** features unless you also want to configure Password Policy Enforcer from this -server. - -**Step 11 –** Click the **icon** beside the Password Policy Enforcer Mailer Service feature, then -click the **Will be installed on local hard drive** button. - -**Step 12 –** Click **Next** twice. - -**Step 13 –** Wait for the Password Policy Enforcer Mailer to install, then click **Finish** twice. diff --git a/docs/passwordpolicyenforcer/10.2/administration/managementconsole/_category_.json b/docs/passwordpolicyenforcer/10.2/administration/managementconsole/_category_.json deleted file mode 100644 index 0b724cc3af..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managementconsole/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Management Console", - "position": 50, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "management_console" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console.md b/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console.md deleted file mode 100644 index fc7dbd9544..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console.md +++ /dev/null @@ -1,65 +0,0 @@ ---- -title: "Management Console" -description: "Management Console" -sidebar_position: 50 ---- - -# Management Console - -This section introduces you to the Password Policy Enforcer management console, and explains how to -configure Password Policy Enforcer's global properties and how to disable and enable Password Policy Enforcer without uninstalling it. - -## Management Console Overview - -The Password Policy Enforcer management console is a Microsoft Management Console snap-in that is -used to edit Password Policy Enforcer's configuration. The management console is installed by -default when Password Policy Enforcer is installed, but you can also install it on your computer if -you want to remotely configure Password Policy Enforcer. - -### Installing the Management Console - -Complete the following steps to install the Password Policy Enforcer management console onto your computer -so that you can remotely configure Password Policy Enforcer. - -**Step 1 –** Start the Password Policy Enforcer installer (PPE10.2.exe). - -**Step 2 –** Read the license agreement and then click **Yes** if you accept all of the license -terms and conditions. - -**Step 3 –** Select the **Advanced** option and then click **Next**. - -**Step 4 –** Double-click the **PPE10.2.msi** file. - -**Step 5 –** Click **Next** when the Password Policy Enforcer installation wizard opens. - -**Step 6 –** Select **I accept the license agreement** and then click **Next**. - -**Step 7 –** Select the **Custom** option, and then click **Next**. - -**Step 8 –** Click the icon beside the Password Policy Server feature, and then click **Entire -feature will be unavailable**. - -![configuring_ppe_0](/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_0.webp) - -**Step 9 –** Click **Next** twice. - -**Step 10 –** Wait for the Management Console to install and then click **Finish**. - -### Opening the Management Console - -Click **Start** > **Netwrix Password Policy Enforcer 10** > **PPE Configuration** to open the -Password Policy Enforcer management console. - -![configuring_ppe_1](/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_1.webp) - -:::note -If you are opening the management console for the first time, click **Yes** when asked if -you would like to create a new Password Policy Enforcer configuration. -::: - - -:::note -Press F1 while using the management console to display help information for the current -window. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console_views.md b/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console_views.md deleted file mode 100644 index ec38c657cc..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console_views.md +++ /dev/null @@ -1,133 +0,0 @@ ---- -title: "Management Console Views" -description: "Management Console Views" -sidebar_position: 10 ---- - -# Management Console Views - -The Password Policy Enforcer management console has four views. Click an item in the left pane of -the management console to select a view. - -## Password Policy Enforcer View - -![configuring_ppe_2](/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_2.webp) - -Click Netwrix Password Policy Enforcer in the left pane to display this view. With this view, you -can perform the following actions: - -- Read the Password Policy Enforcer documentation. -- Connect to configuration. See the - [Connect to a Configuration](/docs/passwordpolicyenforcer/10.2/administration/connecting.md) - topic for additional information. - -## Password Policy Server View - -![configuring_ppe_3](/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_3.webp) - -Click **Password Policy Server** in the left pane to display this view. With this view, you can -perform the following actions: - -- Edit - [PPS Properties Page](/docs/passwordpolicyenforcer/10.2/administration/properties/properties.md) -- Display the [Compromised Password Checker](#compromised-password-checker) page -- Run - [HIBP Updater](/docs/passwordpolicyenforcer/10.2/administration/hibpupdater.md) -- [Connect to a Configuration](/docs/passwordpolicyenforcer/10.2/administration/connecting.md) - to a configuration -- Display the - [Support Tools](/docs/passwordpolicyenforcer/10.2/administration/support_tools.md) - page - -### Compromised Password Checker - -The Compromised Password Checker finds compromised passwords and helps to strengthen them, which -leads to increased security. It checks existing passwords against a compromised hash list at any -time, not only during a password change or reset. - -#### General - -#### ![cpcgeneral](/images/passwordpolicyenforcer/10.2/administration/cpcgeneral.webp) - -- **Enable** – select this checkbox if you want to perform one of the following operations: - - - Notify User – Sends an email to the email address on the user object of an AD user that is - found to have a compromised password. - - Log events in "Event Viewer" – Creates a log entry for each user that has a compromised - password. The log entry can be found in the X log of the event viewer. - - Force password change at next logon – Sets the Force Password Change at next login attribute - on the AD User that was found to have a compromised password. When the user tries to login the - next login, they are prompted to go through the password change process. - -- **Schedule** – Click **Schedule** to open the "Schedule task" window. Choose date and time when the - scan starts and the scan frequency. - - ![supporttoolswindowpasswordcheckerschedule](/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerschedule.webp) - - Set up the scan schedule for Password Checker. You may choose to run it once, or - periodically on a defined schedule. - - - **Frequency** – Select how frequently you want to run Password Checker. - - - **One Time** – There are two options: Run now and Run later. If later, you should select - the time in the **When** area. - - **Daily** – Select the time of day at which you want to run Password Checker. - - **Weekly** – Select the day of the week on which you want to run Password Checker. - - ![supporttoolswindowpasswordcheckerscheduleweekly](/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerscheduleweekly.webp) - - - **Monthly** – Select the day of the month on which you want to run Password Checker. - - ![supporttoolswindowpasswordcheckerschedulemonthly](/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerschedulemonthly.webp) - - - **When** – Select the start date and time when you to run Password Checker. - -- **List of compromised passwords** – The path to the database of compromised passwords. -- **Domain Controller** – Name of the Domain Controller you want to scan with Compromised Password - Checker. The name of the current domain controller can be taken from Configuration Report tab > - Computer value. Use the fully qualified (FQDN) domain controller name. - -#### Report Recipient - -![cpcreportrecipient](/images/passwordpolicyenforcer/10.2/administration/cpcreportrecipient.webp) - -- **To** – Enter the email address of the administrator receiving the full report. -- **From** – Enter the name and email address you want to appear. The correct format is - `"Display Name" ` - -#### User Notification - -![cpcusernotification](/images/passwordpolicyenforcer/10.2/administration/cpcusernotification.webp) - -- **From** – Enter the name and email address you want to appear. The correct format is - `"Display Name" ` -- **Subject** – Enter the subject line of your email. -- **Email** – The text for the message you want to send to the user. The default text contains - information about the recipient's name and account, as well as a request to change the password. - You can customize it any way you want. - -The Compromised Password Checker is now configured to protect your system against compromised -passwords. - -## Policies View - -![configuring_ppe_4](/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_4.webp) - -Click **Password Policy Server** in the left pane to display this view. With this view, you can -perform the following actions: - -- Edit - [Policy Properties](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_properties.md) -- [Testing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/testing_policies.md) -- [Creating a Policy](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/creating_a_policy.md) - and - [Deleting a Policy](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/deleting_a_policy.md) -- Set - [Policy Properties](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_properties.md) - -## Rules View - -#### ![configuring_ppe_5](/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_5.webp) - -Click a **policy name** in the left pane to display this view. Use this view to configure the rules -for a policy. diff --git a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/_category_.json b/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/_category_.json deleted file mode 100644 index 08c533c648..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Managing Policies", - "position": 90, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "managing_policies" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/assigning_policies.md b/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/assigning_policies.md deleted file mode 100644 index db0641ba4e..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/assigning_policies.md +++ /dev/null @@ -1,105 +0,0 @@ ---- -title: "Assigning Policies" -description: "Assigning Policies" -sidebar_position: 40 ---- - -# Assigning Policies - -Password Policy Enforcer uses policy assignments to decide which policy to enforce for each user. -Domain policies can be assigned to users, groups, and containers (Organizational Units). Local -policies can only be assigned to users. See the -[Domain and Local Policies](/docs/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.md) -topic for additional information. - -When a policy is assigned to a group, Password Policy Enforcer enforces the policy for all members -of the group as well as any nested groups. For example, if the Helpdesk group is a member of the -Info Tech group, then any policy assigned to the Info Tech group also applies to the members of the -Helpdesk group. If this behavior isn't desired, then you can assign a different policy to the -Helpdesk group. - -:::note -When a policy is assigned to a container, Password Policy Enforcer enforces the policy for -all users in the container as well as any child containers. For example, if the Helpdesk and -Managers OUs are children of the Info Tech OU, then any policy assigned to the Info Tech OU also -applies to the two child OUs. If this behavior isn't desired, then you can assign a different -policy to a child OU. -::: - - -![managing_policies_3](/images/passwordpolicyenforcer/10.2/administration/managing_policies_3.webp) - -:::note -When a domain policy is assigned to a user or group, Password Policy Enforcer stores the -user or group SID in the configuration. The assignment remains valid even if the user or group is -renamed. When a local policy is assigned to a user, Password Policy Enforcer stores the username in -the configuration. The assignment is invalidated if the user is renamed. -::: - - -![managing_policies_4](/images/passwordpolicyenforcer/10.2/administration/managing_policies_4.webp) - -## Assign a Password Policy - -**Step 1 –** Click the **Policies** item to display the Policies view. - -**Step 2 –** Click the policy you want in the right pane of the management console. - -**Step 3 –** Click **Properties** in the right pane of the management console. - -**Step 4 –** Click the **Assigned To** tab. - -**Step 5 –** Click the **Add...** button corresponding to Users, Groups, or Containers / -Organizational Units. - -**Step 6 –** Select the user, group, or container you want, then click **OK**. - -**Step 7 –** Click **OK** to close the Policy Properties page. - -## Remove a Password Policy - -**Step 1 –** Click the Policies item to display the Policies view. - -**Step 2 –** Click the policy you want in the right pane of the management console. - -**Step 3 –** Click Properties in the right pane of the management console. - -**Step 4 –** Click the Assigned To tab. - -**Step 5 –** Select the policy assignment that you want to remove. - -**Step 6 –** Click the appropriate Remove button. - -**Step 7 –** Click OK to close the Policy Properties page. - -:::note -You can use different assignment types for a single policy. For example, you may assign -users to a policy by both OU and group at the same time. -::: - - -## Policy Assignment Conflicts - -A policy assignment conflict occurs when more than one policy is assigned to a user. Password Policy -Enforcer can resolve these conflicts and choose one policy for each user. - -Password Policy Enforcer first tries to resolve a policy assignment conflict by examining the -assignment type. Assignments by user take precedence over assignments by group, which in turn take -precedence over assignments by container. For example, if Policy A is assigned to a user by group, -and Policy B is assigned to the same user by container, then Password Policy Enforcer will enforce -Policy A because assignments by group take precedence over assignments by container. - -If all the policies are assigned to the user by container, then Password Policy Enforcer enforces -the policy that is assigned to the nearest parent container. For example, if Policy A is assigned to -the Users OU, and Policy B is assigned to the Users\Students OU, then Password Policy Enforcer will -enforce Policy B for all users in the Users\Students and Users\Students\Science OUs because it is -the policy assigned to the nearest parent container. - -If a policy assignment conflict still exists, then Password Policy Enforcer checks the priority of -each remaining policy, and enforces the policy with the highest priority. See the Policy Assignment Conflicts diagram for -a diagrammatic representation of this algorithm. - -Use the Log tab in the Test Policies page to quickly determine which policy Password Policy Enforcer -will enforce for a particular user. - -![managing_policies_5](/images/passwordpolicyenforcer/10.2/administration/managing_policies_5.webp) diff --git a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/creating_a_policy.md b/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/creating_a_policy.md deleted file mode 100644 index 018af34fbb..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/creating_a_policy.md +++ /dev/null @@ -1,68 +0,0 @@ ---- -title: "Creating a Policy" -description: "Creating a Policy" -sidebar_position: 10 ---- - -# Creating a Policy - -There are no password policies defined when Password Policy Enforcer is first installed. Password -Policy Enforcer accepts all passwords in this state, so users only need to comply with the Windows -password policy rules (if enabled). - -**Step 1 –** Click the **Policies** item to display the Policies view. - -**Step 2 –** Click **New Policy** in the right pane of the management console. - -![managing_policies](/images/passwordpolicyenforcer/10.2/evaluation/managing_policies.webp) - -**Step 3 –** Enter a unique policy name in the **New policy name** text box. - -**Step 4 –** If the new policy should inherit its default configuration from an existing policy, -choose a policy from the **Copy settings from** dropdown list. - -**Step 5 –** Optionally, if the new policy should inherit settings from commonly used frameworks, -select an Policy Template from the dropdown list. For a list of policies see -[ Policy Templates ](#policy-templates). - -**Step 6 –** Click **OK**. - -**Step 7 –** Modify the default policy properties as needed. - -**Step 8 –** Click **OK** to close the Policy Properties page, and then configure the rules for this -policy. See the -[Assigning Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/assigning_policies.md) -topic for additional information. - -## Policy Templates - -Password Policy Enforcer v10.1 includes built-in Policy Templates based on the requirements of -the most popular regulatory frameworks. - -- CIS Password Policy Guide — See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- CIS Password Policy Guide MFA — See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- HIPPA — HIPAA Security Rule requires that organizations must implement procedures for creating, - changing, and safeguarding passwords. - - - It also recommends training the workforce on ways to safeguard password information and - establish guidelines to create and change passwords in a periodic cycle. - - HIPAA doesn’t offer any specific password complexity guidelines. To comply with HIPAA, - organizations are better off following NIST password guidelines. - - Most of healthcare institutions use the NIST framework. - -- NERC CIP — See the - [CIP-007-6 — Cyber Security – Systems Security Management](https://www.nerc.com/_layouts/15/PrintStandard.aspx?standardnumber=CIP-007-6&title=Cyber%20Security%20-%20System%20Security%20Management&Jurisdiction=United%20States) article - for additional information. -- NIST 800-63b — See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. -- PCI DSS — See the - [PCI Document Library](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss) web - site for additional information. -- ISO/IEC 27002 — See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. diff --git a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/deleting_a_policy.md b/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/deleting_a_policy.md deleted file mode 100644 index 143a7b907f..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/deleting_a_policy.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -title: "Deleting a Policy" -description: "Deleting a Policy" -sidebar_position: 20 ---- - -# Deleting a Policy - -**Step 1 –** Click the Policies item to display the Policies view. - -**Step 2 –** Click Delete Policy in the right pane of the management console. - -**Step 3 –** Select a policy to delete, and then click **OK**. diff --git a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md b/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md deleted file mode 100644 index 69d80b7b58..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md +++ /dev/null @@ -1,23 +0,0 @@ ---- -title: "Managing Policies" -description: "Managing Policies" -sidebar_position: 90 ---- - -# Managing Policies - -Netwrix Password Policy Enforcer can enforce up to 256 different password policies. You can assign -policies to users directly, or indirectly through Active Directory security groups and containers -(Organizational Units). See the -[Assigning Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/assigning_policies.md) -topic for additional information. - -The following topics explain how to create and configure Password Policy Enforcer password policies: - -- [Creating a Policy](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/creating_a_policy.md) -- [Deleting a Policy](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/deleting_a_policy.md) -- [Policy Properties](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_properties.md) -- [Assigning Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/assigning_policies.md) -- [Policy Priorities](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_priorities.md) -- [Passphrases](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/passphrases.md) -- [Testing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/testing_policies.md) diff --git a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/passphrases.md b/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/passphrases.md deleted file mode 100644 index ad08c13446..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/passphrases.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Passphrases" -description: "Passphrases" -sidebar_position: 60 ---- - -# Passphrases - -Passphrases have gained popularity in recent years as they can be more difficult to crack and easier -to remember than passwords. The difference between passwords and passphrases is their length. -Passwords are rarely longer than 15 characters, but passphrases commonly contain 20 or more -characters. - -Complexity and dictionary rules are less important for passphrases as passphrases rely primarily on -length for security. You may therefore want to relax some password policy requirements for -passphrases. - -![managing_policies_7](/images/passwordpolicyenforcer/10.2/administration/managing_policies_7.webp) - -**Step 1 –** Click the Policies item to display the -[Policies View](/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console_views.md#policies-view). - -**Step 2 –** Click the policy you want in the right pane of the management console. - -**Step 3 –** Click Properties in the right pane of the management console. - -**Step 4 –** Click the Passphrases tab. - -**Step 5 –** Choose the minimum number of characters a password must contain before some rules are -disabled from the dropdown list. - -**Step 6 –** Select the rules to disable. - -**Step 7 –** Click OK to close the Policy Properties page - -Disabled rules aren't counted when calculating the compliance level, but Password Policy Enforcer accepts passphrases that comply with all enabled rules, irrespective of the compliance level. -This ensures that passphrases can be used, even if they don't meet the compliance level when -Password Policy Enforcer is configured to disable one or more rules for passphrases. - -:::note -Opinions differ on how long a passphrase needs to be. Even a 30 character passphrase can -be weaker than a well-chosen password. Don't disable too many rules under the assumption that -length alone makes up for the reduced complexity, as this isn't always true. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_priorities.md b/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_priorities.md deleted file mode 100644 index f027a0cdf3..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_priorities.md +++ /dev/null @@ -1,33 +0,0 @@ ---- -title: "Policy Priorities" -description: "Policy Priorities" -sidebar_position: 50 ---- - -# Policy Priorities - -Policy priorities help Password Policy Enforcer to resolve policy assignment conflicts. If more than -one policy is assigned to a user, and Password Policy Enforcer can't decide which policy to enforce -using the other conflict resolution rules, then Password Policy Enforcer always enforces the policy -with the highest priority. - -**Step 1 –** Click the Policies item to display the Policies view. - -**Step 2 –** Click Set Priorities in the right pane of the management console. This option is only -visible when there is more than one password policy. - -![managing_policies_6_363x434](/images/passwordpolicyenforcer/10.2/administration/managing_policies_6_363x434.webp) - -**Step 3 –** Select the policy you want. - -**Step 4 –** Click the arrow buttons to increase or decrease the priority of the policy. - -**Step 5 –** Click OK to close the Policy Priorities page. - -## Policy Selection Flowchart - -This flowchart shows how Password Policy Enforcer chooses a policy for each user. Use the Test -Policies page to quickly determine which policy Password Policy Enforcer enforces for a -particular user. - -![managing_policies](/images/passwordpolicyenforcer/10.2/administration/managing_policies.webp) diff --git a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_properties.md b/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_properties.md deleted file mode 100644 index 46e0db5946..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_properties.md +++ /dev/null @@ -1,110 +0,0 @@ ---- -title: "Policy Properties" -description: "Policy Properties" -sidebar_position: 30 ---- - -# Policy Properties - -![managing_policies_1](/images/passwordpolicyenforcer/10.2/administration/managing_policies_1.webp) - -**Step 1 –** Click the **Policies** item to display the Policies view. - -**Step 2 –** Click the policy you want in the right pane of the management console. - -**Step 3 –** Click **Properties** in the right pane of the management console. - -Each Password Policy Enforcer policy must have a unique name. To change the name of a policy, type -the new name in the text box beside the policy icon. - -Password Policy Enforcer only enforces enabled policies. Select the **Enabled** checkbox if -Password Policy Enforcer should enforce this policy, or deselect it to disable the policy. The -policy's icon in the left pane of the management console changes to an X icon when a policy is -disabled. - -:::note -A user's password history may be updated even when the policy assigned to the user is -disabled. See the -[Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) -topic for additional information. -::: - - -The **Default character set** dropdown list specifies which character set Password Policy -Enforcer will use to enforce its rules. The default value (Netwrix Password Policy -Enforcer) requires users to comply with rules that use the Password Policy Enforcer character set. -Choose the alternate option (Windows) to have users comply with rules that use the Windows character -set. - -:::note -Only Password Policy Enforcer 10.0 and later contain the Windows character set. Password Policy Enforcer 9, Netwrix Password Reset, and Password Policy Enforcer/Web 7 (and older for all products) always use the Password Policy Enforcer character set. -::: - - -:::warning -This value shouldn't be changed while using PPE9.x clients, APR 3.x and Password -Policy Enforcer/Web 7.x (and older for all above). These clients only support the Password Policy -Enforcer character set. They will work if Password Policy Enforcer is configured to use the Windows -character sets, but they will still continue to use the Password Policy Enforcer character set as -that is all they know. -::: - - -- Some languages such as Japanese don't distinguish between uppercase and lowercase. These - characters are in the Windows Alpha set, but not in the Upper or Lower sets. -- Characters classified as a space, punctuation, control, or blank by Windows are included in the - Special character set. If these characters are also included in some other set by Windows (for - example, a superscript one is both a decimal digit and punctuation), then Password Policy Enforcer - only includes them in the Special character set when the Windows character set is selected. -- When using the Password Policy Enforcer character set, all characters above ANSI 126 are included - in the High set. When using the Windows character set, a character is only included in the High - set if it is above ANSI 126 and not included in any other set by Windows. - -The **Reject passwords that don't comply with** dropdown list specifies the required compliance -level for this policy. The default value (all the rules) requires users to comply with all enabled -rules. Choose an alternative option if Password Policy Enforcer should enforce a more lenient -password policy. The Minimum Age and Maximum Age rules are excluded from compliance level -calculations. See the -[Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) -topic for additional information. - -When setting the compliance level, consider that some rules may be disabled when a user enters a -passphrase. See the Passphrases tab for additional information. Password Policy Enforcer -accepts passphrases that comply with all enabled rules, irrespective of the compliance level. This -ensures that passphrases can be used, even if they don't meet the compliance level when Password -Policy Enforcer is configured to disable one or more rules for passphrases. - -Password Policy Enforcer can start a password synchronization application or script whenever a user -successfully changes their password. Enter the full path to the executable in the **Execute this -program when a password is changed** text box. The path can contain environment variables like -`%SystemRoot%`. Every computer running Password Policy Enforcer should have a local copy of the -program, and only authorized users should have access to it, or any of its components. - -Password Policy Enforcer sends the user logon name and new password to the program as command-line parameters. For -example, if you add the following commands to a batch file, Password Policy Enforcer records each user's logon name and new password in a text file called passwords.txt: - -**echo Username: %1 >> c:\passwords.txt** - -echo Password: %2 >> c:\passwords.txt - -:::warning -This script is shown as an example only. You shouldn't store user passwords. -::: - - -The command can now include the [USERNAME] and [PASSWORD] macros. If neither is specified, then the -command is executed with both parameters to maintain compatibility with existing programs/scripts. - -:::info -Use the [USERNAME] parameter if the password isn't needed by the program/script -so that the password isn't unnecessarily sent to the change notification command/script. -::: - - -Record any configuration notes about this policy in the Notes text box. - -- Click the **Assigned To** tab to assign this policy to users, groups, or containers. -- Click the **Passphrases** tab to specify which rules should be disabled when a user enters a - passphrase. -- Click the **Messages** tab to customize the Password Policy Client message templates for this - policy. diff --git a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/testing_policies.md b/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/testing_policies.md deleted file mode 100644 index 77fc631edc..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/testing_policies.md +++ /dev/null @@ -1,121 +0,0 @@ ---- -title: "Testing Policies" -description: "Testing Policies" -sidebar_position: 70 ---- - -# Testing Policies - -You can quickly test your Password Policy Enforcer configuration by simulating a password change -from the Password Policy Enforcer management console. - -## Password Test - -Complete the following steps to test your configuration. - -**Step 1 –** Click the **Policies** item to display the Policies view. - -**Step 2 –** Click **Test Policies** in the right pane of the management console. - -![passwordtest](/images/passwordpolicyenforcer/10.2/administration/passwordtest.webp) - -**Step 3 –** Select the **Password** Test tab. - -**Step 4 –** Enter a **user name** in the User name text box, and a password in the Old Password and -New Password text boxes. - -**Step 5 –** Click **Test**, or wait a few seconds if Test passwords as I type is selected. - -:::note -Policy testing simulates a password change, but it doesn't change the password. As it is -only a simulation, you don't have to enter the correct password in the Old Password text box. -::: - - -The Password Policy Enforcer management console displays a green check mark below the Test button if -the new password complies with the Password Policy Enforcer password policy, or a red cross if it -doesn't comply. Detailed test results appear in the results panel. - -**Step 6 –** Click the **Results** tab to view the test results for each rule. The check boxes show -which rules the new password complied with. - -| Rule | Status of Password Compliance with Rule | -| ------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- | -| ![testing_the_password_policy_1](/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_1.webp) | Rule disabled or not tested. | -| ![testing_the_password_policy_2](/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_2.webp) | Rule enabled, password complies with rule | -| ![testing_the_password_policy_3](/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_3.webp) | Rule enabled, password doesn't comply with rule. | - -![managing_policies_12](/images/passwordpolicyenforcer/10.2/administration/managing_policies_12.webp) - -**Step 7 –** Click the **Log** tab to view Password Policy Enforcer's internal event log. The event -log can help you to understand why Password Policy Enforcer accepted or rejected a password. For -example, you can use the event log to see which: - -- Computer the configuration was read from. -- Policy was assigned to the user, and why. -- Dictionary word or keyboard pattern matched with the password. -- Errors or warnings occurred during testing. - -## Bulk Password Test - -Bulk Password Test feature allows to check a large number of passwords against a selected policy and -a get a report of the accepted and rejected passwords. - -![bulkpasswordtest](/images/passwordpolicyenforcer/10.2/administration/bulkpasswordtest.webp) - -Complete the following steps to test your configuration. - -**Step 1 –** Click the **Policies** item to display the Policies view. - -**Step 2 –** Click **Test Policies** in the right pane of the management console. - -**Step 3 –** Select the location of the password file. - -**Step 4 –** Select the location of the folder where you want to upload the result. - -:::note -Keep the Password File and Result folder on a local drive, not a shared drive, for faster processing. -::: - - -**Step 5 –** Select a desired policy from the dropdown list. - -**Step 6 –** To receive a list of unacceptable passwords, use the following filters: - -- Show compliant passwords – displays compliant passwords. -- Show rejected passwords – displays rejected passwords. - -**Step 7 –** Click the **Run** button. - -Statistics shows the file line size, the number of passwords processed, and the result -of processing each line. Click the filters you want to show compliant and/or rejected passwords. - -| Statistics of the Bulk Password Testing | | -| --------------------------------------- | ------------------------------------------------------------------------------------------------------- | -| Status | Shows whether the operation is ready for scanning, processing, or whether the scan has been terminated. | -| Accepted | Shows the number of the accepted passwords. | -| Number of lines | Shows the number of lines within the password. | -| Checked | Shows the number of the checked passwords. | -| Rejected | Shows the number of the rejected passwords. | -| Lines processed | Shows the number of the processed lines. | - -## Policy Testing vs. Password Changes - -- Policy testing simulates a password change, but it may not always reflect what happens when a user - changes their password. A password change may yield different results to a policy test because: -- Policy testing doesn't simulate the Windows password policy rules. If the Windows password rules - are enabled, then Windows may reject a password even though it complies with all the Password - Policy Enforcer rules. -- Policy testing doesn't enforce the Minimum Age rule. -- Policy testing doesn't enforce the History rule. -- Policy testing enforces the password policy even if Password Policy Enforcer or the assigned - policy is disabled. Use this to test your configuration before enabling Password Policy - Enforcer, or a new password policy. -- Policy testing occurs on the computer that the management console is running on. If the management - console is connected to a remote domain configuration, then it may not find the dictionary file on - the local computer, or the local dictionary file may be different to the one on the domain - controller. Copy the dictionary file onto the local computer (in the same path) to avoid this - problem. -- If the management console is connected to a domain configuration and the Password Policy Enforcer - configuration was modified recently, then Active Directory may still be propagating the new - configuration to the other domain controllers. diff --git a/docs/passwordpolicyenforcer/10.2/administration/password_reset.md b/docs/passwordpolicyenforcer/10.2/administration/password_reset.md deleted file mode 100644 index af20bc1c44..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/password_reset.md +++ /dev/null @@ -1,24 +0,0 @@ ---- -title: "Netwrix Password Reset and Web" -description: "Netwrix Password Reset and Web" -sidebar_position: 160 ---- - -# Netwrix Password Reset and Web - -With Netwrix Password Reset and Web, users can securely manage their passwords from a web browser. -Both products integrate with Netwrix Password Policy Enforcer to ensure that passwords comply with -the password policy, and to help users choose compliant passwords. - -Password Reset is a self-service password management system. Users can change their -password, reset a forgotten password, and unlock their account without calling the helpdesk. It -includes the Password Reset Client, which gives users access to APR from the Windows Logon and -Unlock screens. - -The [Web](/docs/passwordpolicyenforcer/10.2/web/web_overview.md) -application lets users change their password from a web browser. - -Visit [www.netwrix.com](https://www.netwrix.com/password_policy_enforcer.html) -to download an evaluation copy. - -![netwrix_password_reset_and_ppe_1105x808](/images/passwordpolicyenforcer/10.2/evaluation/netwrix_password_reset_and_ppe_1105x808.webp) diff --git a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/_category_.json b/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/_category_.json deleted file mode 100644 index b92d29d447..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Password Policy Client", - "position": 110, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "password_policy_client" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/configuring_the_password_policy_client.md b/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/configuring_the_password_policy_client.md deleted file mode 100644 index f5ae663ff1..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/configuring_the_password_policy_client.md +++ /dev/null @@ -1,112 +0,0 @@ ---- -title: "Configuring the Password Policy Client" -description: "Configuring the Password Policy Client" -sidebar_position: 20 ---- - -# Configuring the Password Policy Client - -The Password Policy Client is self-configuring and doesn't require manual configuration in most -cases. You may need to manually configure the Password Policy Client if: - -- You want to install it in a disabled state to be enabled later. -- You want to change the display settings for small screens. -- The Password Policy Client displays policy messages in the wrong language. -- The default communication settings aren't suitable (for example, if you change the default - Password Policy Server Port). - -Password Policy Enforcer includes an administrative template to help configure the Password Policy -Client. You can use Active Directory GPOs to configure many computers, or the Local Group Policy -Editor to configure one computer. The Password Policy Client configuration is stored in the -HKLM\SOFTWARE\Policies\ANIXIS\Password Policy Client\ registry key. - -**Install the Password Policy Client Administrative Template** - -**Step 1 –** Connect to any Domain Controller where you have Password Policy Enforcer installed and -have the group policy management console available. - -**Step 2 –** Go to Password Policy Enforcer install directory (C:\Program Files (x86)\Password -Policy Enforcer) and copy the following two files (highlighted in yellow): - -![ppc_configuration](/images/passwordpolicyenforcer/10.2/administration/ppc_configuration.webp) - -**Step 3 –** Go to C:\Windows\Policy Definitions and paste the .admx file in the root of this -folder. - -![ppc_configuration2](/images/passwordpolicyenforcer/10.2/administration/ppc_configuration2.webp) - -**Step 4 –** Go to C:\Windows\Policy Definitions\en-US and paste the .adml file in the root of this -folder. - -![ppc_configuration1](/images/passwordpolicyenforcer/10.2/administration/ppc_configuration1.webp) - -**Step 5 –** Open **Group Policy Management** console and check if you have a GPO created for -Client. If not, see the -[Installing Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/installing_password_policy_client.md) -topic's -[Edit the Group Policy Object](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/installing_password_policy_client.md#edit-the-group-policy-object) -section for additional information. - -**Step 6 –** In the left pane, navigate to **Forest: ``** > **Domain** > -**``**, right-click **``** and select **Create a GPO** in this domain and Link -it here. - -After the GPO is configured, it has the following view: - -![ppc_configuration3](/images/passwordpolicyenforcer/10.2/administration/ppc_configuration3.webp) - -**Step 7 –** Right-click the newly created GPO and select **Edit** from the pop-up menu. - -**Step 8 –** Expand **Computer Configuration** > **Policies** > **Administrative Templates** > -**Netwrix Password Policy Enforcer** - -![ppc_configuration4](/images/passwordpolicyenforcer/10.2/administration/ppc_configuration4.webp) - -**Step 9 –** Click **Netwrix Password Policy Client** to open a list of modification settings -with brief descriptions of each. - -![ppc_configuration5](/images/passwordpolicyenforcer/10.2/administration/ppc_configuration5.webp) - -**Step 10 –** Select the one you need, then modify and save it. - -## Changing the Default Display Settings - -The Windows 10 and 11 Change Password screen has less space for the Password Policy message than -earlier Windows versions. Users may need to scroll to see the message if their screen is small, or -if their computer is set to use large fonts. - -The Password Policy Client for Windows 10 and 11 maximizes the available screen space by hiding -non-essential user interface elements on small screens. It can also display the Password Policy -message in a message box to draw attention to the password policy. - -![the_password_policy_client_3](/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_3.webp) - -You can change the default display settings to control which user interface elements are hidden, and -the point at which they are hidden. The display of the Password Policy message box is also -configurable. - -Complete the following steps to change the default display settings for the Password Policy Client on -Windows 10 and 11. - -**Step 1 –** Use the **Group Policy Management Console** (gpmc.msc) to display the GPOs linked at -the domain level. - -:::note -If you aren't using Active Directory, then open the Local Group Policy Editor -(gpedit.msc) and skip step 2. -::: - - -**Step 2 –** Right-click the **Password Policy Client GPO**, then click the **Edit...** button. - -**Step 3 –** Expand the **Computer Configuration**, **Policies** (if visible), **Administrative -Templates**, **Classic Administrative Templates** (**ADM**), **Password Policy Enforcer**, and -**Password Policy Client** items. - -**Step 4 –** Double-click the **Display settings (Windows 10)** setting in the right pane of the -Group Policy Management Editor. - -:::note -Information about each option is shown in the Help box. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/customizing_message_templates.md b/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/customizing_message_templates.md deleted file mode 100644 index b43734f713..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/customizing_message_templates.md +++ /dev/null @@ -1,81 +0,0 @@ ---- -title: "Customizing Message Templates" -description: "Customizing Message Templates" -sidebar_position: 40 ---- - -# Customizing Message Templates - -Each Password Policy Enforcer password policy has three message templates, one for each of the -Password Policy Client messages. - -- Password Policy — Displays the password policy guidelines on clients that have the Netwrix - Password Policy Enforcer Client installed -- Rejection Reason — Displays why an intended password was rejected on clients that have the Netwrix - Password Policy Enforcer Client installed -- Generic Rejection — Displays if Password Policy Enforcer doesn't have a specific reason for the - rejection, generally because the password doesn't comply with the Windows password policy - -Complete the following steps to edit a policy's message templates. - -**Step 1 –** Click the **Policies** item to display the Policies view. - -![customizing_message_templates_1](/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_1.webp) - -**Step 2 –** Click the policy you want in the right pane of the management console. - -![customizing_message_templates_2](/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_2.webp) - -**Step 3 –** Right-click the policy you want to display the policy Settings page. Click -**Properties**. - -![customizing_message_templates_3](/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_3.webp) - -**Step 4 –** Click the **Messages** tab. - -![customizing_message_templates_4](/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_4.webp) - -**Step 5 –** Choose a language from the Language dropdown list. - -![customizing_message_templates_5](/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_5.webp) - -**Step 6 –** Edit the message templates in the Password Policy, Rejection Reason, and Generic -Rejection text boxes, as needed. - -## Customizing Password Policy Client Messages - -The Password Policy Client displays three messages to help users choose a password: - -- The Password Policy message is shown as the user changes their password. This message explains the - password policy to the user. -- The Rejection Reason message is shown if a password doesn't comply with the Password Policy - Enforcer password policy. This message tells the user why their password was rejected. -- The Generic Rejection message is shown if Password Policy Enforcer doesn't have a specific reason - for the rejection, generally because the password doesn't comply with the Windows password - policy. - -### Password Policy Client Message Components - -Password Policy Client messages are built using templates, macros, and inserts. The following image -shows a sample policy message with the template in blue, a macro in green, and policy inserts in -white. - -![the_password_policy_client_2](/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_2.webp) - -### Live Password Message - -You can configure Password Policy Client messages to display live feedback to end users as they -enter their passwords. With this feature, users can see whether their passwords meet the requirements of -the policy set by the organization. The following image illustrates an example of a live policy message. - -![livepolicymessageexample](/images/passwordpolicyenforcer/10.2/administration/livepolicymessageexample.webp) - -:::note -The password client needs to be at version 10.2+ to support this capability. -::: - - -To support password live messages the password policy message must include the [Live_Policy] -declaration in the Password Policy Message. - -![policypropertieswindow](/images/passwordpolicyenforcer/10.2/administration/policypropertieswindow.webp) diff --git a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/customizing_rule_inserts.md b/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/customizing_rule_inserts.md deleted file mode 100644 index 61dddd3085..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/customizing_rule_inserts.md +++ /dev/null @@ -1,65 +0,0 @@ ---- -title: "Customizing Rule Inserts" -description: "Customizing Rule Inserts" -sidebar_position: 30 ---- - -# Customizing Rule Inserts - -Rule inserts allow the Password Policy and Rejection Reason messages to display the most appropriate -information for each user. Most Password Policy Enforcer rules have a Policy and Reason insert. The -The [POLICY] macro uses the Policy insert, and the [REASON] macro uses the Reason insert. - -Complete the following steps to edit a rule's inserts. - -**Step 1 –** Click the **Policies** item to display the Policies view. - -![customizing_rule_inserts_1](/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_1.webp) - -**Step 2 –** Click the policy you want in the right pane of the management console. In this -example it is Policy 1. - -![customizing_rule_inserts_2](/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_2.webp) - -**Step 3 –** Double-click the rule you want to display the Rule Properties page. In this example -it is a -[Compromised Rule](/docs/passwordpolicyenforcer/10.2/administration/rules/compromised_rule.md). - -![customizing_rule_inserts_3](/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_3.webp) - -**Step 4 –** Click the **Messages** tab. - -![customizing_rule_inserts_4](/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_4.webp) - -**Step 5 –** Choose a language from the Language list. - -![customizing_rule_inserts_5](/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_5.webp) - -**Step 6 –** Edit the rule inserts in the Policy and Reason text boxes. - -:::note -Use the \n escape sequence to start a new line in a message template or rule insert -(Password Policy Client V5.1 and later). Inserts and lines starting with two or more spaces, a -minus, and a space are shown with a bullet to the left (Password Policy Client V8.0 and later). -::: - - -## Customizing Password Policy Client Messages - -The Password Policy Client displays three messages to help users choose a password: - -- The Password Policy message is shown as the user changes their password. This message explains the - password policy to the user. -- The Rejection Reason message is shown if a password doesn't comply with the Password Policy - Enforcer password policy. This message tells the user why their password was rejected. -- The Generic Rejection message is shown if Password Policy Enforcer doesn't have a specific reason - for the rejection, generally because the password doesn't comply with the Windows password - policy. - -### Password Policy Client Message Components - -Password Policy Client messages are built using templates, macros, and inserts. The following image -shows a sample policy message with the template in blue, a macro in green, and policy inserts in -white. - -![the_password_policy_client_2](/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_2.webp) diff --git a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/installing_password_policy_client.md b/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/installing_password_policy_client.md deleted file mode 100644 index b2d3e22afa..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/installing_password_policy_client.md +++ /dev/null @@ -1,209 +0,0 @@ ---- -title: "Installing Password Policy Client" -description: "Installing Password Policy Client" -sidebar_position: 10 ---- - -# Installing Password Policy Client - -The Password Policy Client is compatible with Windows 8, 8.1, 10, or 11. It is also compatible with -Windows Server 2016, 2019, and 2022. The Password Policy Client can be used with Remote Desktop -Services on these operating systems. - -:::note -The Password Policy Client is also compatible with Windows XP, Vista, and 7. However, -Netwrix no longer provides technical support for these versions. -::: - - -## System Requirements - -- Windows 8, 8.1, 10, or 11. -- Windows Server 2016, 2019, and 2022 -- One Megabyte free disk space. -- 256 Kilobytes free RAM (per session if using Remote Desktop Services). - -You can install the Password Policy Client manually by running the Password Policy Enforcer -installer (PPE10.2.exe) and choosing the Express Setup option if you only need to install it on a -few computers. If you have many computers, then follow the following instructions to perform an -automated installation with Group Policy, or use your regular software distribution tool to do the -same. - -## Create a Distribution Point - -A distribution point can either be a UNC path to a server share, or a DFS (Distributed File System) -path. You can use the distribution point you created earlier for Password Policy Enforcer to -distribute the Password Policy Client. See the -[Installation](/docs/passwordpolicyenforcer/10.2/administration/installation/installation.md) -topic for additional information. - -If you didn't create a distribution point for Password Policy Enforcer, then create one now. - -Complete the following steps to create a Password Policy Client distribution point. - -**Step 1 –** Log on to a server as an administrator. - -**Step 2 –** Create a shared network folder to distribute the files from. - -**Step 3 –** Give the **Domain Computers** security group read access to the share, and limit write -access to authorized personnel only. - -### Copy PPECIt10.2.msi into the Distribution Point - -Complete the following steps to copy the .msi file into the distribution point. - -**Step 1 –** Start the Password Policy Enforcer installer (PPE10.2.exe). - -**Step 2 –** Read the license agreement, and then click **Yes** if you accept all the license terms -and conditions. - -**Step 3 –** Select the **Advanced** option, then click **Next**. - -**Step 4 –** Right-click the **PPEClt10.2.msi** icon, click **Copy**, and then paste the file into -the distribution point. - -![the_password_policy_client](/images/passwordpolicyenforcer/10.2/administration/installing_ppe.webp) - -**Step 5 –** Give the **Domain Computers** security group read access to the PPEClt10.2.msi file in -the distribution point. - -**Step 6 –** Click **Finish**. - -## Create a Group Policy Object - -Complete the following steps to create a group policy object. - -**Step 1 –** Start the **Group Policy Management Console** (gpmc.msc). - -**Step 2 –** Expand the **forest** and **domain** items in the left pane. - -**Step 3 –** Right-click the **domain root node** in the left pane, and then click **Create a GPO in -this domain, and Link it here...**. - -**Step 4 –** Enter **Password Policy Client** in the provided field, then press **ENTER**. - -![the_password_policy_client_1](/images/passwordpolicyenforcer/10.2/administration/ppe1.webp) - -## Edit the Group Policy Object - -Complete the following steps to edit a group policy object. - -**Step 1 –** Right-click the **Password Policy Client GPO**, then click the **Edit...** edit. - -**Step 2 –** Expand the **Computer Configuration**, **Policies**, and **Software Settings** items in -the left pane. - -**Step 3 –** Right-click the **Software installation** item, then select **New** > **Package...**. - -**Step 4 –** Enter the full **UNC path to PPEClt10.2.msi** in the Open dialog box. - -:::note -You must enter a UNC path so that other computers can access this file over the network. -For example, `\\file server\distribution point share\PPEClt10.2.msi` -::: - - -**Step 5 –** Click **Open**. - -**Step 6 –** Select the **Assigned deployment method**, then click **OK**. - -![the_password_policy_client_2](/images/passwordpolicyenforcer/10.2/administration/installing_ppe_2.webp) - -**Step 7 –** Close the **Group Policy Management Editor**. - -## Complete the Installation - -Restart each computer to complete the installation. Windows installs the Password Policy Client -during startup. - -## Testing the Password Policy Client - -Test the Password Policy Client by logging on to a computer and pressing the CTRL + ALT + DEL keys -and clicking the **Change a password** item. If you don't see the password policy, it could be -because a Password Policy Enforcer policy hasn't been assigned to you, or because the firewall -rules haven't been created. - -:::note -The Password Policy Client doesn't store or send passwords or password hashes over the -network. An attacker can't determine user passwords by sniffing the communication protocol. The -protocol is also encrypted by default for additional protection. -::: - - -## Creating Firewall Rules for the Password Policy Client - -You may need to create firewall rules for the Password Policy Client if your domain controllers are -running a software (host) firewall, or if the Password Policy Client and Password Policy Server -communicate through a firewall. Firewall rules aren't necessary for local policies because the -Password Policy Client and Password Policy Server are on the same computer. - -### Windows Firewall - -If Windows Firewall is enabled on your domain controllers, then you must create a port exception to -allow connections to the Password Policy Server. Windows Firewall is enabled by default on Windows -Server 2008 and later. - -Complete the following steps to create the port exception on all domain controllers. - -**Step 1 –** Use the **Group Policy Management Console** (gpmc.msc) to display the GPOs linked to -the Domain Controllers OU. - -**Step 2 –** Right-click the **Password Policy Enforcer GPO**, and then click **Edit...**. - -:::note -You need to create the GPO if you chose the Express Setup option. -::: - - -**Step 3 –** Expand the **Computer Configuration**, **Policies**, **Administrative Templates**, -**Network**, **Network Connections**, and **Windows Firewall** items. - -**Step 4 –** Click **Domain Profile** in the left pane then double-click **Windows Firewall: Define -inbound port exceptions** in the right pane. - -![the_password_policy_client_3](/images/passwordpolicyenforcer/10.2/administration/ppe2.webp) - -**Step 5 –** Select the **Enabled** option, and then click **Show...**. - -![the_password_policy_client_4](/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_4.webp) - -**Step 6 –** Select the **Enabled** option, and then click **Show...**. - -![the_password_policy_client_5](/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_5.webp) - -**Step 7 –** Click **OK** until you return to the Group Policy Management Editor. - -**Step 8 –** Close the **Group Policy Management Editor**. - -### Other Firewalls - -Use the information on this page to create appropriate rules for your firewall that allow the -Password Policy Client and Password Policy Server to communicate through the firewall. - -The Password Policy Client initiates a request by sending a datagram with the following attributes -to the Password Policy Server: - -| Attribute | Result | -| ------------------- | ---------------------------- | -| Protocol | UDP | -| Source Address | Client Computer IP address | -| Source Port | Any | -| Destination address | Domain controller IP address | -| Destination port | 1333 | - -The Password Policy Server responds by sending a datagram with the following attributes back to the -Password Policy Client: - -| Attribute | Result | -| ------------------- | ---------------------------- | -| Protocol | UDP | -| Source Address | Domain controller IP address | -| Source Port | Any | -| Destination address | Client Computer IP address | -| Destination port | Any | - -:::note -If your firewall performs Stateful Packet Inspection, then only create a rule for the -request datagram as the firewall will automatically recognize and allow the response datagram. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/multilingual_messages.md b/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/multilingual_messages.md deleted file mode 100644 index bf1ef881da..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/multilingual_messages.md +++ /dev/null @@ -1,29 +0,0 @@ ---- -title: "Multilingual Messages" -description: "Multilingual Messages" -sidebar_position: 50 ---- - -# Multilingual Messages - -The Password Policy Client initially displays all messages in English, but you can configure it to -display messages in 30 other languages. - -Complete the following steps to configure Password Policy Client for another language. - -**Step 1 –** Configure message templates for the new language (see [Customizing Message Templates](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/customizing_message_templates.md)). - -**Step 2 –** Configure rule inserts for each enabled rule (see [Customizing Rule Inserts](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/customizing_rule_inserts.md)). - -![the_password_policy_client_6](/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_6.webp) - -![the_password_policy_client_7](/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_7.webp) - -The Password Policy Client uses the Windows client language settings to determine which language to -display. - -:::note -You don't have to create a Password Policy Enforcer policy for each language. Each policy -can have messages defined in multiple languages. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md b/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md deleted file mode 100644 index 0ad0b69122..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: "Password Policy Client" -description: "Password Policy Client" -sidebar_position: 110 ---- - -# Password Policy Client - -The Password Policy Client helps users to choose a compliant password. You don't have to install -the Password Policy Client to use Password Policy Enforcer, but the -[Similarity Rule](/docs/passwordpolicyenforcer/10.2/administration/rules/similarity_rule.md) -is only enforced if the Password Policy Client is installed. - -The Password Policy Client helps users to choose a compliant password by explaining the password -policy to them, and by telling them why their password was rejected. If the Password Policy Client -isn't installed, then users will see the default Windows error message when their password is -rejected. - -![the_password_policy_client](/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client.webp) - -![the_password_policy_client_1](/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_1.webp) - -The Password Policy Client displays the password policy during a password change so that users can -see the policy while they choose their password. The Password Policy Client also displays a detailed -rejection message to explain why a password was rejected. Both these messages are customizable. - -:::note -The Password Policy Client doesn't modify any Windows system files. It also doesn't send -passwords or password hashes over the network. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/ppe_tool.md b/docs/passwordpolicyenforcer/10.2/administration/ppe_tool.md deleted file mode 100644 index 278c301664..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/ppe_tool.md +++ /dev/null @@ -1,183 +0,0 @@ ---- -title: "PPE Tool" -description: "PPE Tool" -sidebar_position: 130 ---- - -# PPE Tool - -The PPE Tool is designed to configure local and domain instances of Password Policy Enforcer and -produce reports pertaining to the configuration of Password Policy Enforcer. The PPE Tool is -designed to perform the following functions: - -- Export the configuration from the existing instance of Password Policy Enforcer, regardless if the - server is local or domain. -- Import existing PPE configurations on another PPE server instance. -- Generate user-friendly reports that contain configuration values and descriptions. -- Create HTML reports with configuration values and descriptions of the PPE server instance. - -This topic covers how to install the PPE Tool, customize, and run reports, and review configuration -options in the PPE Tool. - -## Using the PPE Tool - -The PPE Tool installs with the default installation of Password Policy Enforcer under the -`C:\Program Files (x86)\Password Policy Enforcer\ppetool` folder. Once installed, the PPE Tool -supports the following operations related to Password Policy Enforcer functionality. - -:::note -All PPE Tool operations can be executed from the Command Prompt, if run with administrator -rights. -::: - - -### PPE Tool Operations - -:::info -PPE Tool operations should only be executed one at a time. For example, you -shouldn't execute the /e (Export) and /i (Import) operations simultaneously; you shouldn't run /e -(Export) and /r (Report) operations simultaneously. -::: - - -**Common PPE Tool Operations** - -| Operation | Operation Name | Operation Description | -| --------- | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| /? | help |
  • Displays Help and exits the application. All other options are ignored.
| -| /m | minimal |
  • Configures the PPE Tool to operate in Minimal mode.
  • This operation strips away all extraneous information (e.g., policy messages, license information, etc.) while importing or exporting to the PPE Tool.
  • By default, the PPE Tool imports and exports all information available (e.g., policy messages, license information, etc.).
| -| /d | domain [in controller] |
  • Configures the PPE Tool to operate in Domain mode.
  • The default controller is localhost.
  • This operation makes PPE Tool work with the LDAP Password Policy Enforcer instance. PPE Tool imports or exports configurations from the local registry.
  • To use this operation , you must run PPE Tool as a domain administrator user. However, this operation can be used on both the domain controller and on any member. If an invalid domain controller is provided as an argument, then the PPE Tool will fail at the import / export stage.
  • This operation is ignored when used to create reports from the file source (present with the /c (Config [in file name]) option). When the PPE Tool starts in a domain environment without the /d (Domain [in controller]) operation, a warning message appears. However, this won't prevent the PPE Tool from operating on a local environment.
| -| /c | config [in file name] |
  • Uses a config file instead of Password Policy Enforcer export when exporting reports (in the case of /i (Import), /h (Human [out file name]), and /r (Report [out file name]).
  • The default file is `config.xml`.
  • This operation defines the input file for the i/ (Import) operation, and thus is necessary for importing files to the PPE Tool. An error message will appear if the /c (Config [in file name]) option is omitted.
  • By default, the /h (Human [out file name]) and /r (Report [out file name]) operations use the Password Policy Enforcer instance as the reporting source. The /c (Config [in file name]) operation should provide the source configuration file as an argument to create reports. If an invalid file name is provided as an argument in this operation, the PPE Tool displays the appropriate error message and exits.
| - - -Operations PPE Tool options are as follows: - -| Task | Task Name | Task Description | -| ---- | ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| /e | export [out file name] |
  • Exports config data (default) from the Password Policy Enforcer instance to the file.
  • This operations is enabled by default.
  • This operation can't be used with /c (Config [in file name]) or i/ (Import) operations, but can be combined with /h (Human [out file name]).
| -| /i | import |
  • Imports the config file.
  • Imports existing configuration using the input configuration file defined by the /d (Domain [in controller]) . If the /c (Config [in file name]) operation is omitted, the PPE Tool displays an error message and exits.
  • When i/ (Import) is used with the /h (Human [out file name]) or /r (Report [out file name]) operations, the latter is ignored.
  • /d (Domain [in controller]) and /m (Minimal) operations may affect the result of the import.
| -| /h | human [out file name] |
  • Converts the config file to a human-readable format and produces a human-readable report based on the current Password Policy Enforcer instance configuration or the configuration provided by the /d (Domain [in controller]).
  • If no custom file name is provided, the default file name is `config_human_readable.xml`.
| -| /r | report [out file name] |
  • Converts the config file to HTML and produces an HTML report file based on the current Password Policy Enforcer instance configuration or the configuration provided by the /d (Domain [in controller]).
  • Generates the HTML report into `C:\Program Files (x86)\Password Policy Enforcer\Report` alongside the .css file.
  • The default files name is `report.html`.
| - - -### PPE Usage Samples - -This section covers some sample operations usable in either the PPE Tool or in the Command console -(with administrator rights). Each operation can be executed after the following commands have been -executed: - -C:\Windows/system32>cd.. - -`C:\`[location of PPE Tool]`>`[operation] - -After navigating to this location in the Command console, enter one of the following commands in -the [operation] variable above to execute a PPE Tool operation in the Command console. - -| Action | Operation | Message | -| -------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Simple Config export operation |
  • ppetool
| Warning: PPETool started in domain environment without /d option. Using local source. Hope you know what are you doing. Config successfully exported. | -| Simple Config export in domain environment with DC %Full computer name of Domain Controller% |
  • ppetool /d localhost
  • ppetool /d %Full computer name of Domain Controller%
| Config successfully exported. | -| Export local config into local.xml and create it from the HR.xml and report.html reports |
  • ppetool /e local.xml /h HR.xml /r Report.html
| Warning: PPETool started in domain environment without /d option. Using local source. Hope you know what are you doing. Config successfully exported. Human readable config representation successfully exported. HTML config representation exported successfully. | -| Import Config from config.xml |
  • ppetool /c config.xml /i
| Warning: PPETool started in domain environment without /d option. Using local source. Hope you know what are you doing. Config import successful. | - - -### Generating Reports with Custom Descriptions - -The PPE Tool generates user-friendly reports by processing configuration tags (i.e., ``). For -example, the PPE Tool searches for the file tagname.xml (or, ppe.xml in this case). This file has -root elements which name match each file name. Each root tag contains child tags (e.g., ``). -Each tag has the following attributes: - -- name — Contains the original tag name from the input configuration file. If this attribute is - missed, then the original tag and its value are absent in the human-readable report. -- DisplayName — Contains the user-friendly description for the original tag. If this attribute is - missed, then the original tag and its value appear in the report without a description. - -The `` tag can also contain the child `` tag. This tag can have an optional attribute -'mode' and this attribute can have the following values: - -- value (default) — With the default value, the report contains only tag descriptions for the - child `` tag. The 'value' attribute matches the child `` tag with the value of the - original tag. -- combined — With the combined value, the report contains the child `` tags which contain - values that are bitwise or are the result of the original values. - -#### Example of 'value' mode - -**Original configuration** - -```xml -1 -``` - -**Transform configuration** - -```xml - - - - - - - -``` - -**Transformation result** - -```xml - - - - - - - -``` - -#### Example of 'combined' mode - -**Original configuration** - -```xml -25 -``` - -**Transformation configuration** - -```xml - - - - - - - - - - - -``` - -**Result human-readable report** - -```xml - - - - - - - - - - - -``` - -### Customize HTML Report - -The PPE Tool comes with a pre-defined template.css file in the configuration folder, found here: -`C:\Program Files (x86)\Password Policy Enforcer\config`. The template.css defines the visual design -(formatting, colors, fonts etc.) of HTML report. See the -[XSLT - Transformation](https://www.w3schools.com/xml/xsl_transformation.asp) article for additional -information of transforming .xml to .xhtml. diff --git a/docs/passwordpolicyenforcer/10.2/administration/properties/_category_.json b/docs/passwordpolicyenforcer/10.2/administration/properties/_category_.json deleted file mode 100644 index d03c6544df..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/properties/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "PPS Properties Page", - "position": 80, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "properties" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/administration/properties/license_generator.md b/docs/passwordpolicyenforcer/10.2/administration/properties/license_generator.md deleted file mode 100644 index 68d73b85bb..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/properties/license_generator.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "License Generator" -description: "License Generator" -sidebar_position: 10 ---- - -# License Generator - -Use the License Generator tool to create licenses for Netwrix Password Policy Enforcer, -Netwrix Password Policy Enforcer Web, and Netwrix Password Reset products. Licenses can be -configured and customized based on individual security polices. Each generated license is saved locally as a .txt file. Use the license generated from this tool when configuring the Password -Policy Enforcer console. - -![License Generator](/images/passwordpolicyenforcer/10.2/administration/licensegenerator.webp) - -## Using the License Generator - -The License Generator tool installs with the default installation of Password Policy Enforcer under -the `C:\Program Files (x86)\Password Policy Enforcer\licensegenerator` folder. Once installed, -execute the AnixisLicenseTool.exe file. The LicenseGenerator folder also contains templates for -common licensing scenarios across all password policy enforcement products. - -The License Generator tool has the following features: - -- Product Type — This dropdown contains all password policy enforcement products under the Netwrix - suite of products -- License Type — This dropdown contains all license categories and determines the scope and - permissions granted to the license. The different License types are as follows: - - - Evaluation license — This license type allows users on the server to have full evaluation - permissions - - Perpetual license — This license type allows users on the server to have full permissions - indefinitely - - Subscription license — This license type allows users on the server to have all permissions as - granted by their subscription model - -- Product Version — Lists all product versions the License Generator can create valid license for. - This field is enabled only when selecting the Perpetual license type. -- License Period — This dropdown contains all available options for licensing. This field is - enabled only when selecting the Evaluation and Subscription license types. -- End Date — Date on which the custom license will expire. This field is enabled only when selecting - the Evaluation and Subscription license types. -- Licensed To — The name of the entity to receive the license -- Users count — The number of users granted permissions set in the license -- Custom Data — This dropdown contains the option to classify this license as a enzoic-enabled - license -- Generate — Press this button to generate the license and save the .txt file. -- Generate & open — Press this button to generate the license and open the .txt file. Copy the entire license and import it into Password Policy Enforcer. See the - [Management Console](/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console.md) - topic for additional information. diff --git a/docs/passwordpolicyenforcer/10.2/administration/properties/properties.md b/docs/passwordpolicyenforcer/10.2/administration/properties/properties.md deleted file mode 100644 index 56ca5c7203..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/properties/properties.md +++ /dev/null @@ -1,266 +0,0 @@ ---- -title: "PPS Properties Page" -description: "PPS Properties Page" -sidebar_position: 80 ---- - -# PPS Properties Page - -The Password Policy Server (PPS) is the Password Policy Enforcer component that checks passwords and -responds to queries from the Password Policy Client. PPS properties are global settings that apply -to all Password Policy Enforcer policies. See the -[Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) -topic for additional information. If you choose any of the options that log PPE Events, the events are viewable in Windows Event Viewer. See the -[View Event Logs in Windows Event Viewer](#view-event-logs-in-windows-event-viewer) topic for -additional information. - -Complete the following steps to open the PPS Properties page: - -![configuring_ppe_6](/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_6.webp) - -**Step 1 –** Click the **Password Policy Server** item to display the Password Policy Server view. - -**Step 2 –** Click **PPS Properties** in the right pane of the management console. - -**Step 3 –** Click the **Disable/Enable** button to disable or enable Password Policy Enforcer. - -## General Tab - -The General tab provides options to enable or disable policy enforcement and log events. - -- Enforce policy when password is reset — Check this box if Password Policy Enforcer should enforce - the password policy when a password is reset. - - - If this option isn't selected, administrators and helpdesk operators won't have to comply - with the password policy when resetting a user's password, or creating a new user account. - - This option doesn't change the behavior of the Minimum Age rule, as this rule is never - enforced during a reset. - - The History rule is only enforced during a reset if this checkbox is selected, and the - **Enforce this rule when a password is reset** checkbox is selected in the History Rule - Properties page. See the - [Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) - topic for additional information. - -- Log event when password not checked by app— Check this box if Password Policy Enforcer should add - an entry to the Windows Application Event Log whenever it accepts a password without checking it. - This may occur if: - - - Password Policy Enforcer is disabled - - The policy assigned to a user is disabled - - No policy is assigned to a user or an error occurs when determining the assigned policy, and a - Default Policy isn't specified - - A password is reset, and the Enforce policy when password is reset checkbox isn't selected - -- Log event when password rejected by app— Check this box if Password Policy Enforcer should add an - entry to the Windows Application Event Log whenever it rejects a password. The logged event - includes the following: - - - Username - - Source (client or server) - - The rules the password didn't comply with. - - :::note - Password Policy Enforcer doesn't send passwords or password hashes over the - network, even when logging rejections by the Password Policy Client. - ::: - - - Most Password Policy Enforcer rules are enforced by both the Password Policy Client and Password - Policy Server. If the Password Policy Enforcer Client is installed, then it will often reject a - non-compliant password before Windows sends it to the domain controller. The following - limitations apply when a password is rejected by the Password Policy Client: - - - An event is only logged if the Password Policy Enforcer Client version is 9.0 or later. - - If a password is rejected by an earlier client version, then no event is logged. If a - password is rejected by the Password Policy Server, then an event is logged irrespective of - the client version. - - - The logged event may not show all the rules the password didn't comply with because some - rules are only enforced by the Password Policy Server. - - For example, a password that doesn't comply with the Length, Complexity, and Compromised - rules would only show the Length and Complexity rules in the event when rejected by the - Password Policy Enforcer Client because the Compromised rule is only enforced by the server. - - If the Password Policy Enforcer Client isn't installed, then the server logs the event - with all three rules because the server enforces all these rules. See the - [Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) - topic for additional information. - - - Client rejections may not be logged, or they may be logged more than once if the Password - Policy Client and Password Policy Server can't communicate reliably. - -- Log event when password accepted by app— Check this box if Password Policy Enforcer should add an - entry to the Windows Application Event Log whenever it accepts a password. The logged event - includes the username. - -- Only accept encrypted client requests — Check this box if Password Policy Enforcer should only - accept encrypted requests from the Password Policy Client, Netwrix Password Reset, Password Policy - Enforcer/Web. See the - [Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) - topic and the - [Netwrix Password Reset and Web](/docs/passwordpolicyenforcer/10.2/administration/password_reset.md) - topic for additional information. - - - Client requests don't contain passwords or password hashes, and they weren't encrypted prior - to Password Reset and Web V9.0. - - Select this option if you aren't using the Password Reset/Web V8.x Password Policy Client, - Password Reset V3.x, or PPE/Web V7.x (or earlier). Password Policy Enforcer accepts both - encrypted and unencrypted requests if this option isn't selected. - - :::note - For versions v9.x and above, this option is selected by default. - ::: - - -Choose a password policy from the Default Policy dropdown list. Users must comply with the default -policy if no other policy is assigned to them. See the -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topic for additional information. Using Password Policy Enforcer without a default policy isn't -recommended, as it may leave some passwords unchecked. - -### Exempt Users from a Password Policy - -Complete the following steps to exempt some users from having to comply with the password policy when a -default policy is specified. - -**Step 1 –** Create a new policy for these users. - -**Step 2 –** Leave all the rules disabled for this policy. - -**Step 3 –** Assign this policy to the users who don't have to comply with any Password Policy -Enforcer rules. - -Refer to the -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topic for a diagrammatic representation of Password Policy Enforcer's policy selection algorithm, or -use the Test Policies page to quickly determine which policy Password Policy Enforcer enforces -for a particular user. See the -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topic for additional information. - -:::warning -If Password Policy Enforcer has only one policy and that policy is also the default -policy, then Password Policy Enforcer enforces the policy for all users. -::: - - -The Password Policy Client and Password Policy Server communicate over UDP port 1333 by default. If -you need to change the default port, then enter the new port number in the **Password Policy Server -Port** text box. Setting the port number to zero stops Password Policy Enforcer from accepting -client requests. If you change the port number, then you must also: - -- Restart all the Password Policy Server computers. -- Configure the Password Policy Client to use the new port. - -### Disabling and Enabling Password Policy Enforcer - -You can disable Password Policy Enforcer to stop checking new passwords for compliance with the -password policy. - -Complete the following steps to disable Password Policy Enforcer. - -**Step 1 –** Click the **Password Policy Server** item to display the Password Policy Server view. - -**Step 2 –** Click **PPS Properties** in the right pane of the management console. - -![configuring_ppe_6](/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_6.webp) - -**Step 3 –** Click **Disable**. - -**Step 4 –** Click **Yes** to confirm, then click **OK**. - -**Step 5 –** Click **OK** to close the PPS Properties page. - -The Password Policy Server icon in the left pane of the management console displays a red X when -Password Policy Enforcer isn't checking passwords. - -Complete the following steps to re-enable Password Policy Enforcer. - -**Step 1 –** Click the **Password Policy Server** item to display the Password Policy Server view. - -**Step 2 –** Click **PPS Properties** in the right pane of the management console. - -![configuring_ppe_7](/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_7.webp) - -**Step 3 –** Click **Enable**, then click **OK**. - -**Step 4 –** Click **OK** to close the PPS Properties page. - -:::note -Password Policy Enforcer is disabled or enabled immediately, but if the management console -is connected to a domain configuration, Active Directory propagates the change to other domain controllers with a short delay. See the -[Connect to a Configuration](/docs/passwordpolicyenforcer/10.2/administration/connecting.md) -topic for additional information. A user's password history may be updated even when Password Policy -Enforcer is disabled. See the -[Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) -topic for additional information. -::: - - -## Email Tab - -Use the Email tab to configure the e-mail delivery options. - -![emailtab](/images/passwordpolicyenforcer/10.2/administration/emailtab.webp) - -- Disable email reminders – Select this option if you prefer not to receive email reminders. -- Send email to an SMTP server – Select this option if you want receive email reminders. - - - Server – Provide the server address. - - Port – Provide the number of the port you are using. - - Username – Provide your username. - - Password – Provide your password. - - - Use TLS – Select this checkbox if you want to use TLS email encryption. - -- Save email to a pickup folder – Select this option if you want to have a backup copy of the sent - email. - - - Path – Click **Browse** and select the path to the pickup folder. - -## License Tab - -The License tab shows the status of your license. - -Click the **License** tab to display your Password Policy Enforcer license details. - -![licensetab](/images/passwordpolicyenforcer/10.2/administration/licensetab.webp) - -**Step 1 –** Receive a license key from -[](https://www.netwrix.com/support.html)[Netwrix Support](https://www.netwrix.com/support.html) -after purchasing the Netwrix Password Policy Enforcer. - -If you haven't yet purchased the product, you can contact -[Netwrix Support](https://www.netwrix.com/support.html)[ ](https://www.netwrix.com/support.html)to -obtain it. - -**Step 2 –** Copy the license certificate to the clipboard. - -**Step 3 –** Click **Get license from clipboard** button. - -The license file has been imported. - -## View Event Logs in Windows Event Viewer - -Complete the following steps to view events logs in Windows Event Viewer. - -**Step 1 –** Open **Windows Event Viewer**. - -![View Event Logs](/images/passwordpolicyenforcer/10.2/administration/vieweventlogs.webp) - -**Step 2 –** Navigate to **Windows Logs** > **Application**. - -**Step 3 –** In the Application list, select a Netwrix Password Policy Enforcer event under the -Source column. - -The General tab shows details for the selected event. The Details tab shows... - -### View Log Properties - -To view Log Properties, navigate to the Actions menu and select **Properties**. - -![Log Properties Window](/images/passwordpolicyenforcer/10.2/administration/vieweventlogslogproperties.webp) - -The Log Properties window displays. You can configure settings for this log from this window. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/_category_.json b/docs/passwordpolicyenforcer/10.2/administration/rules/_category_.json deleted file mode 100644 index 8c65666514..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Rules", - "position": 100, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "rules" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/character_pattern.md b/docs/passwordpolicyenforcer/10.2/administration/rules/character_pattern.md deleted file mode 100644 index 8eae83f59d..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/character_pattern.md +++ /dev/null @@ -1,30 +0,0 @@ ---- -title: "Character Pattern Rule" -description: "Character Pattern Rule" -sidebar_position: 140 ---- - -# Character Pattern Rule - -The Character Pattern rule rejects passwords that contain character patterns such as "abcde". -Passwords shouldn't contain character patterns because they can weaken the password. - -![ppe_rules_19](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_19.webp) - -- Select the **Enabled** checkbox to enable the Character Pattern rule. -- Select the Detect character substitution checkbox if Password Policy Enforcer should reject - passwords that rely on character substitution to comply with this rule. -- Select the **Bi-directional analysis** checkbox if Password Policy Enforcer should additionally - test passwords with their characters reversed. Enabling bi-directional analysis stops users from - circumventing this rule by reversing the order of characters in their password. For example, a - user may enter "edcba" instead of "abcde". -- Choose a value from the **Tolerance** dropdown list to specify the longest pattern that Password - Policy Enforcer will tolerate before rejecting a password. For example, the password - "password**wxyz**" contains a four-character pattern (shown in bold type). Password Policy - Enforcer rejects this password if the tolerance is set to three or lower, and accepts it if - the tolerance is set to four or higher. Choose the **Auto** value if passwords should be - rejected if they only contain a single, continuous, character pattern. For example, "abcde" would - be rejected, but "abcdz" and "abc123" wouldn't. -- Click the **Character Patterns** button to select which character patterns Password Policy - Enforcer detects. You must select at least one pattern. -- Click the **Messages** tab to customize the Password Policy Client rule inserts. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/character_rules.md b/docs/passwordpolicyenforcer/10.2/administration/rules/character_rules.md deleted file mode 100644 index e444cc7c7c..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/character_rules.md +++ /dev/null @@ -1,92 +0,0 @@ ---- -title: "Character Rules" -description: "Character Rules" -sidebar_position: 110 ---- - -# Character Rules - -Password Policy Enforcer has seven Character rules that reject passwords if they contain, or don't -contain certain characters. These rules can increase password strength or ensure password -compatibility with other systems. - -![ppe_rules_12](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_12.webp) - -All the Character rules work identically, but each has their own default character set. A character -set is the collection of characters that each rule searches for when checking a password. You can -use the Character rules with their default character sets, or define your own. By default, the -Password Policy Enforcer will select the Password Policy Enforcer character on the -[Policy Priorities](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_priorities.md) -page. - -:::note -Only Password Policy Enforcer 10.2 and later contain the Windows character set. -Password Policy Enforcer 9, Netwrix Password Reset 3, and Password Policy Enforcer/Web 7 (and older -for all products) always use the Password Policy Enforcer character set. -::: - - -This default character set contains the following: - -| Rule | Default character set | -| ----------- | ------------------------------------------------------------------------ | -| Alpha Lower | Lowercase alphabetic (a-z) | -| Alpha Upper | Uppercase alphabetic (A-Z) | -| Alpha | Uppercase and lowercase alphabetic (a-z & A-Z) | -| Numeric | Numerals (0-9) | -| Special | All characters not included above | -| High | All characters above ANSI 126 | -| Custom | No default characters | - - -Select the **Enabled** checkbox to enable the Character rule. - -Select the **contain** option if this rule should ensure that new passwords contain certain -characters. Only one character is required by default, but you can specify a different value by -choosing the required number of characters from the dropdown list beside the **contain** option. - -Select the **not contain any...** option if this rule should ensure that new passwords don't -contain certain characters. - -To restrict this rule to certain character positions, choose the starting position from the **in position** dropdown list, and the ending position from the **to** dropdown list. For -example, you may want to enforce a rule that requires a numeric character in the second character -position to maintain compatibility with some other system. - -Select the **Embedded** checkbox if users are required to embed these characters within their -passwords. For example, the passwords "12hello", "1hello", and "hello$987" don't contain any -embedded numeric characters, but these passwords do contain embedded numeric characters (shown in -bold type): "he**7**llo", "4he**3**llo", "23hello**7**$45". Embedded numeric and special characters -can help to protect passwords from cracking attacks. - -Enter a character set name in the **Name** text box. The Password Policy Client displays the new -name, but the Password Policy Enforcer management console continues to display the original -character set name. - -Enter some characters in the **Characters** text box to define a custom character set to replace the default. For example, enter "AaEeIiOoUu" to create a vowel character set. - -Click the **Messages** tab to customize the Password Policy Client rule inserts. - -:::note -The First Character, Last Character, and Complexity rules are easier to configure, and -easier for users to understand. Use these rules instead of the Character rules if they can enforce -your desired policy. -::: - - -### Enforcing Complex Character Requirements - -Character rules can be combined to enforce complex password requirements. For example, you may need -to enforce a policy such as "passwords must contain a numeric character, but not in the first two -positions" to ensure compatibility with some other system. Use two of the -Character rules to accomplish this. The first rule (shown on the left in the following table) ensures that passwords contain at least -one numeric character. The second rule ensures that passwords don't contain any numeric characters -in the first two positions. - -| | | -| ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | -| ![ppe_rules_13](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_13.webp) | ![ppe_rules_14](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_14.webp) | - -Password Policy Enforcer has only one Numeric rule, so the second requirement must be enforced by -one of the other rules. Use any unused Character rule for this purpose by changing its name -and default character set. In this Example, the Custom rule was chosen as it wasn't being used. The -character set name was changed to "numeric", and the character set was defined as "1234567890". diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/complexity_rule.md b/docs/passwordpolicyenforcer/10.2/administration/rules/complexity_rule.md deleted file mode 100644 index 12cf6a769e..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/complexity_rule.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -title: "Complexity Rule" -description: "Complexity Rule" -sidebar_position: 40 ---- - -# Complexity Rule - -The Complexity rule rejects passwords that don't contain characters from a variety of character -sets. Using several character types can make passwords more difficult to crack. - -![ppe_rules_4](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_4.webp) - -Select the **Enabled** checkbox to enable the Complexity rule. - -Choose the number of required character sets from the dropdown list. Password Policy Enforcer rejects passwords that don't contain characters from at least the specified number of character sets. - -Choose the available character sets by selecting the check boxes beside the character set names. The -number of available character sets must be equal to or greater than the number of required character -sets. - -Select the **Passwords must always comply with this rule** checkbox to make the Complexity rule -mandatory. Password Policy Enforcer rules are mandatory by default, but can be made optional by -changing the Reject passwords that don't comply with value in the Policy Properties page. A -mandatory rule can still be disabled when a passphrase is used. See the -[Passphrases](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/passphrases.md) -topic for additional information. - -Click the Messages tab to customize the Password Policy Client rule inserts. - -:::note -The Complexity rule uses custom character set definitions from the Character rules, even -if the Character rules are disabled. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/compromised_rule.md b/docs/passwordpolicyenforcer/10.2/administration/rules/compromised_rule.md deleted file mode 100644 index 22070154cf..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/compromised_rule.md +++ /dev/null @@ -1,29 +0,0 @@ ---- -title: "Compromised Rule" -description: "Compromised Rule" -sidebar_position: 60 ---- - -# Compromised Rule - -The Compromised rule rejects passwords from prior breaches. These passwords shouldn't be used as -they are vulnerable to credential stuffing attacks. - -![ppe_rules_6_337x406](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_6_337x406.webp) - -Select the **Enabled** checkbox to enable the Compromised rule. - -Click the **...** (ellipsis) button beside each text box to select a hash file. You can also enter a -path into the text box. The path can contain environment variables like - -:::warning -%SystemRoot%. hash files should only be read from a local disk. Using shared hash files -degrades performance, and could jeopardize security. -::: - - -Click the **Messages** tab to customize the Password Policy Client rule inserts. - -For information about Have I Been Pwned (HIBP) database usage, see the -[HIBP Updater](/docs/passwordpolicyenforcer/10.2/administration/hibpupdater.md) -topic. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/dictionary_rule.md b/docs/passwordpolicyenforcer/10.2/administration/rules/dictionary_rule.md deleted file mode 100644 index f1350cfef5..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/dictionary_rule.md +++ /dev/null @@ -1,160 +0,0 @@ ---- -title: "Dictionary Rule" -description: "Dictionary Rule" -sidebar_position: 50 ---- - -# Dictionary Rule - -The Dictionary rule rejects passwords that are vulnerable to guessing, hybrid, and precomputed -attacks. These attacks can crack weak passwords in seconds, and they can be very effective if -passwords are based on common words. - -![ppe_rules_5](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_5.webp) - -There are two Dictionary rules in each password policy. You can use the second rule with a different -dictionary file, or to enforce a more tolerant policy for passphrases by disabling the primary rule -for long passwords. - -Select the **Enabled** checkbox to enable the Dictionary rule. - -Select the **Detect inclusion of non-alpha characters** checkbox if Password Policy Enforcer should -remove all non-alphabetic characters during analysis. This allows Password Policy Enforcer to reject -passwords such as "myp8asswor8d." - -Select the **Detect character substitution** checkbox if Password Policy Enforcer should reject -passwords that rely on character substitution to comply with this rule. - -Select the **Bi-directional analysis** checkbox if Password Policy Enforcer should additionally -test passwords with their characters reversed. Enabling bi-directional analysis stops users from -circumventing this rule by reversing the order of characters in their password. For example, a user -may enter "drowssapym" instead of "mypassword". - -Select the Wildcard analysis checkbox if Password Policy Enforcer should search for wildcard -templates in the dictionary file. Wildcard templates are specially formatted dictionary words that -Password Policy Enforcer uses to reject a range of passwords. The Dictionary rule supports two -wildcard template formats: - - - - - - - - - - - - - - - - - - - - - -
FormatExampleDescription
Prefix - - - - - - - - - -
!!BAN*!!
!!2*!!
-
- - - - - - - - - -
Rejects passwords that start with BAN. For example: band, banish, ban, bank, etc.
Rejects passwords that start with the numeric character 2. For example: 2ABC, 2123, etc.
-
- Suffix - - !!*ING!! - - Rejects passwords that end with ING. For example: pushing, howling, trying, etc. -
- -Partial matching is performed even if Wildcard analysis is disabled. For example, the dictionary -word "password" rejects the passwords "My**Password**$", "**Password**100", and -"12**password**34" even if Wildcard analysis is disabled. - -Wildcard analysis should only be used to limit matching to the characters at the start or end of a -password. - -Enabling Wildcard analysis slightly increases search times, so only enable this option if the -dictionary file contains wildcard templates. The sample dictionary file included with Password -Policy Enforcer doesn't contain any wildcard templates. - -Choose a value from the Tolerance dropdown list to specify the maximum number of consecutive -matching characters that Password Policy Enforcer tolerates before rejecting a password. For example, the dictionary word "**sword**" and the password "4my**sword**%" contain five consecutive matching characters (shown in bold). Password Policy Enforcer rejects this password if the tolerance is four or lower, and accepts it if the tolerance is five or higher. - -Click the **Browse** button to select a dictionary file, or enter a path into the text box. The path -can contain environment variables like %SystemRoot%. A sample dictionary is installed in the -\Program Files (x86)\Password Policy Enforcer\ folder. The dictionary file should be read from a -local disk. Using a shared dictionary degrades performance, and could jeopardize security. - -:::note -The `\Program Files (x86)\` folder doesn't exist on 32-bit Windows, so move the -dictionary into the `\Program Files\Password Policy Enforcer\` folder if you have 32-bit and 64-bit -computers sharing a common Password Policy Enforcer configuration. -::: - - -Click the **Sort** button if the dictionary file is being used with Password Policy Enforcer for the -first time, or if words have been added to the file since it was last sorted. The Password Policy -Enforcer management console will sort and reformat the file so that Password Policy Enforcer can use -it. Sorting also removes duplicate words, so the sorted file may be smaller than the original. - -Click the **Messages** tab to customize the Password Policy Client rule inserts. If both Dictionary -rules have identical inserts, then only one of the inserts is shown in the corresponding Password -Policy Client message if the password is rejected by both rules. - -## Sample Dictionary File - -A sample dictionary file called DICT.TXT is installed in the \Program Files (x86) - -\Password Policy Enforcer\ folder. This file is sorted and ready to use. It contains approximately -257,000 words, names, and acronyms. - -## Creating a Custom Dictionary - -You can add words to the sample dictionary file, or download larger dictionary files from the -Internet. Always sort a dictionary file before using it with Password Policy Enforcer, and ensure -that all computers have a local copy of the updated and sorted file. - -The custom dictionary should meet the following requirements: - -1. The dictionary should begin and end with a blank line. -2. All words are capitalized. -3. The sort button is pressed after pointing to a file in the dictionary rule. - -:::note -If you are using a custom dictionary, use a different filename. The default -dictionary file (dict.txt) may be replaced during an upgrade. -::: - - -## Dictionary File Replication - -Password Policy Enforcer doesn't distribute dictionary file updates to other computers, but you can -use the Windows Distributed File System to ensure that all domain controllers have the latest -dictionary file. Copy the dictionary file into the Sysvol share on one domain controller, and the -Distributed File System will copy the file into the Sysvol share of all other domain controllers. -Configure the Dictionary rule to read the file from \\127.0.0.1\sysvol\your.domain\filename.txt - -The preceding path only works if the computer has a Sysvol share. This won't be the case if you are -using a workstation for policy testing, or if you are using Password Policy Enforcer to enforce -local polices. If you are using Password Policy Enforcer for local policies and want all computers -to receive dictionary file updates, then use the Sysvol share for file replication and a script or -scheduled task to copy the file to a local folder. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/first_and_last.md b/docs/passwordpolicyenforcer/10.2/administration/rules/first_and_last.md deleted file mode 100644 index d653f8464f..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/first_and_last.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: "First and Last Character Rules" -description: "First and Last Character Rules" -sidebar_position: 120 ---- - -# First and Last Character Rules - -The First and Last Character rules reject passwords that don't begin or end with an appropriate -character. These rules are typically used to ensure password compatibility with other systems. - -| | | -| ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | -| ![ppe_rules_15](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_15.webp) | ![ppe_rules_16](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_16.webp) | - -Select the **Enabled** checkbox to enable the First or Last Character rule. - -Select the **begin** (First Character rule) or **end** (Last Character rule) option if you want to -specify the **acceptable** character sets. - -Select the **not begin** (First Character rule) or **not end** (Last Character rule) option if you -want to specify the **unacceptable** character. - -Choose one or more character sets by selecting the check boxes beside the character set names. - -:::note -Click the Messages tab to customize the Password Policy Client rule inserts. The First and -Last Character rules use custom character set definitions from the Character rules, even if the -Character rules are disabled. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/history_rule.md b/docs/passwordpolicyenforcer/10.2/administration/rules/history_rule.md deleted file mode 100644 index d9e292eaf1..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/history_rule.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "History Rule" -description: "History Rule" -sidebar_position: 70 ---- - -# History Rule - -The History rule rejects passwords that are identical to recently used passwords. Password reuse -should be avoided because it defeats the purpose of regular password changes. Password Policy -Enforcer can stop users from reusing passwords for a specified number of password changes or a -number of days. - -![ppe_rules_7](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_7.webp) - -Select the **Enabled** checkbox to enable the History rule. - -Select the **one of the last** option to stop passwords from being reused for a specified number of -password changes. Choose the number of password changes from the dropdown list. - -Select the **password used in the last** option to stop passwords from being reused for a specified -number of days. Enter the number of days in the text box. - -Choose an item from the **Hash function** dropdown list. Argon2 is recommended for best security. -The Argon2 option uses 100,000 times more computing power to create a hash, so an attacker needs -100,000 more computing power to crack Argon2 hashes. Argon2 increases password change times by 400%, -so a domain controller that can handle 1,000 password changes a minute with SHA-256 can be expected -to handle 250 password changes a minute with Argon2. All numbers are approximate. Use Argon2 if your -domain controllers can handle the load. - -:::note -Changing the **Hash function** doesn't modify existing history records. It sets the -function to be used for new password history records. If a user has Argon2 and SHA-256 hashes in -their password history, then Password Policy Enforcer calculates both the Argon2 and SHA-256 hashes -during a password change to ensure the new password isn't in the password history. -::: - - -The History rule is normally not enforced when a password is reset. Select the **Enforce this rule -when a password is reset** checkbox to override the default behavior. You must also select the -**Enforce policy when password is reset** option in the PPS Properties page to enforce this rule -when a password is reset. - -Click the **Messages** tab to customize the Password Policy Client rule inserts. - -:::note -The History rule isn't enforced when testing passwords from the Test Policies page. -::: - - -Password Policy Enforcer updates a user's password history whenever their password changes. It -updates the password history even if Password Policy Enforcer or the assigned policy is disabled. A -Password Policy Enforcer deletes a user's password history if the user doesn't have an assigned policy, or if the History -rule is disabled at the time of the password change. - -Password Policy Enforcer's password history is stored in Active Directory for domain user accounts, -and in the registry for local user accounts. You can create a new Active Directory attribute for the -password history, or configure Password Policy Enforcer to use an existing attribute. - -Disable Password Policy Enforcer's History rule if you don't want Password Policy Enforcer to store -the password history. - -:::note -Password Policy Enforcer doesn't store passwords in the password history, it only stores -the Argon2 or SHA-256 hashes. A salt protects the hashes from precomputed attacks, including rainbow -tables. If you don't want Password Policy Enforcer to store a password history, then leave the -History rule disabled. You can use the Windows History rule together with Password Policy Enforcer's -other rules to enforce your password policy. -::: - - -Password Policy Enforcer can store up to 100 password hashes for each user, but it only stores the -minimum needed to enforce the current password policy. For example, if Password Policy Enforcer is -configured to reject the last 24 passwords, then only the last 24 password hashes are stored. -Reconfiguring Password Policy Enforcer to reject the last 30 passwords won't have an immediate effect because only 24 password hashes are stored. The full effect of the new configuration is realized after users change their passwords six more times, at which point Password Policy Enforcer has 30 stored password hashes for each user. - -Leave both the Windows and Password Policy Enforcer History rules enabled when transitioning from -one to the other. This allows the old rule to enforce the policy until the new rule has built up its -password history. The old rule can be disabled after users have completed the required number of -password changes to enforce the new rule. - -As Password Policy Enforcer is limited to storing the last 100 password hashes, it is possible for -the History rule to run out of storage space before the specified number of days. Use the Minimum -Age rule to avoid this problem. For example, if the History rule is configured to not allow password -reuse for 365 days, then set the minimum password age to four or more days. Even if a user changes -their password every four days, they can only perform 91 password changes in 365 days. - -## Creating a New Attribute for the Password History - -Windows stores a domain user's password history in two Active Directory attributes, but these -attributes can't be used by other applications. Password Policy Enforcer can store the password -history in a new or existing attribute. A new attribute is recommended, but you can use an existing -attribute if you don't want to extend the AD schema. An AD attribute is only needed for domain user -accounts because the password history for local user accounts is stored in the registry. - -:::warning -Password Policy Enforcer's password history attribute is confidential to stop -authenticated users from accessing the password history of other users. See the Microsoft Article -[Mark an attribute as confidential in Windows Server 2003 Service Pack 1](http://support.microsoft.com/kb/922836) -Microsoft article for additional information. Confidential attributes have additional protection in -Active Directory, but they aren't as well protected as the Windows password history attributes. -There is a higher risk of unauthorized access to the password history if it is stored outside the -Windows password history attributes. -::: - - -Complete the following steps to create a new Active Directory attribute for the password history. - -**Step 1 –** Log on to the server holding the Schema Operations Master role with an account that is -a member of the Schema Admins group. - -**Step 2 –** Open a Command Prompt window to the Password Policy Enforcer installation folder. - -**(\Program Files (x86)\Password Policy Enforcer\)** - -**Step 3 –** Enter the following command: - -**: ldifde -i -f History.ldf -c "DC=X" "DC=yourdomain,DC=yourdomain"** - -Replacing the last parameter with your domain's DN. - -**Step 4 –** Press **ENTER** and check the output for errors. - -![ppe_rules_8](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_8.webp) - -## Using an Existing Attribute for the Password History - -Password Policy Enforcer can store the password history in an existing attribute. The desktopProfile -attribute is well suited because it isn't used by Windows. Other attributes are also suitable if -they aren't being used. Contact [Netwrix Support](https://www.netwrix.com/support.html) if you -would like to use an existing attribute for the password history. - -## Password Histories for Local User Accounts - -The password histories of local user accounts are stored in the HKLM\SECURITY\PPE Password History\ -registry key. Users aren't granted access the HKLM\SECURITY\ registry key by default, so a user -can't read the password history of any user (including themselves). This is also true for members -of the Administrators group, but administrators can change the default permissions. If an -administrator accesses the password history they might be able to extract the hashes for cracking, -but they can't extract the passwords directly because the password history doesn't contain any -passwords. - -:::warning -The password history of a local user account isn't automatically deleted when the user -account is deleted. If a local user account is deleted, then another local user account is created -on the same computer with the same username, the new user will inherit the deleted user's password -history. The default registry permissions stop users from accessing their own password history, so -it is difficult for the new user to use this information. They could try to guess the deleted user's -password during a password change to see if it is rejected by the History rule, but they would only -have a few attempts to guess correctly before the old hashes are overwritten with new hashes. The -user's current password is validated, and the Windows Minimum Age rule is enforced before the -password history is checked, so every compliant and incorrect password guessed will overwrite one -hash in the password history. This information applies only to local user accounts. The password -history for domain user accounts is deleted when users are deleted. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/keyboard_pattern.md b/docs/passwordpolicyenforcer/10.2/administration/rules/keyboard_pattern.md deleted file mode 100644 index 2d92216afb..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/keyboard_pattern.md +++ /dev/null @@ -1,60 +0,0 @@ ---- -title: "Keyboard Pattern Rule" -description: "Keyboard Pattern Rule" -sidebar_position: 130 ---- - -# Keyboard Pattern Rule - -The Keyboard Pattern rule rejects passwords that contain keyboard patterns such as "qwerty". -Passwords shouldn't contain keyboard patterns because they are vulnerable to cracking attacks and -shoulder surfing (observing users as they enter their password). - -![ppe_rules_17](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_17.webp) - -The examples for this rule are taken from a US keyboard layout. These patterns may not exist on -other keyboard layouts. - -- Select the **Enabled** checkbox to enable the Keyboard Pattern rule. -- Choose the pattern detection mode from the **keyboard patterns** dropdown list. The Horizontal - mode only detects horizontal patterns such as "qwerty" and "zxcvbn". The Vertical mode only - detects vertical patterns such as "4esz" and "4rfc". The "Horizontal or vertical" mode detects - patterns in both axes. -- Select the **Detect direction change** checkbox if Password Policy Enforcer should detect - keyboard patterns that contain direction changes. For example, "qwewq" and "4rfr4" are both - recognized as five-character keyboard patterns if direction change detection is enabled. - -:::note -Password Policy Enforcer detects direction changes in both axes if the pattern detection -mode is set to "Horizontal or vertical". For example, "qawsed", "qwedsa", "qwedcv", and "qwsazx" are -all recognized as six-character keyboard patterns if direction change detection is enabled and the -pattern detection mode is set to "Horizontal or vertical". -::: - - -- Select the **Detect key repeat** checkbox if Password Policy Enforcer should detect keyboard - patterns that contain repeated keystrokes. For example, "qwwert" and "qwwwer" are both recognized - as six-character keyboard patterns if key repeat detection is enabled. -- Select the **Detect key skip** checkbox if Password Policy Enforcer should detect keyboard - patterns that contain a horizontally skipped key. For example, "qwryui" is recognized as a six- - character keyboard pattern if key skip detection is enabled. -- Choose a value from the **Tolerance** dropdown list to specify the longest keyboard pattern that - Password Policy Enforcer tolerates before rejecting a password. For example, the password - "my**qwer**pw" contains a four-character keyboard pattern (shown in bold type). Password Policy - Enforcer rejects this password if the tolerance is set to three or lower, and accepts it if - the tolerance is set to four or higher. -- Click the **Keyboard Layouts** button to select which keyboard layouts Password Policy Enforcer - uses for pattern detection. You must select at least one layout. Click OK to configure the - keyboard layout for the Keyboard Patter rule. - -![Keyboard Layout Window](/images/passwordpolicyenforcer/10.2/administration/keboardlayoutwindow.webp) - -Click the **Messages** tab to customize the Password Policy Client rule inserts. - -:::note -Modifier keys such as Shift and AltGr won't evade pattern detection. Key positions can -differ, even in keyboards with matching layouts. The Keyboard Pattern rule may not detect some -patterns because of these differences. Report any missed patterns to -[Netwrix Support](https://www.netwrix.com/support.html). - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/length_rule.md b/docs/passwordpolicyenforcer/10.2/administration/rules/length_rule.md deleted file mode 100644 index 868cacef7b..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/length_rule.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: "Length Rule" -description: "Length Rule" -sidebar_position: 30 ---- - -# Length Rule - -The Length rule rejects passwords that contain too few or too many characters. Longer passwords are -generally stronger, so only specify a maximum password length if password compatibility must be -maintained with a system that can't accept long passwords. - -![ppe_rules_3](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_3.webp) - -Select the **Enabled** checkbox to enable the Length rule. - -Select the **at least** option to specify the minimum number of characters that passwords must -contain. Choose the minimum number of characters from the dropdown list. - -Select the **no more than** option to specify the maximum number of characters that passwords can -contain. Choose the maximum number of characters from the dropdown list. - -Select the **between** option to specify the minimum and maximum number of characters that passwords -can contain. Choose the minimum number of characters from the first dropdown list, and the maximum -from the second drop- down list. - -Click the **Messages** tab to customize the Password Policy Client rule inserts. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/maximum_age_rule.md b/docs/passwordpolicyenforcer/10.2/administration/rules/maximum_age_rule.md deleted file mode 100644 index a3541470b7..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/maximum_age_rule.md +++ /dev/null @@ -1,90 +0,0 @@ ---- -title: "Maximum Age Rule" -description: "Maximum Age Rule" -sidebar_position: 10 ---- - -# Maximum Age Rule - -The Maximum Age rule forces users to change their passwords regularly. This decreases the likelihood -of an attacker discovering a password before it changes. This rule can only be enforced by domain -policies. - -![ppe_rules](/images/passwordpolicyenforcer/10.2/administration/ppe_rules.webp) - -## Settings Tab - -Configure the Settings tab to ensure that passwords are changed regularly to increase their -effectiveness. - -Select the **Enabled** checkbox to enable the Maximum Age rule. - -Choose a value from the first days dropdown list to specify how many days must elapse before -passwords expire. - -You can encourage users to choose longer passwords by extending the lifetime of their password if it -exceeds a certain length. To enable this feature, choose a higher value from the second days -dropdown list and a minimum length from the contains dropdown list. Passwords that contain the -required number of characters won't expire until the second (higher) days value. If both days -values are identical, then passwords will expire after the specified number of days, irrespective of -length. - -:::note -When the Maximum Age rule is configured to delay the expiry of longer passwords, it -creates an Active Directory security group called "PPE Extended Maximum Age Users". Password Policy -Enforcer uses this group to identify which users are eligible for a delayed password expiry. Password Policy Enforcer adds and removes users from the group automatically. You can move and rename this group, but don't -change the pre-Windows 2000 name. Contact Netwrix support if you must change the pre-Windows 2000 -name. Change a Password Policy Enforcer configuration setting (any setting) after moving or renaming -the group to trigger a cache update in Password Policy Enforcer. Password Policy Enforcer recreates -this group if you delete it. To stop creating a group, make the two days values equal in all -policies. -::: - - -Optionally, check the **Log Event...** box to have Password Policy Enforcer log an event each time a -password expires. Password Policy Enforcer expires passwords 1:00 AM daily on the server holding the -PDC emulator operations master role. With this optional feature enabled Password Policy Enforcer -will log an event for every password that expires. Events are logged to the Windows Application -Event Log. - -Choose a value from the Mode dropdown list to specify how Password Policy Enforcer handles expired -passwords. The Standard mode forces all users with expired passwords to change their password during -logon. The Transitional modes force a percentage of users with expired passwords to change their -password during logon. The Warning mode warns users that their password has expired without forcing -them to change it. - -Click the Email tab to configure the e-mail message options. See the -[Mailer](/docs/passwordpolicyenforcer/10.2/administration/mailer/mailer.md) -topic for additional information. - -Use the Warning and Transitional modes to gradually introduce a new password policy. These modes -reduce the number of forced password changes, allowing the help desk to deal with any extra calls -relating to the new policy. Switch to the Standard mode after most users have had a chance to change -their password. - -It takes approximately 50 days for all users with expired passwords to be forced to change them in -the 2% Transitional mode (2% every day). The 5% Transitional mode reduces this to 20 days, and the -10% Transitional mode further reduces it to 10 days. The selection algorithm is randomized, so these -are estimates only. You must switch to the Standard mode to ensure that all old passwords will -expire. - -Users with expired passwords are always prompted to change their password, even in the Transitional -and Warning modes. Users can ignore the prompt to change their password unless they are being forced -to change it. - -:::note -The password expiry prompt is a Windows client feature, and is displayed even if the -Password Policy Client isn't installed. Windows clients display the prompt 5 days before passwords -expire by default. You can alter this behavior in the Windows Group Policy security settings. See -the -[Interactive logon: Prompt user to change password before expiration](https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/interactive-logon-prompt-user-to-change-password-before-expiration) -Microsoft article for additional information. -::: - - -Password Policy Enforcer expires passwords at 1:00 AM every day on the domain controller holding the -PDC emulator operations master role. It sets "User must change password at next logon" for users -whose password has expired, or is due to expire on that day. Password Policy Enforcer doesn't -expire passwords if the Maximum Age rule is in Warning mode, or for users with "Password never -expires" set in Active Directory. Some passwords won't expire immediately when the Maximum Age -rule is in a Transitional mode. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/minimum_age_rule.md b/docs/passwordpolicyenforcer/10.2/administration/rules/minimum_age_rule.md deleted file mode 100644 index dda2ad879e..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/minimum_age_rule.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -title: "Minimum Age Rule" -description: "Minimum Age Rule" -sidebar_position: 20 ---- - -# Minimum Age Rule - -The Minimum Age rule stops users from quickly cycling through a series of passwords to -evade the History and Similarity rules. This rule can only be enforced by domain policies. - -![ppe_rules_2](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_2.webp) - -Select the **Enabled** checkbox to enable the Minimum Age rule. - -Choose a value from the **days** dropdown list to specify how many days users must wait before -changing their password. - -Click the **Messages** tab to customize the Password Policy Client. Only the Reason insert is shown -because minimum age requirements aren't included in the Password Policy message. - -:::note -The Minimum Age rule is unique because users can't comply with it by choosing a different -password; they must wait until the required number of days has elapsed. The Password Policy Client -consequently handles rejections by this rule differently to other rules. Rather than displaying the -usual message components, the Password Policy Client only displays the Minimum Age rule's Reason -insert. See -[Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) -topic for additional information. The Rejection Reason template, macros, and inserts from other -rules aren't displayed when a password change is denied by the Minimum Age rule. -::: - - -The Minimum Age rule isn't enforced during policy testing, but the test log does show the user's -password age. A log entry is also added if the Minimum Age rule would have rejected the password -change. See the -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topic for additional information. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/repeating_characters.md b/docs/passwordpolicyenforcer/10.2/administration/rules/repeating_characters.md deleted file mode 100644 index a930ce8989..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/repeating_characters.md +++ /dev/null @@ -1,19 +0,0 @@ ---- -title: "Repeating Characters Rule" -description: "Repeating Characters Rule" -sidebar_position: 160 ---- - -# Repeating Characters Rule - -The Repeating Characters rule rejects passwords that contain excessive character repetition. -Reducing character repetition can increase resistance to both brute-force and dictionary cracking -algorithms. The Repeating Characters rule isn't case sensitive, so "mypaSssSword" contains four -consecutive repeating characters (SssS). - -![ppe_rules_21](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_21.webp) - -- Select the **Enabled** checkbox to enable the Repeating Characters rule. -- Choose the maximum number of consecutive repeating characters that passwords can contain from the - **consecutive repeating characters** dropdown list. -- Click the **Messages** tab to customize the Password Policy Client rule inserts. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/repeating_pattern.md b/docs/passwordpolicyenforcer/10.2/administration/rules/repeating_pattern.md deleted file mode 100644 index ea96388223..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/repeating_pattern.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: "Repeating Pattern Rule" -description: "Repeating Pattern Rule" -sidebar_position: 150 ---- - -# Repeating Pattern Rule - -The Repeating Pattern rule rejects passwords that contain repeating character sequences. Users may -use repetition to artificially increase the length of a short password. This should be avoided as it -can weaken the password. - -![ppe_rules_17](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_17.webp) - -- Select the **Enabled** checkbox to enable the Repeating Pattern rule. -- Select the Detect character substitution checkbox if Password Policy Enforcer should reject - passwords that rely on character substitution to comply with this rule. -- Select the **Bi-directional analysis** checkbox if Password Policy Enforcer should search for - patterns with their characters reversed. Enabling bi-directional analysis stops users from - circumventing this rule by reversing the order of characters in the repeated pattern. For example, - a user may enter "password@drowssap" instead of "password@password". -- Choose a value from the **Tolerance** dropdown list to specify the maximum number of consecutive - matching characters that Password Policy Enforcer tolerates before rejecting a password. For - example, the password "**mypwd**4**mypwd**5" contains a five-character repeating pattern (shown - in bold type). Password Policy Enforcer rejects this password if the tolerance is four or lower, - and accepts it if the tolerance is five or higher. -- Click the **Messages** tab to customize the Password Policy Client rule inserts. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md b/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md deleted file mode 100644 index 791ff306d7..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md +++ /dev/null @@ -1,231 +0,0 @@ ---- -title: "Rules" -description: "Rules" -sidebar_position: 100 ---- - -# Rules - -Netwrix Password Policy Enforcer uses rules to decide if it should accept or reject a password. Each -policy has rules that are configured independently of the rules in other policies. To display the -rules for a policy: - -**Step 1 –** Click the Policies item to display the Policies view. - -**Step 2 –** Double-click the policy you want in the right pane of the management console. - -The management console shows rules in the right pane. A check mark beside a rule indicates -that the rule is enabled (being enforced). Double-click a rule to show the rule's properties. - -## Detecting Character Substitution - -Character substitution is a technique used by some users to improve password quality. They replace -some alphabetic characters with non-alphabetic characters that have a similar appearance. For -example, "sold" becomes "$old". Many of these substitutions are well known and do little to improve -password strength. - -Some Password Policy Enforcer rules have a Detect Character Substitution checkbox. When this check -box is selected, Password Policy Enforcer tests passwords with, and without character substitution. -This stops users from circumventing the rule by substituting some characters. Password Policy -Enforcer detects these common character substitutions: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Original - - Substituted -
- A - - a - - ^ @ -
- B - - b - - 8 -
- C - - c - - - - - - - - - -
- ( or { - <[
-
- D - - d - - - - - - - - - -
- ) or } - >]
-
- E - - e - - 3 -
- G - - g - - 6 or 9 -
- I - - i - - - - - - - - -
- ! or | -   1
-
- O - - o - - 0 or (zero) -
- S - - s - -

$ or 5

-
- T - - t - - + or 7 -
- Z - - z - - 2 -
- -## Tolerance - -Some Password Policy Enforcer rules have a Tolerance dropdown list. Use it to control how -strictly the rule is enforced. Tolerance is normally expressed as the maximum allowable number of -consecutive matching characters in the password and some other parameter. Password Policy Enforcer -rejects a password if the specified tolerance is exceeded. For example, the logon name -"mary**jones**", and the password "**Jones**town" contain five consecutive matching characters -(shown in bold type). Password Policy Enforcer rejects this password if the tolerance for the -User Logon Name rule is four or lower, and accepts it if the tolerance is five or higher. - -The User Logon Name, User Display Name, Similarity, and Character Patter rules have an Auto -tolerance option. Setting the tolerance to Auto instructs Password Policy Enforcer to only reject -passwords that contain the entire parameter being compared. This is very useful when the length of -the comparison parameter is unknown. For example, if you want Password Policy Enforcer to reject -passwords that contain the user's entire logon name, then you can't specify a fixed tolerance -unless all logon names have the same length. Setting the tolerance to Auto allows Password Policy -Enforcer to calculate an appropriate tolerance during every password change. - -Password Policy Enforcer sets the tolerance to the length of the comparison parameter minus one. The -following table shows some parameter values and the calculated tolerance. Password Policy Enforcer -rejects a password if it contains all the text in the Value column (or a derivative of it if -character substitution detection or bi-directional analysis is enabled). - -| Rule | Parameter | Value | Tolerance | -| ----------------- | ----------------- | ---------- | --------- | -| User Logon Name | Logon name | maryjones | 8 | -| User Display Name | Display name | Mary Jones | 9 | -| Similarity | Current password | oldpass | 6 | -| Character Pattern | Character pattern | abcdefgh | 7 | - -Password Policy Enforcer's Auto tolerance calculation has a minimum limit to stop passwords from -being rejected when the comparison parameter is very short. The limit is set to two characters by -default, so Password Policy Enforcer accepts passwords that contain the parameter value if the -comparison parameter only contains one or two characters. Contact Netwrix support if you need to -change the minimum limit. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/similarity_rule.md b/docs/passwordpolicyenforcer/10.2/administration/rules/similarity_rule.md deleted file mode 100644 index 41d2277686..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/similarity_rule.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Similarity Rule" -description: "Similarity Rule" -sidebar_position: 80 ---- - -# Similarity Rule - -The Similarity rule rejects passwords that are similar to a user's current password. Password -similarity may indicate that a user is serializing their passwords. For example, "password1", -"password2", "password3", etc. Password serialization should be avoided because it may allow an -attacker to guess the new password. - -![ppe_rules_9](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_9.webp) - -Select the **Enabled** checkbox to enable the Similarity rule. - -- Select the Detect character substitution checkbox if Password Policy Enforcer should reject - passwords that rely on character substitution to comply with this rule. -- Select the **Bi-directional analysis** checkbox if Password Policy Enforcer should additionally - test passwords with their characters reversed. Enabling bi-directional analysis stops users from - circumventing this rule by reversing the order of characters in their password. For example, a - user may enter "drowssapdloym" instead of "myoldpassword". -- Choose a value from the **Tolerance** dropdown list to specify the maximum number of consecutive - matching characters that Password Policy Enforcer tolerates before rejecting a password. For - example, the two passwords "old**passwd**" and "new**passwd**" contain six consecutive matching - characters (shown in bold type). Password Policy Enforcer rejects the new password if the - tolerance is five or lower, and accepts it if the tolerance is six or higher. Choose the - **Auto** value to reject passwords that contain the user's entire current password. - -:::note -Click the Messages tab to customize the Password Policy Client rule inserts. This rule is -only enforced if the Password Policy Client is installed. It doesn't store or transmit passwords or -password hashes. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/unique_characters.md b/docs/passwordpolicyenforcer/10.2/administration/rules/unique_characters.md deleted file mode 100644 index 1d4d8d53cf..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/unique_characters.md +++ /dev/null @@ -1,21 +0,0 @@ ---- -title: "Unique Characters Rule" -description: "Unique Characters Rule" -sidebar_position: 170 ---- - -# Unique Characters Rule - -The Unique Characters rule rejects passwords that don't contain a minimum number of unique -characters. For example, the password "aaaaaaaa" only contains one unique character (a), whereas -"mypassword" contains nine unique characters (mypasword). Increasing the number of unique characters -in a password can increase password strength by avoiding repetitive sequences that are easily -guessed. The Unique Characters rule is case sensitive, so "LoOpHole" contains seven unique -characters (LoOpHle). - -![ppe_rules_22](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_22.webp) - -- Select the **Enabled** checkbox to enable the Unique Characters rule. -- Choose the minimum number of unique characters that passwords must contain from the **unique - characters** dropdown list. -- Click the **Messages** tab to customize the Password Policy Client rule inserts. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/user_display_name_rule.md b/docs/passwordpolicyenforcer/10.2/administration/rules/user_display_name_rule.md deleted file mode 100644 index 0181d85e2b..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/user_display_name_rule.md +++ /dev/null @@ -1,28 +0,0 @@ ---- -title: "User Display Name Rule" -description: "User Display Name Rule" -sidebar_position: 100 ---- - -# User Display Name Rule - -The User Display Name rule rejects passwords that are similar to a user's Active Directory display -name (full name for local accounts). Passwords that are similar to a user's display name aren't -desirable because they are easily guessed. - -![ppe_rules_11](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_11.webp) - -- Select the **Enabled** checkbox to enable the User Display Name rule. -- Select the Detect character substitution checkbox if Password Policy Enforcer should reject - passwords that rely on character substitution to comply with this rule. -- Select the **Bi-directional analysis** checkbox if Password Policy Enforcer should additionally - test passwords with their characters reversed. Enabling bi-directional analysis stops users from - circumventing this rule by reversing the order of characters in their password. For example, a - user may enter "emanyalpsidym" instead of "mydisplayname". -- Choose a value from the **Tolerance** dropdown list to specify the maximum number of consecutive - matching characters that Password Policy Enforcer tolerates before rejecting a password. For - example, the display name "John **Smith**ers", and the password "12**smith**town" contain five - consecutive matching characters (shown in bold type). Password Policy Enforcer rejects this - password if the tolerance is four or lower, and accepts it if the tolerance is five or higher. - Choose the **Auto** value to reject passwords that contain the user's entire display name. -- Click the **Messages** tab to customize the Password Policy Client rule inserts. diff --git a/docs/passwordpolicyenforcer/10.2/administration/rules/user_logon_name_rule.md b/docs/passwordpolicyenforcer/10.2/administration/rules/user_logon_name_rule.md deleted file mode 100644 index 519349d84c..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/rules/user_logon_name_rule.md +++ /dev/null @@ -1,28 +0,0 @@ ---- -title: "User Logon Name Rule" -description: "User Logon Name Rule" -sidebar_position: 90 ---- - -# User Logon Name Rule - -The User Logon Name rule rejects passwords that are similar to a user's logon name (user name). -Passwords that are similar to a user's logon name aren't desirable because they are easily guessed. - -![ppe_rules_10](/images/passwordpolicyenforcer/10.2/administration/ppe_rules_10.webp) - -- Select the Enabled checkbox to enable the User Logon Name rule. -- Select the Detect character substitution checkbox if Password Policy Enforcer should reject - passwords that rely on character substitution to comply with this rule. - -- Select the **Bi-directional analysis** checkbox if Password Policy Enforcer should additionally - test passwords with their characters reversed. Enabling bi-directional analysis stops users from - circumventing this rule by reversing the order of characters in their password. For example, a - user may enter "emannogolym" instead of "mylogonname". -- Choose a value from the **Tolerance** dropdown list to specify the maximum number of consecutive - matching characters that Password Policy Enforcer tolerates before rejecting a password. For - example, the logon name "mary**jones**", and the password "**Jones**town" contain five consecutive - matching characters (shown in bold type). Password Policy Enforcer rejects this password if - the tolerance is four or lower, and accepts it if the tolerance is five or higher. Choose the - **Auto** value to reject passwords that contain the user's entire logon name. -- Click the **Messages** tab to customize the Password Policy Client rule. diff --git a/docs/passwordpolicyenforcer/10.2/administration/support_tools.md b/docs/passwordpolicyenforcer/10.2/administration/support_tools.md deleted file mode 100644 index 681ae73d1d..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/support_tools.md +++ /dev/null @@ -1,98 +0,0 @@ ---- -title: "Support Tools" -description: "Support Tools" -sidebar_position: 70 ---- - -# Support Tools - -Use the Support Tools page to create a Configuration Report that you can send to Netwrix Support, or -to directly edit Password Policy Enforcer's configuration settings. - -## Configuration Report - -Create a Configuration Report and e-mail it to Netwrix Support if Password Policy Enforcer isn't -working as expected. The Configuration Report helps Netwrix Support diagnose the problem. - -Complete the following steps to create a Configuration Report. - -**Step 1 –** Click the **Password Policy Server** item to display the Password Policy Server view. - -**Step 2 –** Click **Support Tools** in the right pane of the management console. - -![Support Tools Window - Configuration Report tab](/images/passwordpolicyenforcer/10.2/administration/supporttoolswindow.webp) - -**Step 3 –** Click **Save Configuration Report...** - -**Step 4 –** Enter a file name, then click **Save**. - -### Create Configuration Report as Text or HTML for Auditors - -Password Policy Enforcer 10.2 doesn't support exporting reports. -However, you can export Password Policy Enforcer's domain configuration with the following command: - -ldifde -f PPE10.1.txt -d "CN=Password Policy Enforcer 10.0,CN=System,DC=netwrix,DC=net" -l -url,wWWHomePage - -Change the domain name in the command to match your domain. User, group, and OU assignments aren't valid in the new domain and must be updated after the import. Do this from the PPE Management Console in the Policy Properties page for each policy. See the -[Assigning Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/assigning_policies.md) -topic for additional information. You must also import your license into the new domain from the About tab on the PPS Properties page. - -Complete the following steps to edit the edit the PPE10.1.txt file . - -**Step 1 –** Open the **PPE10.1.txt** file in a text editor. - -**Step 2 –** Replace **changetype: add** with **changetype: modify** - -**Step 3 –** Add the line **replace: wWWHomePage** above the line starting with **wWWHomePage:** - -**Step 4 –** Add a line with just a "**-**" (hyphen) character below the line starting with -**wWWHomePage:** - -**Step 5 –** Add the line **replace: url** above the line starting with **url::** - -**Step 6 –** Add a "**-**" hyphen near the end of the file, below the last line in the URL attribute - -**Step 7 –** Open ADSIEdit or AD Users and Computers in the target domain and clear the **URL** and -**www wWWHomePage** attributes for the Password Policy Enforcer configuration object (CN=Password -Policy Enforcer 10.0,CN=System). - -**Step 8 –** Import configuration with the following command: - -**ldifde -i -f PPE10.1.txt** - -Check **URL** and **wWWHomePage** attributes in ADSIEdit or AD Users and Computers before opening -PPE Management Console to ensure that configuration has been maintained. - -## Property Editor Tab - -Use the Property Editor to directly edit the Password Policy Enforcer configuration. You -should only use the Property Editor if instructed to by Netwrix Support. - -:::warning -Only configure the settings on the Property Editor tab if instructed to do so by -[Netwrix Support](https://www.netwrix.com/support.html). -::: - - -Complete the following steps to open and configure the Property Editor. - -**Step 1 –** Click the **Password Policy Server** item to display the Password Policy Server view. - -**Step 2 –** Click **Support Tools** in the right pane of the management console. - -![Support Tools Window - Property Editor tab](/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpropertyeditor.webp) - -**Step 3 –** Click the **Property Editor** tab. - -**Step 4 –** Select the policy you want from the dropdown list. - -**Step 5 –** Select property from the dropdown list. - -**Step 6 –** Enter a value directly related to the Property ID. - -**Step 7 –** Provide a valid Property ID to make changes in the configuration. - -**Step 8 –** Click **Set value**. - -**Step 9 –** Click **Close** to save the updates. diff --git a/docs/passwordpolicyenforcer/10.2/administration/troubleshooting.md b/docs/passwordpolicyenforcer/10.2/administration/troubleshooting.md deleted file mode 100644 index cbc54069cb..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/troubleshooting.md +++ /dev/null @@ -1,86 +0,0 @@ ---- -title: "Troubleshooting" -description: "Troubleshooting" -sidebar_position: 150 ---- - -# Troubleshooting - -This topic contains troubleshooting information for the most common support questions. Contact -Netwrix support with any questions. - -Password policy assigned to some users is being enforced for all users. Check the Default Policy in -the PPS Properties page. Users must comply with the default policy if no other policy is assigned to -them. Select the first (blank) item in the dropdown list if you don't want a default policy. - -#### Password policy not displayed during password change - -Open the Programs and Features list in Control Panel on the computer you are changing the password -from, and check if the Password Policy Client is in the list of installed programs. If it isn't, -then install the Password Policy Client. See the -[Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) -topic for additional information. - -If Password Policy Enforcer is enforcing a domain policy, then search the Windows Application Event -Log on every domain controller for events from Password Policy Enforcer. If there are no events from -Password Policy Enforcer since the last restart on any domain controller, then ensure that -Password Policy Enforcer is installed on that domain controller and restart it. Check the Windows -Application Event Log again after the restart to ensure that Password Policy Enforcer started. For -local policies, search the Application Event Log on the local computer. - -If there is a firewall between the client computer and the domain controllers (including Windows -Firewall), then you must create firewall rules to allow the Password Policy Client and Password -Policy Server to communicate. Windows firewall is enabled by default on Windows Server 2008 and -later. - -Use the Test Policies page to test a password for the user. Click the **Log** tab to see if a -password policy is assigned to the user. - -Ensure that the Password Policy Server is enabled. See the -[Management Console](/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console.md) -topic for additional information. - -Ensure that the Password Policy Client is enabled. See -[Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) -topic for additional information. - -#### Accepting passwords that don't comply with the policy - -If Password Policy Enforcer is enforcing a domain policy, then search the Windows Application Event -Log on every domain controller for events from Password Policy Enforcer. If there are no events from -Password Policy Enforcer since the last restart on any domain controller, then ensure that -Password Policy Enforcer is installed on that domain controller and restart it. Check the Windows -Application Event Log again after the restart to ensure that Password Policy Enforcer started. For -local policies, search the Application Event Log on the local computer. - -Use the Test Policies page to test a password that Password Policy Enforcer is accepting. Examine -the test results and event log to determine why Password Policy Enforcer accepted the password. If -the Test Policies page rejects the password, you must configure the policy. See the -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topic for additional information. - -If the **Enforce policy when password is reset** checkbox isn't selected in the PPS Properties -page, then Password Policy Enforcer won't enforce the password policy for passwords that are -reset from the Active Directory Users and Computers console, or the Local Users and Groups console. -You should select this option during testing, or test password changes from the Windows Change -Password screen. - -#### Rejecting passwords that comply with the policy - -Use the Test Policies page to test a password that Password Policy Enforcer is rejecting. Examine -the test results and event log to determine why Password Policy Enforcer rejected the password. If -the Test Policies page rejects the password, you must configure the policy. See the -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topic for additional information. - -Set **User must change password at next logon** for the user and repeat the password change test. If -the password is accepted, then either Windows or Password Policy Enforcer is configured to enforce a -minimum password age. Disable the Minimum Age rule in Windows and Password Policy Enforcer to -facilitate testing. If you can't disable the Minimum Age rule, then set User must change password -at next logon before every password change test to bypass the rule. - -#### Passwords that are accepted in the Test Policies page are rejected during a password change - -See the -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topic for additional information. diff --git a/docs/passwordpolicyenforcer/10.2/administration/uninstall.md b/docs/passwordpolicyenforcer/10.2/administration/uninstall.md deleted file mode 100644 index 9894ba5bfa..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/uninstall.md +++ /dev/null @@ -1,30 +0,0 @@ ---- -title: "Uninstall Netwrix Password Policy Enforcer" -description: "Uninstall Netwrix Password Policy Enforcer" -sidebar_position: 40 ---- - -# Uninstall Netwrix Password Policy Enforcer - -:::note -Uninstalling the product doesn't remove system files as the PPE.DLL from the System32 -folder. Before rebooting the Domain Controller, Windows has a lock on the system files. You can -delete system files after rebooting the Domain Controller. -::: - - -**Step 1 –** On the computer where Netwrix Password Policy Enforcer, navigate to Start > Control -Panel > Programs and Features. - -**Step 2 –** Click **Uninstall a program**. - -**Step 3 –** Select Netwrix Password Policy Enforcer to uninstall the PPE console. - -**Step 4 –** Click **Uninstall**. - -**Step 5 –** Select Netwrix Password Policy Client to uninstall the credential provider for version -10.2. - -**Step 6 –** Click **Uninstall**. - -**Step 7 –** Reboot the Domain Controller. diff --git a/docs/passwordpolicyenforcer/10.2/administration/upgrading.md b/docs/passwordpolicyenforcer/10.2/administration/upgrading.md deleted file mode 100644 index 30b47a9361..0000000000 --- a/docs/passwordpolicyenforcer/10.2/administration/upgrading.md +++ /dev/null @@ -1,347 +0,0 @@ ---- -title: "Upgrading" -description: "Upgrading" -sidebar_position: 30 ---- - -# Upgrading - -## Upgrading from v9.x - -The Password Policy Enforcer 10.2 Password Policy Server is backwards compatible with the V9.x -Password Policy Client. You don't have to upgrade existing V9.x Password Policy Clients to use the -10.2 Password Policy Server. - -### Upgrading the Password Policy Server - -The Password Policy Enforcer installer detects existing V9.x installations and upgrades them to -10.2. See the -[Installation](/docs/passwordpolicyenforcer/10.2/administration/installation/installation.md) -topic for additional information. If you are performing an automated installation with Group Policy, -then add PPE10.2.msi to the same Group Policy Object used to install the older version. See the -[Automated Installation (Advanced Setup)](/docs/passwordpolicyenforcer/10.2/administration/installation/automated_installation.md) -topic for additional information. - -### Upgrading the Password Policy Client - -The Password Policy Client installer detects existing V9.x installations and upgrades them to 10.2. -See the -[Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) -topic for additional information. If you are distributing the Password Policy Client with Group -Policy, then add PPEClt10.2.msi to the same Group Policy Object used to install the older version. -Upgrade and reboot the Password Policy Servers before upgrading the clients. - -### Upgrading the Mailer - -The Password Policy Enforcer installer detects existing V9.x installations of the Password Policy -Enforcer Mailer and upgrades them to 10.2. See the -[Installing the Mailer](/docs/passwordpolicyenforcer/10.2/administration/mailer/mailer.md#installing-the-mailer) -topic for additional information. - -## Upgrading from v8.x - -The Password Policy Enforcer 10.2 Password Policy Server is backwards compatible with the V8.x -Password Policy Client. You can benefit from most of the new features by upgrading the Password -Policy Server on the domain controllers. Do this before deploying the 10.2 Password Policy Client. - -### Upgrading the Password Policy Server - -The Password Policy Enforcer installer detects existing V8.x installations and upgrades them to -10.2. See the -[Installation](/docs/passwordpolicyenforcer/10.2/administration/installation/installation.md) -topic for additional information. If you are performing an automated installation with Group Policy, -then add PPE10.2.msi to the same Group Policy Object used to install the older version. See the -[Automated Installation (Advanced Setup)](/docs/passwordpolicyenforcer/10.2/administration/installation/automated_installation.md) -topic for additional information. - -Open the Password Policy Enforcer 10.2 management console immediately after upgrading to -automatically import the V8.x configuration settings into the new version. - -![installing_ppe_4](/images/passwordpolicyenforcer/10.2/administration/installing_ppe_4.webp) - -The management console imports valid subscription license keys, but it won't import V8.x -perpetual license keys as they can't be used with Password Policy Enforcer 10.2. Password Policy -Enforcer reverts to a 30-day evaluation license if it can't import the license key. Open the -PPS Properties page after an upgrade to check your license details. See the -[Management Console](/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console.md) -topic for additional information. - -You can run a combination of V8.x and 10.2 Password Policy Servers, but extended use of both -versions isn't recommended as it adds administrative overhead. Maintain both versions only for a -short time while you roll out Password Policy Enforcer V9.x. - -:::note -Any configuration changes made from the 10.2 management console only affect 10.2 -domain controllers. Likewise, any changes made from the V8.x management console only affect -V8.x domain controllers. You must make configuration changes in both management consoles until all -domain controllers are upgraded to 10.2. Failure to do so may lead to inconsistent enforcement of -the password policy. -::: - - -Older versions of the Password Policy Enforcer Client (before V6.0) can't detect passphrases. -Users must comply with the policy's compliance level when these older clients are installed. See the -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topic for additional information. - -Password Policy Enforcer 10.2 accepts passphrases that comply with all enabled rules, irrespective -of the compliance level. Password Policy Enforcer V6.x didn't do this, so it was possible to -configure Password Policy Enforcer in a way that would reject all passphrases because they couldn't -meet the compliance level after some rules were disabled. Password Policy Enforcer V6.x clients will -continue to use the old compliance level calculation until they are upgraded to 10.2. Take this into -consideration when setting the compliance level while Password Policy Enforcer V6.x clients are -still in use. This includes Netwrix Password Reset v2.x and PPE/Web v6.x. See the -[Netwrix Password Reset](https://helpcenter.netwrix.com/category/passwordreset) and -[Web](/docs/passwordpolicyenforcer/10.2/web/web_overview.md) -topics for additional information. - -Password Policy Enforcer 10.2 allows the use of longer rule insert in Password Policy Client -messages. Older versions of the Password Policy Enforcer Client (before V7.0), including PPE/Web -V6.x and Netwrix Password Reset V2.x may truncate messages with long inserts. See the -[Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) -topic for additional information. - -PPE/Web V3.x and Netwrix Password Reset V1.x use the Password Policy Enforcer V3.x communication -protocol. These clients aren't compatible with the 10.2 server. - -:::warning -Don't use the automatic tolerance option with Password Policy Enforcer V4.x clients. -These clients enforce an extremely restrictive password policy if this option is enabled and -reject any password that contains a character found in the comparison parameter. See the -[Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) -topic for additional information. -::: - - -### Upgrading the Password Policy Client - -The Password Policy Client installer detects existing V8.x installations and upgrades them to 10.2. -If you are distributing the Password Policy Client with Group Policy, then add PPEClt10.2.msi to the -same Group Policy Object used to install the older version. Upgrade and reboot the Password Policy -Servers before upgrading the clients. - -### Upgrading the Mailer - -The Password Policy Enforcer installer detects existing V8.x installations of the Password Policy -Enforcer Mailer and upgrades them to 10.2. See the -[Installing the Mailer](/docs/passwordpolicyenforcer/10.2/administration/mailer/mailer.md#installing-the-mailer) -topic for additional information. - -## Upgrading from v7.x - -The Password Policy Enforcer 10.2 Password Policy Server is backwards compatible with the V7.x -Password Policy Client. You can benefit from most of the new features by upgrading the Password -Policy Server on the domain controllers. Do this before deploying the 10.2 Password Policy Client. - -### Upgrading the Password Policy Server - -The PPE installer detects existing V7.x installations and upgrades them to V10.2. See the -[Installation](/docs/passwordpolicyenforcer/10.2/administration/installation/installation.md) -topic for complete installation instructions. If you are performing an -[Automated Installation (Advanced Setup)](/docs/passwordpolicyenforcer/10.2/administration/installation/automated_installation.md) -with Group Policy, then add PPE10.2.msi to the same Group Policy Object used to install the older -version. - -Open the PPE V10.2 management console immediately after upgrading to automatically import the V7.x -configuration settings into the new version. - -![ppe7configurationimport](/images/passwordpolicyenforcer/10.2/administration/ppe7configurationimport.webp) - -The management console imports valid subscription license keys, but it won't import V7.x -perpetual license keys as they can't be used with Password Policy EnforcerV10.2. Password Policy -Enforcer reverts to a 30-day evaluation license if it can't import the license key. Refer to the -[PPS Properties Page](/docs/passwordpolicyenforcer/10.2/administration/properties/properties.md) -topic after an upgrade to check your license details. - -You can run a combination of V7.x and V9.x Password Policy Servers, but extended use of both -versions isn't recommended as it adds administrative overhead. Maintain both versions only for a -short time while you roll out PPE V9.x. - -:::note -Any configuration changes made from the V10.2 management console only affect V10.x -domain controllers. Likewise, any changes made from the V7.x management console only affect -V7.x domain controllers. You must make configuration changes in both management consoles until all -domain controllers are upgraded to V10.x. Failure to do so may lead to inconsistent enforcement of -the password policy. -::: - - -Older versions of the PPE Client (before V6.0) can't detect passphrases. Users must comply with -the policy's compliance level when these older clients are installed. - -Netwrix Password Policy Enforcer V10.x accepts passphrases that comply with all enabled rules, -irrespective of the compliance level. Password Policy EnforcerV6.x didn't do this, so it was -possible to configure Password Policy Enforcer in a way that would reject all passphrases because -they couldn't meet the compliance level after some rules were disabled. Password Policy Enforcer -V6.x clients continue to use the old compliance level calculation until they are upgraded to -V10.x. Take this into consideration when setting the compliance level while Password Policy Enforcer -V6.x clients are still in use. This includes Netwrix Password Reset V2.x, and Password Policy -Enforcer Web V6.x. - -Netwrix Password Policy Enforcer V10.x allows the use of longer rule inserts in Password Policy -Client messages. Older versions of the PPE Client (before V7.0), including PPE/Web V6.x and -Netwrix Password Reset V2.x may truncate messages with long inserts. - -Password Policy Enforcer Web V3.x and Netwrix Password Reset V1.x use the Password Policy Enforcer -V3.x communication protocol. These clients aren't compatible with the V10.x server. - -:::warning -Don't use the automatic tolerance option with Password Policy Enforcer V4.x clients. -These clients enforce an extremely restrictive password policy if this option is enabled and -reject any password that contains a character found in the comparison parameter. -::: - - -The PPE Client for Windows 8, 10, Server 2012, Server 2016, and Server 2019 displays messages in a -smaller area than previous versions of Windows. Some of the default message components were -shortened to fit the available space. Your existing templates and macros won't change, but some -of the default inserts may be different to the ones your users are familiar with. Any new policies -you create after upgrading to PPE V9.x use the new templates and macros. - -To use the new templates and macros for your existing policies, create a new -policy and copy the templates from the new policy to your existing policies. See the -[Policy Properties](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/policy_properties.md) -topic for details. - -### Upgrading the Password Policy Client - -The Password Policy Client installer detects existing V7.x installations and upgrades them to V10.2. -Refer to the -[Installing Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/installing_password_policy_client.md) -topic for complete installation instructions. If you are distributing the PPC with Group Policy, -then add PPEClt912.msi to the same Group Policy Object used to install the older version. Upgrade -and reboot the Password Policy Servers before upgrading the clients. - -### Upgrading the Mailer - -The PPE installer detects existing V7.x installations of the PPE Mailer and upgrades them to V10.2. -Refer to the -[Mailer](/docs/passwordpolicyenforcer/10.2/administration/mailer/mailer.md) -topic for complete installation instructions. - -## Upgrading from v6.x - -The Password Policy Enforcer 10.2 Password Policy Server is backwards compatible with the V6.x -Password Policy Client. You can benefit from most of the new features by upgrading the Password -Policy Server on the domain controllers. Do this before deploying the 10.2 Password Policy Client. - -### Upgrading the Password Policy Server - -The Password Policy Enforcer installer detects existing V6.x installations and upgrades them to -10.2. See the -[Installation](/docs/passwordpolicyenforcer/10.2/administration/installation/installation.md) -topic for additional information. If you are performing an automated installation with Group Policy, -then add PPE10.2.msi to the same Group Policy Object used to install the older version. See the -[Automated Installation (Advanced Setup)](/docs/passwordpolicyenforcer/10.2/administration/installation/automated_installation.md) -topic for additional information. - -Open the Password Policy Enforcer 10.2 management console immediately after upgrading to -automatically import the V6.x configuration settings into the new version. - -![installing_ppe_7](/images/passwordpolicyenforcer/10.2/administration/installing_ppe_7.webp) - -The management console imports valid subscription license keys, but it won't import V6.x -perpetual license keys as they can't be used with Password Policy Enforcer 10.2. Password Policy -Enforcer reverts to a 30-day evaluation license if it can't import the license key. Open the -PPS Properties page after an upgrade to check your license details. See the -[Management Console](/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console.md) -topic for additional information. - -You can run a combination of V6.x and 10.2 Password Policy Servers, but extended use of both -versions isn't recommended as it adds administrative overhead. Maintain both versions only for a -short time while you roll out Password Policy Enforcer V9.x. If you are using Password Policy -Enforcer's Maximum Age rule and would like to enable the new extended maximum age feature for long -passwords, then you must first upgrade the domain controller holding the PDC emulator operations -master role to Password Policy Enforcer V910x. See the -[Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) -topic for additional information. - -:::note -Any configuration changes made from the 10.2 management console only affect 10.2 -domain controllers. Likewise, any changes made from the V6.x management console only affect -V6.x domain controllers. You must make configuration changes in both management consoles until all -domain controllers are upgraded to 10.2. Failure to do so may lead to inconsistent enforcement of -the password policy. -::: - - -The **Don't check admin/helpdesk password resets** property in the PPS Properties page was renamed -to **Enforce policy when password is reset**. The checkbox value changes after upgrading, but -Password Policy Enforcer enforces the same policy. See the -[Management Console](/docs/passwordpolicyenforcer/10.2/administration/managementconsole/management_console.md) -topic for additional information. - -Password Policy Enforcer V6.x included two dictionary files. DICT.TXT, and an optimized version -called DICT_O.TXT. The two files had identical coverage when the tolerance was set below five, but -DICT_O.TXT offered better performance due to its smaller file size. The performance difference is -insignificant on modern servers, so Password Policy Enforcer 10.2 includes only DICT.TXT. If you are -using DICT_O.TXT with the Dictionary rules, then you should reconfigure it to use DICT.TXT after -upgrading. See the -[Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) -topic for additional information. - -Older versions of the Password Policy Enforcer Client (before V6.0) can't detect passphrases. -Users must comply with the policy's compliance level when these older clients are installed. -Password Policy Enforcer 10.2 accepts passphrases that comply with all enabled rules, irrespective -of the compliance level. See the -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topic for additional information. Password Policy Enforcer V6.x didn't do this, so it was possible -to configure Password Policy Enforcer in a way that would reject all passphrases because they could -not meet the compliance level after some rules were disabled. Password Policy Enforcer V6.x clients -continue to use the old compliance level calculation until they are upgraded to 10.2. Take this -into consideration when setting the compliance level while Password Policy Enforcer V6.x clients are -still in use. This includes Netwrix Password Reset v2.x and PPE/Web v6.x. See the -[Netwrix Password Reset](https://helpcenter.netwrix.com/category/passwordreset) and -[Web](/docs/passwordpolicyenforcer/10.2/web/web_overview.md) -topics for additional information. - -Password Policy Enforcer 10.2 allows the use of longer rule inserts in Password Policy Client -messages. See the -[Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) -topic for additional information. Older versions of the Password Policy Enforcer Client (before -V7.0), including PPE/Web V6.x and Netwrix Password Reset V2.x may truncate messages with long -inserts. - -PPE/Web V3.x and Netwrix Password Reset V1.x use the Password Policy Enforcer V3.x communication -protocol. These clients aren't compatible with the 10.2 server. - -:::warning -Don't use the automatic tolerance option with Password Policy Enforcer V4.x clients. -These clients enforce an extremely restrictive password policy if this option is enabled and -reject any password that contains a character found in the comparison parameter. See the -[Rules](/docs/passwordpolicyenforcer/10.2/administration/rules/rules.md) -topic for additional information. -::: - - -The Password Policy Enforcer Client for Windows 2016, 2019, and 2022 displays messages in a smaller -area than previous versions of Windows. Some of the default message components were shortened to fit -the available space. See the -[Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) -topic for additional information. Your existing templates and macros won't change, but some of -the default inserts may be different to the ones your users are familiar with. Any new policies you -create after upgrading to Password Policy Enforcer 10.2 use the new templates and macros. - -To use the new templates and macros for your existing policies, create a new -policy and copy the templates from the new policy to your existing policies. Templates are in the -tab of the Policy Properties page. See -[Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) -and -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topics for additional information. - -### Upgrading the Password Policy Client - -The Password Policy Client installer detects existing V6.x installations and upgrades them to 10.2. -See the -[Installation](/docs/passwordpolicyenforcer/10.2/administration/installation/installation.md) -topic for additional information. If you are distributing the Password Policy Client with Group -Policy, then add PPEClt10.2.msi to the same Group Policy Object used to install the older version. -Upgrade and reboot the Password Policy Servers before upgrading the clients. - -### Upgrading the Mailer - -The Password Policy Enforcer installer detects existing V6.x installations of the Password Policy -Enforcer Mailer and upgrades them to 10.2. See the -[Installing the Mailer](/docs/passwordpolicyenforcer/10.2/administration/mailer/mailer.md#installing-the-mailer) -topic for additional information. diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/_category_.json b/docs/passwordpolicyenforcer/10.2/evaluation/_category_.json deleted file mode 100644 index fd3ccfb28e..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Evaluation", - "position": 30, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "evaluation_overview" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/conclusion.md b/docs/passwordpolicyenforcer/10.2/evaluation/conclusion.md deleted file mode 100644 index fab6d2113c..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/conclusion.md +++ /dev/null @@ -1,29 +0,0 @@ ---- -title: "Conclusion" -description: "Conclusion" -sidebar_position: 80 ---- - -# Conclusion - -You have successfully installed, configured, and tested Netwrix Password Policy -Enforcer. This guide is only an introduction to Password Policy Enforcer's capabilities. You can -enforce almost any password policy imaginable with Password Policy Enforcer, customize the Password -Policy Client messages, and even synchronize passwords with other networks and applications. The -[Administration](/docs/passwordpolicyenforcer/10.2/administration/administration_overview.md) -topic contains more information to help you get the most out of Password Policy Enforcer. - -You may also be interested in Netwrix Password Reset and PPE/Web. With these products, users can -securely manage their passwords from a web browser. Both products integrate with Password Policy -Enforcer to ensure that passwords comply with the password policy, and to help users choose -compliant passwords. - -Password Reset is a self-service password management system. Users can change their -password, reset a forgotten password, and unlock their account without calling the helpdesk. It -includes the Password Reset Client, which gives users access to APR from the Windows Logon and -Unlock screens. - -The [Web](/docs/passwordpolicyenforcer/10.2/web/web_overview.md) -application lets users change their password from a web browser. - -![conclusion_1](/images/passwordpolicyenforcer/10.2/evaluation/conclusion_1.webp) diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/configuring_policy_rules.md b/docs/passwordpolicyenforcer/10.2/evaluation/configuring_policy_rules.md deleted file mode 100644 index b93a174498..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/configuring_policy_rules.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "Configuring Policy Rules" -description: "Configuring Policy Rules" -sidebar_position: 40 ---- - -# Configuring Policy Rules - -The policy you just created doesn't enforce any password requirements yet. You can now configure -the policy to enforce these rules: - -- Password must contain at least seven characters. -- Password must contain at least one lowercase alpha character. -- Password must contain at least one uppercase character. -- Password must not be similar to the user's logon name. -- Password must not exist in a dictionary of common passwords. - -**Step 1 –** Click the **Users** policy in the left pane of the management console to display the -policy's rules. Rules are displayed in the right pane. - -![configuring_policy_rules](/images/passwordpolicyenforcer/10.2/evaluation/configuring_policy_rules.webp) - -**Step 2 –** Double-click the **Length** rule. - -**Step 3 –** Select the **Characters (Alpha Lower)** rule. - -**Step 4 –** Select the **Enabled** checkbox, then click **OK**. - -**Step 5 –** Double-click the **Characters (Alpha Upper)** rule. - -**Step 6 –** Select the **Enabled** checkbox, then click **OK**. - -**Step 7 –** Double-click the **User Logon Name** rule. - -**Step 8 –** Select the **Enabled** checkbox, then click **OK**. - -**Step 9 –** Double-click the **Dictionary** rule. - -**Step 10 –** Select the **Enabled** checkbox. - -**Step 11 –** Click **Browse**, select **Dict.txt** from the **\Program File (x86)\Password Policy -Enforcer** folder. - -**Step 12 –** Click **Open**, then click **OK**. - -:::note -Press F1 while using the management console to display help information for the current -window. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/creatingapasswordpolicy/_category_.json b/docs/passwordpolicyenforcer/10.2/evaluation/creatingapasswordpolicy/_category_.json deleted file mode 100644 index 2082970a80..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/creatingapasswordpolicy/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Creating a Password Policy", - "position": 30, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "creating_a_password_policy" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/creatingapasswordpolicy/creating_a_password_policy.md b/docs/passwordpolicyenforcer/10.2/evaluation/creatingapasswordpolicy/creating_a_password_policy.md deleted file mode 100644 index 2f1c9fa1c9..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/creatingapasswordpolicy/creating_a_password_policy.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: "Creating a Password Policy" -description: "Creating a Password Policy" -sidebar_position: 30 ---- - -# Creating a Password Policy - -There are no password policies defined when Password Policy Enforcer is first installed. You can now -create your first Password Policy Enforcer password policy. Password Policy Enforcer accepts all -passwords in this state, so users only need to comply with the Windows password policy rules (if -enabled). - -Complete the following steps to create a Password Policy Enforcer password policy. - -**Step 1 –** Click **Start** > **Password Policy Enforcer 10** > **PPE Configuration** to open the -Password Policy Enforcer management console. - -Click **Yes** when asked if you would like to create a new Password Policy Enforcer configuration. - -**Step 2 –** Click the **Policies** item in the left pane of the management console, then click -**New Policy** in the right pane. This opens the New Policy page. - -![managing_policies](/images/passwordpolicyenforcer/10.2/evaluation/managing_policies.webp) - -**Step 3 –** Enter a unique policy name in the **New policy name** text box. - -- If the new policy should inherit its default configuration from an existing policy, choose a - policy from the **Copy settings from** dropdown list. -- If the new policy should inherit settings from commonly used frameworks, select a Policy Template - from the dropdown list. For a list of policies see - [Policy Templates ](/docs/passwordpolicyenforcer/10.2/evaluation/creatingapasswordpolicy/policy_templates.md). - -**Step 4 –** Click **OK**. - -**Step 5 –** Click **No** when asked if you would like to assign users to the policy. - -![creating_a_password_policy_2](/images/passwordpolicyenforcer/10.2/evaluation/creating_a_password_policy_2.webp) - -**Step 6 –** Click the **Password Policy Server** item in the left pane of the management console, -and then click **PPS Properties** in the right pane. - -**Step 7 –** Choose the new **Users** (in step 3) policy from the Default Policy dropdown, then -click **OK**. - -**Step 8 –** Click **Yes** when asked to confirm the choice of Default Policy. diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/creatingapasswordpolicy/policy_templates.md b/docs/passwordpolicyenforcer/10.2/evaluation/creatingapasswordpolicy/policy_templates.md deleted file mode 100644 index 4b49421bd0..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/creatingapasswordpolicy/policy_templates.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -title: "Policy Templates" -description: "Policy Templates" -sidebar_position: 10 ---- - -# Policy Templates - -Password Policy Enforcer includes built-in Policy Templates based on the requirements of the -most popular regulatory frameworks. - -- CIS Password Policy Guide — See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- CIS Password Policy Guide MFA — See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- HIPPA — HIPAA Security Rule requires that organizations must implement procedures for creating, - changing, and safeguarding passwords. - - - It also recommends training the workforce on ways to safeguard password information and - establish guidelines to create and change passwords in a periodic cycle. - - HIPAA doesn’t offer any specific password complexity guidelines. To comply with HIPAA, - organizations are better off following NIST password guidelines. - - Most of healthcare institutions use the NIST framework. - -- NERC CIP — See the - [CIP-007-6 — Cyber Security – Systems Security Management](https://www.nerc.com/_layouts/15/PrintStandard.aspx?standardnumber=CIP-007-6&title=Cyber%20Security%20-%20System%20Security%20Management&Jurisdiction=United%20States) article - for additional information. -- NIST 800-63b — See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. -- PCI DSS — See the - [PCI Document Library](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss) web - site for additional information. -- ISO/IEC 27002 — See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies.md b/docs/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies.md deleted file mode 100644 index d2bd80fb92..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies.md +++ /dev/null @@ -1,69 +0,0 @@ ---- -title: "Enforcing Multiple Policies" -description: "Enforcing Multiple Policies" -sidebar_position: 70 ---- - -# Enforcing Multiple Policies - -Password Policy Enforcer can enforce up to 256 password policies on each domain or computer. You can -assign policies to users directly, or indirectly through Active Directory security groups and -containers (Organizational Units). - -### Create Additional Password Policy - -**Step 1 –** Click the **Policies** item in the left pane of the management console, then click -**New Policy** in the right pane. - -![managing_policies](/images/passwordpolicyenforcer/10.2/evaluation/managing_policies.webp) - -**Step 2 –** Enter **Admins** in the New Policy name text box, then choose the **Users** policy from -the **Copy Settings From:** dropdown. - -**Step 3 –** Click **OK** to create the policy, then click the **Assigned To** tab. - -![enforcing_multiple_policies_1](/images/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies_1.webp) - -**Step 4 –** Click the **Add...** button beside the Groups list and type "**domain admins**" in the -provided field. - -- If the test computer isn't a domain controller, click the **Add...** button and type - "**PPETestAdmin**" in the provided field. - -**Step 5 –** Click OK. - -![enforcing_multiple_policies_2](/images/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies_2.webp) - -**Step 6 –** Click **OK** to close the Policy Properties page. - -- Members of the Domain Admins group (or the PPETestAdmin user, if not using a domain controller) - must now comply with the Administrators policy. All other users must comply with the Users policy. - Users won't notice any difference at this point because the two polices are enforcing identical - rules. - -### Differentiate Password Policies - -The following example instructs how to change the minimum password length for the Admins policy from -seven to nine characters. To differentiate the policies, change the minimum password length for the -Admins policy from seven to nine characters. - -Complete the following steps to differentiate password policies. - -**Step 1 –** Click the **Admins** policy in the left pane of the management console. - -**Step 2 –** Double-click the **Length** rule. - -**Step 3 –** Choose **9** from the At Least dropdown list, then click **OK**. - -Use the Password Policy Enforcer management console, the Windows Change Password screen, the Active -Directory Users and Computers console, or the Local Users and Groups console to test password -changes and resets for the PPETestUser and PPETestAdmin accounts. Password Policy Enforcer should -enforce the Users policy for PPETestUser, and the Admins policy for PPETestAdmin. - -:::note -The -[Administration](/docs/passwordpolicyenforcer/10.2/administration/administration_overview.md) -topic contains more information about policy assignments, and how Password Policy Enforcer resolves -policy assignment conflicts that occur when more than one policy is assigned to a user. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/evaluation_overview.md b/docs/passwordpolicyenforcer/10.2/evaluation/evaluation_overview.md deleted file mode 100644 index e8891cfcf1..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/evaluation_overview.md +++ /dev/null @@ -1,30 +0,0 @@ ---- -title: "Evaluation" -description: "Evaluation" -sidebar_position: 30 ---- - -# Evaluation - -Netwrix Password Policy Enforcer is an advanced password filter for Windows. This Evaluator's Guide -shows you how to quickly install, configure, and test Password Policy Enforcer. Password Policy -Enforcer helps you to secure your network by ensuring that users choose strong passwords. If a user -chooses a password that doesn't comply with the password policy, Password Policy Enforcer -immediately rejects the password and tells the user why their password was rejected. - -![introduction_3](/images/passwordpolicyenforcer/10.2/evaluation/introduction_3.webp) - -Unlike password cracking products that check passwords after they are accepted by the operating -system, Password Policy Enforcer checks new passwords immediately to ensure that weak passwords do -not jeopardize system security. - -:::note -You can also use Password Policy Enforcer to ensure that passwords are compatible with -other systems, and to synchronize passwords with other systems and applications. -::: - - -The -[Administration](/docs/passwordpolicyenforcer/10.2/administration/administration_overview.md) -topic contains additional installation and configuration information. Refer to the Administrator's -topic for more detailed coverage of the information in this document. diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/improving_the_password_policy.md b/docs/passwordpolicyenforcer/10.2/evaluation/improving_the_password_policy.md deleted file mode 100644 index fff2284c09..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/improving_the_password_policy.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Improving the Password Policy" -description: "Improving the Password Policy" -sidebar_position: 60 ---- - -# Improving the Password Policy - -Password Policy Enforcer rules have properties that control how rules are enforced. You can improve -the effectiveness of the Users policy by enabling "character substitution detection" and -"bi-directional analysis" for the User Logon Name and Dictionary rules. - -When character substitution detection is enabled, Password Policy Enforcer searches passwords for -common character substitutions. For example, an S replaced with a $. If a password only complies -with the policy because of the substitution (i.e. the substitution is needed to make the password -compliant), then Password Policy Enforcer rejects the password. - -Bi-directional analysis tests passwords with their characters reversed to stop users from -circumventing a rule by entering a non-compliant password backwards. For example, "drowssapym" -instead of "mypassword". - -To enable the character substitution detection and bi-directional analysis properties for the User -Logon Name and Dictionary rules, complete the following steps. - -**Step 1 –** Click the **Users** policy in the left pane of the management console. - -**Step 2 –** Double-click the **User Logon Name** rule. - -**Step 3 –** Select the **Detect Character Substitution** and **Bi-directional analysis** check -boxes, then click **OK**. - -**Step 4 –** Double-click the **Dictionary Rule**. - -**Step 5 –** Select the **Detect Character Substitution** and **Bi-direction analysis** check boxes, -then click **OK**. - -Test the improved Users policy with passwords that were accepted under the previous policy (see the -following table). Password Policy Enforcer rejects all of them. - -| Password | Result | Reason | -| -------- | -------- | ---------------------------------- | -| tseTEPP | Rejected | Similar to user logon name | -| kravdraA | Rejected | Similar to word in dictionary file | -| Aardv@rk | Rejected | Similar to word in dictionary file | diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/installation.md b/docs/passwordpolicyenforcer/10.2/evaluation/installation.md deleted file mode 100644 index 36cc131fff..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/installation.md +++ /dev/null @@ -1,57 +0,0 @@ ---- -title: "Installation" -description: "Installation" -sidebar_position: 20 ---- - -# Installation - -You can install Password Policy Enforcer manually, or you can automate the installation with a -software distribution tool. Installing Password Policy Enforcer doesn't extend the Active Directory -schema. - -:::note -Refer to the -[Administration](/docs/passwordpolicyenforcer/10.2/administration/administration_overview.md) -topic to learn how to install Password Policy Enforcer with Group Policy. You can also use other -software distribution tools like Microsoft's System Center Configuration Manager to install Password -Policy Enforcer. -::: - - -Complete the following steps to manually install Password Policy Enforcer. - -**Step 1 –** Start the Password Policy Enforcer installer from the PPE10.exe file. - -**Step 2 –** Read the license agreement, then click **Yes** to accept the license terms and -conditions. - -**Step 3 –** Select **Express**, then **click** Next. - -**Step 4 –** Select the **Password Policy Server** checkbox, if unchecked. - -**Step 5 –** Click **Next** to install Password Policy Enforcer. - -**Step 6 –** Click **Yes** when asked to restart the computer. - -If you are evaluating Password Policy Enforcer on a domain with more than one domain controller, -repeat the preceding steps on every domain controller in the domain. - -The Password Policy Client is an optional Password Policy Enforcer component that helps users to -choose a compliant password. You don't have to install the Password Policy Client to enforce a -Password Policy Enforcer password policy, but installing the Password Policy Client will make it -easier for users to choose a password. If you are testing Password Policy Enforcer on a domain that -contains client computers, then repeat the preceding steps on any Windows client computers if you would -like to evaluate the Password Policy Client. You don't need to select the **Password Policy -Server** checkbox to install the Password Policy Client on a client computer. - -You may need to create a firewall port exception on the domain controllers if you are evaluating the -Password Policy Client on a domain with client computers. See the -[Password Policy Client](/docs/passwordpolicyenforcer/10.2/administration/passwordpolicyclient/password_policy_client.md) -topic for additional information. - -:::note -The Password Policy Client doesn't replace or modify any Windows system files. You can -install it with Group Policy, or some other software distribution tool in your production network. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer.md b/docs/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer.md deleted file mode 100644 index 901c1d8d92..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer.md +++ /dev/null @@ -1,62 +0,0 @@ ---- -title: "Preparing the Computer" -description: "Preparing the Computer" -sidebar_position: 10 ---- - -# Preparing the Computer - -You only need one computer for the evaluation. A Windows Server 2016, 2019, or 2022 domain -controller in its own domain is recommended. You can also use Windows 8, 10, or 11 if you only need -to enforce policies for local accounts. - -## Disable the Windows Password Policy Rules - -If the Password Policy Enforcer and Windows password policies are both enabled, then users will have -to comply with both policies. This isn't recommended for the evaluation because the Windows policy -may stop users from reusing recent passwords, or from changing their password more than once a day. -These restrictions can make it difficult to evaluate Password Policy Enforcer. - -Complete the following steps to disable the Windows password policy. - -**Step 1 –** Open the appropriate policy management tool: - -- If you are evaluating Password Policy Enforcer on a domain, use the Group Policy Management - Console (gmpc.msc) to display the GPOs linked at the domain level. Right-click the **Default - Domain Policy GPO** (or whichever GPO you use to set the password policy), then click the - **Edit...** button. -- If you are evaluating Password Policy Enforcer on a standalone server or workstation, open the - **Local Group Policy Editor** (gpedit.msc). - -**Step 2 –** Expand the following items: - -- Computer Configuration -- Policies (if it exists) -- Windows Settings -- Security Settings -- Account Policies -- Password Policy - -**Step 3 –** Double-click **Enforce password history** in the right pane of the GPO Editor. - -**Step 4 –** Enter **0** in the text box, then click **OK**. - -**Step 5 –** Repeat the preceding step for the Maximum Password Age and Minimum Password Length -policies. - -**Step 6 –** Double-click the **Group Policy Management Editor**. - -**Step 7 –** Close the **Group Policy Management Editor**. - -![preparing_the_computer](/images/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer.webp) - -**Step 8 –** Execute the `gpupdate/target:computer` command to refresh the Group Policy. - -## Create Test Accounts - -Create two user accounts for the evaluation: PPETestUser and PPETestAdmin. - -![preparing_the_computer_1](/images/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer_1.webp) - -Make PPETestAdmin a member of the Domain Admins group if you are evaluating Password Policy Enforcer -on a domain controller. diff --git a/docs/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy.md b/docs/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy.md deleted file mode 100644 index f7c1df42e8..0000000000 --- a/docs/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy.md +++ /dev/null @@ -1,145 +0,0 @@ ---- -title: "Testing the Password Policy" -description: "Testing the Password Policy" -sidebar_position: 50 ---- - -# Testing the Password Policy - -The Users policy is now being enforced for all users. You can test the policy from the Password -Policy Enforcer management console, the Windows Change Password screen, or the Active Directory -Users and Computers / Local Users and Groups consoles. - -## Management Console - -This is often the best way to test password policies because it shows you the most information. -Complete the following steps to test password policies from the Password Policy Enforcer management -console. - -**Step 1 –** Click the Policies item in the left pane of the management console, then click Test -Policies in the right pane. - -![testing_the_password_policy](/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy.webp) - -**Step 2 –** Enter a user name in the User name text box. - -**Step 3 –** Enter a password in the Old Password and New Password text boxes. - -The Password Policy Enforcer management console tests the password by simulating a password change, -but it doesn't change the user's password. It displays a green check mark below the Test button if -the new password complies with the Password Policy Enforcer password policy, or a red cross if it -doesn't comply. Detailed test results appear in the results panel below the New Password text box. - -The Results tab shows the test results for each rule. The check boxes show which rules the new -password complied with. - -| Rule | Status of Password Compliance with Rule | -| ------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- | -| ![testing_the_password_policy_1](/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_1.webp) | Rule disabled or not tested. | -| ![testing_the_password_policy_2](/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_2.webp) | Rule enabled, password complies with rule | -| ![testing_the_password_policy_3](/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_3.webp) | Rule enabled, password doesn't comply with rule. | - -Click the Log tab to view Password Policy Enforcer's internal event log. The information in the -event log can help you to understand why Password Policy Enforcer accepted or rejected a password. - -:::note -Policy testing simulates a password change, but it may not always reflect what happens -when a user changes their password. See the -[Managing Policies](/docs/passwordpolicyenforcer/10.2/administration/managingpolicies/managing_policies.md) -topic for details. -::: - - -## Windows Change Password Screen - -This is how most users change their password. Testing password policies from the Windows Change -Password screen is useful because it shows you exactly what your users see. - -Complete the following steps to test password policies from the Windows Change Password screen. - -**Step 1 –** Press **CTRL + ALT + DEL**. - -**Step 2 –** Click the **Change a password** option. - -**Step 3 –** Enter a user name in the User name text box. - -**Step 4 –** Enter passwords in the Old Password, New Password, and Confirm Password text boxes. - -**Step 5 –** Click the **submit arrow**. - -You may have noticed that the Change Password screen looks different after installing Password -Policy Enforcer. The Password Policy Enforcer password policy is shown during password changes if -the Password Policy Client is installed. This helps users to choose a compliant password. The -Password Policy Client also changes the message that users see when their password is rejected. Both -these messages are customizable. - -![introduction_3](/images/passwordpolicyenforcer/10.2/evaluation/introduction_3.webp) - -The Password Policy Client doesn't modify any Windows system files, and you don't have to install -it to enforce a Password Policy Enforcer password policy. Web browser based versions of the Password -Policy Enforcer Client are also available. - -## Active Directory Users / Computers Console and local Users and Groups Console - -Administrators often change domain passwords from the Active Directory Users and Computers console -and local passwords from the Local Users and Groups console. In fact, these consoles don't change -passwords; they reset them. This is an important distinction because a password reset is: - -- Restricted to privileged users -- Performed without knowing the current password - -Password Policy Enforcer can enforce the password policy for both password changes and password -resets. It does this by default, but you can configure it to only enforce the password policy for -password changes. The Minimum Age rule is never enforced when a password is reset. - -Complete the following steps to test password policies from these consoles. - -**Step 1 –** Open the appropriate console: - -- If Password Policy Enforcer is enforcing a domain policy, open the Active Directory Users and - Computers console -- If Password Policy Enforcer is enforcing a local policy, open the Local Users and Groups console - -**Step 2 –** Right-click a user, then click **Reset Password**. - -**Step 3 –** Enter a password in the **New password** and **Confirm password** text boxes. - -**Step 4 –** Click **OK**. - -:::note -These consoles don't explain why a password was rejected. Use the Password Policy -Enforcer management console, or the Change Password screen with the Password Policy Enforcer Client -installed to see this information. -::: - - -The following table contains some sample passwords and expected test results when the Users policy is -enforced. Try to change the password for the PPETestUser account to confirm that Password Policy -Enforcer is enforcing the password policy correctly. - -| Password | Result | Reason | -| -------- | -------- | -------------------------------------------- | -| AbdF6 | Rejected | Doesn't contain at least 7 characters | -| abd65fgo | Rejected | Doesn't contain an upper alpha character | -| ABD65FGO | Rejected | Doesn't contain a lower alpha character | -| PPETest1 | Rejected | Similar to user logon name | -| Aardvark | Rejected | Similar to common password (dictionary file) | -| tseTEPP | Accepted | N/A | -| kravdraA | Accepted | N/A | -| Aardv@rk | Accepted | N/A | - -Password Policy Enforcer accepts the last three passwords in the table because they comply with the -password policy, but this highlights some weaknesses in this policy: - -- tseTEPP is part of the user logon name with the characters reversed -- kravdraA is Aardvark with the characters reversed -- Aardv@rk is Aardvark with an @ substituting an "a." - -These three passwords are only marginally stronger than the rejected passwords. The next section -shows you how to improve the password policy so Password Policy Enforcer rejects these passwords. - -:::note -Contact Netwrix support[ ](mailto:support@anixis.com)if Password Policy Enforcer isn't -working as expected. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/index.md b/docs/passwordpolicyenforcer/10.2/index.md deleted file mode 100644 index 2ba8bf25a2..0000000000 --- a/docs/passwordpolicyenforcer/10.2/index.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -title: "Netwrix Password Policy Enforcer v10.2" -description: "Netwrix Password Policy Enforcer v10.2" -sidebar_position: 1 ---- - -# Netwrix Password Policy Enforcer v10.2 - -Netwrix Password Policy Enforcer helps you to secure your network by ensuring that users choose -strong passwords. When a user chooses a password that doesn't comply with the password policy, -Password Policy Enforcer immediately rejects the password and tells them why their password was -rejected. diff --git a/docs/passwordpolicyenforcer/10.2/web/_category_.json b/docs/passwordpolicyenforcer/10.2/web/_category_.json deleted file mode 100644 index de4ea82eff..0000000000 --- a/docs/passwordpolicyenforcer/10.2/web/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Web", - "position": 40, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "web_overview" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/10.2/web/configuration.md b/docs/passwordpolicyenforcer/10.2/web/configuration.md deleted file mode 100644 index c64e10149a..0000000000 --- a/docs/passwordpolicyenforcer/10.2/web/configuration.md +++ /dev/null @@ -1,86 +0,0 @@ ---- -title: "Configuration" -description: "Configuration" -sidebar_position: 40 ---- - -# Configuration - -Click **Start** >**[All] Programs** > **PPE Web Configuration Console** to open the Password Policy -Enforcer/Web Configuration Console. - -## General Tab - -Use the General tab to maintain the list of managed domains, and to configure Password Policy -Enforcer integration. See the [Password Policy Enforcer](#password-policy-enforcer) topic for -additional information. - -![configuring_ppe_web](/images/passwordpolicyenforcer/10.2/web/configuring_ppe_web.webp) - -### Domain List - -When Password Policy Enforcer/Web is first installed, the Domain List is empty and users must type -their domain name. You can configure Password Policy Enforcer/Web to display a list of domains -instead of an empty text box. - -**Add Domain** - -Complete the following steps to add a domain to the list. - -**Step 1 –** Click the **Add...** button. - -**Step 2 –** Enter a NetBIOS (NT Compatible) or DNS domain name. - -**Step 3 –** Click **OK**, the click **Apply**. - -:::note -Put the most frequently used domain first in the list — it is the default. You -can rearrange the domains by dragging them to another position. You can also click **Sort** to sort -them alphabetically. -::: - - -**Remove Domain** - -Complete the following steps to remove a domain from the list. - -**Step 1 –** Select the domain name from the Domain List. - -**Step 2 –** Click **Remove**, then click **Yes** when asked to confirm. - -**Step 3 –** Click **Apply**. - -### Password Policy Enforcer - -Password Policy Enforcer is a configurable password filter that enforces granular password policies -with many advanced features. Password Policy Enforcer/Web can integrate with Password Policy -Enforcer to help users choose a compliant password. - -![configuring_ppe_web_1](/images/passwordpolicyenforcer/10.2/web/configuring_ppe_web_1.webp) - -Password Policy Enforcer/Web displays the Password Policy Enforcer password policy message when a -user is prompted for their new password, and the Password Policy Enforcer rejection message if the -new password doesn't comply with the password policy. Select the **Password Policy Enforcer -integration** checkbox if you have installed and configured Password Policy Enforcer on your domain -controllers. - -You can also set the Port, Timeout, and number of Retries for the Password Policy Protocol if the -defaults aren't suitable. - -:::note -A Password Policy Enforcer/Web license doesn't include a Password Policy Enforcer -license. See [Netwrix Password Policy Enforcer](https://www.netwrix.com/password_policy_enforcer.html) for licensing information. -::: - - -## About Tab - -The About tab contains version and license key information. - -Complete the following steps to install a new license key. - -**Step 1 –** Copy the entire license e-mail to the clipboard. - -**Step 2 –** Click **Get license from clipboard**. - -**Step 3 –** Click **Apply**. diff --git a/docs/passwordpolicyenforcer/10.2/web/editing_html_templates.md b/docs/passwordpolicyenforcer/10.2/web/editing_html_templates.md deleted file mode 100644 index eb4bfe1f50..0000000000 --- a/docs/passwordpolicyenforcer/10.2/web/editing_html_templates.md +++ /dev/null @@ -1,205 +0,0 @@ ---- -title: "Editing HTML Templates" -description: "Editing HTML Templates" -sidebar_position: 60 ---- - -# Editing HTML Templates - -Password Policy Enforcer/Web's user interface is built with customizable templates. Modify the user interface by editing the templates. - -### User Interface Files - -Password Policy Enforcer/Web installs four .htm files for every language. Each filename starts with -a language code. The files for the US English language are: - -| Filename | Content | -| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| en_default.htm | Static HTML for the Welcome page. See the [Using Password Policy Enforcer Web](/docs/passwordpolicyenforcer/10.2/web/using_web.md) topic for additional information. | -| en_ppeweb.htm | Template for the Password Change page. See the [Changing a Password](/docs/passwordpolicyenforcer/10.2/web/using_web.md#changing-a-password) topic for additional information. | -| en_finished.htm | Template for the Finished page. | -| en_error.htm | Template for the Password Critical Error page. See the [Error Messages](/docs/passwordpolicyenforcer/10.2/web/using_web.md#error-messages) topic for additional information. | - -The other user interface files are language independent. Most of the formatting is in ppeweb.css, -and some additional CSS for Internet Explorer is in ppeweb_ie.css. The image files are in the images -folder. These files are installed into the `\Inetpub\wwwroot\ppeweb\` folder by default. - -:::note -Always backup the user interface files before and after editing them. Your changes may be -overwritten when Password Policy Enforcer/Web is upgraded, and some changes could stop Password -Policy Enforcer/Web from working correctly. Web browsers display pages differently, so test your -changes with several versions of the most popular browsers to ensure compatibility. -::: - - -The en_default.htm contains static HTML, but the other .htm files contain special comment tags that -are used to prepare the pages. Some of these comments define ranges. A range looks like this: - -`Some text or HTML` - -Password Policy Enforcer/Web deletes ranges (and the text inside them) when they aren't needed. -Some ranges span only one word, while others span several lines. The other type of comment tag is -called a field. - -`` - -Fields are replaced by some other information. For example, the preceding field is replaced with a -username. - -#### Resource Strings - -Templates end with a resource string section. - -`` - -Resource strings are mostly validation error messages, but they can contain any text Password Policy -Enforcer/Web may need to build the page. See the -[Error Messages](/docs/passwordpolicyenforcer/10.2/web/using_web.md#error-messages) -topic for additional information. Don't modify the identifiers on the left, only edit the text on -the right. Resource strings are always inside a range called RESOURCE_STRINGS. Password Policy -Enforcer/Web deletes this range before sending the page to the user's web browser. - -:::warning -You may rebrand the Password Policy Enforcer/Web user interface, but it is a violation -of the License Agreement to modify, remove, or obscure any copyright notice. -::: - - -## Examples - -This topic contains examples of common customizations. Use these examples to gain a better -understanding of Password Policy Enforcer/Web's templates. You don't need to be an expert in HTML to -follow these examples, but a basic understanding of HTML will help. Work through them carefully, and -backup files before you edit them. The examples in this section are from the US English files, but -the format is the same for all languages. - -### Replacing the Netwrix Logo - -The Netwrix logo is shown in the top left corner of the Welcome page. The logo is installed into the -`\Inetpub\wwwroot\ppeweb\images\` folder by default, and it is called logo.gif. You can replace this -file with one containing your organization's logo. - -Your logo may appear distorted if it isn't the same size as the Netwrix logo. You can fix this by -opening en_default.htm in a text editor such as Notepad. Search for the following line, and replace the width (116) and height (69) with the dimensions of your logo in pixels. - -`` - -### Edit Page Instructions - -Instructions appear at the top of the Password Change page in the white section above the input -fields. You can edit these instructions by opening `en_ppeweb.htm` and searching for the text you -want to modify. - -Instructions are inside ranges called SECTION_A and SECTION_B. Each section contains the -instructions for a page in the template. Ensure you edit the instructions in the correct section, -or they may be displayed on the wrong page. - -```html - -

Enter your username and domain, and then click Next to continue…

- -``` - -`` - -

Enter your old and new passwords in the text boxes below.

- -`` - -### Edit Validation Error Messages - -Validation error messages are shown in a yellow box below the page instructions. Validation errors -are normally caused by invalid user input. - -![using_ppe_web_1](/images/passwordpolicyenforcer/10.2/web/using_ppe_web_1.webp) - -Validation error messages are defined in en_ppeweb.htm. The error messages are in the resource -strings section near the end of the file. See the [Resource Strings](#resource-strings) topic for -additional information. - -| String | Error Message | -| ----------------------------- | ---------------------------------------- | -| @RES_EMPTY_FIELD_USERNAME | Enter your username in the Username box. | -| @RES_EMPTY_FIELD_DOMAIN | Enter your domain name in the Domain bo… | -| @RES_BAD_USERNAME_OR_PASSWORD | The username, domain, or old password i… | - -### Edit Critical Error Messages - -All the critical error messages are defined in `en_error.htm`. The error messages are in the -resource strings section near the end of the file. See the [Resource Strings](#resource-strings) -topic for additional information. - -![using_ppe_web_2](/images/passwordpolicyenforcer/10.2/web/using_ppe_web_2.webp) - -You may see placeholders like %1 and %2 in some error messages. These are replaced with more -information about the error. You should keep these as they provide important information about the -error, but you can delete them if you don't want them. - -| String | Error Message | -| ----------------------- | ---------------------------------------------- | -| @RES_ACCESS_DENIED | You don't have permission to change your pas… | -| @RES_ACCOUNT_LOCKED_OUT | Your account is locked out. Try aga… | -| @RES_LICENSE_MISSING | License reminder. Your password wasn't chang… | - -If you want to display some text for all error messages, then insert your text above or below the -`

{/*ERROR*/}

` line. For example: - -`

{/*ERROR*/}

` - -

The help desk phone number is 555-555-5555.

- -### Edit Finished Message - -The finished message is shown after users successfully change their password. This message is -defined in en_finished.htm. - -![editing_the_html_templates_1](/images/passwordpolicyenforcer/10.2/web/editing_the_html_templates_1.webp) - -```html -

Finished

-

Your password has been changed. You can now logon with your new pass…

-``` - -### Change Font Sizes and Colors - -`ppeweb.css` contains most of the user interface formatting information. Change font sizes and colors by editing this file. To reposition and resize items, you need some understanding of CSS. For example, this is the CSS for the validation error box: - -```css -.error { - background-color: #ffffd6; - border: 3px solid #ff8080; - color: #333333; - font: - bold 1.3em/1.2em Arial, - sans-serif; - margin: 3px 0 0 4px; - padding: 6px 22px 6px 8px; - width: 499px; -} -``` - -Edit these properties to change the appearance of the error box. You may need to clear your web -browser's cache to see the changes. - -:::note -Web browsers display pages differently, so test your changes with several versions of the -most popular browsers to ensure compatibility. -::: - - -### Replace URLs to the Welcome Page - -Password Policy Enforcer/Web shows the Welcome page when users click OK or Cancel on the Password -Change, Error, and Finished pages. - -To display a different page when users click OK or Cancel, search for `en_default.htm` in -`en_ppeweb.htm`, `en_finished.htm`, and `en_error.htm` and replace `en_default.htm` with an -alternative URL. For example: - -`https://myserver/accounts/login.htm` diff --git a/docs/passwordpolicyenforcer/10.2/web/installation.md b/docs/passwordpolicyenforcer/10.2/web/installation.md deleted file mode 100644 index 286b62e0d9..0000000000 --- a/docs/passwordpolicyenforcer/10.2/web/installation.md +++ /dev/null @@ -1,284 +0,0 @@ ---- -title: "Installation" -description: "Installation" -sidebar_position: 20 ---- - -# Installation - -Password Policy Enforcer/Web V7.11 is designed to run on Windows 2003, 2008, and 2012. Users access -Password Policy Enforcer/Web from their web browser. - -### System Requirements - -- Windows 2003, 2003 R2, 2008, 2008 R2, 2012, or 2012 R2. -- 5 megabytes of free disk space. -- 5 megabytes free RAM. - -:::note -Password Policy Enforcer/Web can share server resources with other applications. It can be -installed on an existing, well secured web server. -::: - - -## Preparing IIS - -Windows 2008 and 2012 include a modular version of IIS that only has a small set of core features -enabled by default. Password Policy Enforcer/Web is an ISAPI (Internet Server Application -Programming Interface) extension, so you must enable ISAPI extensions on the server that will host -Password Policy Enforcer/Web. - -Complete the following steps to manage various circumstances that may arise during installation. The following are common situations that impact installation and the steps necessary to work around them: - -- [If IIS isn't installed on Windows 2012](#if-iisis-not-installed-on-windows-2012) -- [If IIS is already installed on Windows 2012](#if-iisis-already-installed-on-windows-2012) -- [If IIS isn't installed on Windows 2008](#if-iisis-not-installed-on-windows-2008) -- [If IIS is already installed on Windows 2008](#if-iisis-already-installed-on-windows-2008) - -#### If IIS isn't installed on Windows 2012 {#if-iisis-not-installed-on-windows-2012} - -Complete the following steps to prepare IIS is IIS isn't installed on Windows 2012. - -**Step 1 –** Start the Server Manager (ServerManager.exe). - -![installing_ppe_web](/images/passwordpolicyenforcer/10.2/web/installing_ppe_web.webp) - -**Step 2 –** Click **Manage** > **Add Roles and Features**. - -**Step 3 –** Click **Next** on Before You Begin page (if applicable). - -**Step 4 –** Select **Role-based or Feature-based installation**, then click **Next**. - -**Step 5 –** Select an appropriate server, then click **Next**. - -**Step 6 –** Select the Web Server (IIS) role. - -**Step 7 –** Click **Add Features** if asked to install required features. - -**Step 8 –** Click **Next** three times. - -![installing_ppe_web_1](/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_1.webp) - -**Step 9 –** Expand the Application Development group, then select **ISAPI Extensions**. - -**Step 10 –** Click **Next**, then click **Install**. - -**Step 11 –** Wait for IIS to install, then click **Close**. - -#### If IIS is already installed on Windows 2012 - -Complete the following steps to prepare IIS is IIS is already installed on Windows 2012 - -**Step 1 –** Start the Server Manager (ServerManager.exe). - -![installing_ppe_web](/images/passwordpolicyenforcer/10.2/web/installing_ppe_web.webp) - -**Step 2 –** Click **Manage** > **Add Roles and Features**. - -**Step 3 –** Click **Next** on the Before You Begin page (if applicable). - -**Step 4 –** Select **Role-based or Feature-based installation**, then click **Next**. - -**Step 5 –** Select an appropriate server, then click **Next**. - -**Step 6 –** Expand the Web Server (IIS) (Installed) group. - -**Step 7 –** Expand the Web Server (Installed) group. - -![installing_ppe_web_2](/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_2.webp) - -**Step 8 –** Expand the Application Development group, then select **ISAPI Extensions**. - -**Step 9 –** Click **Next** twice, then click **Install**. - -**Step 10 –** Wait for the ISAPI Extensions feature to install, then click **Close**. - -#### If IIS isn't installed on Windows 2008 {#if-iisis-not-installed-on-windows-2008} - -Complete the following steps to prepare IIS if IIS isn't installed on Windows 2008. - -**Step 1 –** Start the Server Manager console (ServerManager.msc). - -**Step 2 –** Click the **Roles** item in the left pane. - -![installing_ppe_web_3](/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_3.webp) - -**Step 3 –** Click **Add Roles** in the right pane. - -**Step 4 –** Click **Next** on the Before You Begin page (if applicable). - -**Step 5 –** Select the Web Server (IIS) role, then click **Next** twice. - -![installing_ppe_web_4](/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_4.webp) - -**Step 6 –** Select **ISAPI Extensions** in the Application Development group. - -**Step 7 –** Click **Next**, then click **install**. - -**Step 8 –** Wait for IIS to install, then click **Close**. - -#### If IIS is already installed on Windows 2008 - -Complete the following steps to prepare IIS is IIS is already installed on Windows 2008. - -**Step 1 –** Start the Server Manager console (ServerManager.msc). - -**Step 2 –** Expand the **Roles** item in the left pane, then click **Web Server (IIS)**. - -**Step 3 –** Scroll down to the Role Services section in the right pane. - -![installing_ppe_web_5](/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_5.webp) - -**Step 4 –** Click **Add Role Services**. - -**Step 5 –** Select **ISAPI Extensions** in the Application Development group. - -**Step 6 –** Click **Next**, then click **Install**. - -**Step 7 –** Wait for the role service to install, then click **Close**. - -## The PPE/Web Setup Wizard - -The Setup Wizard copies the required files onto the server and configures IIS to run the Password -Policy Enforcer/Web application. - -Complete the following steps to install PPE/Web. - -**Step 1 –** Start the Password Policy Enforcer/Web Setup Wizard (PPEWeb711.exe). - -**Step 2 –** If another version of Password Policy Enforcer/Web is detected, the Setup Wizard may -required older files to be backed up. Back up these files if the original files have been modified. -Click **Next**. - -**Step 3 –** Click **Next**. - -**Step 4 –** Read the License Agreement. Click **I accept the terms of the license agreement**, then -click **Next** if you accept all the terms. - -**Step 5 –** Click **Browse...** if you want to choose a different folder for the Password Policy -Enforcer/Web documentation and tools, then click **Next**. - -**Step 6 –** Select an **IIS Web Site** from the dropdown. Change the default Virtual Directory, if -needed. - -:::note -Password Policy Enforcer/Web should be installed in its own virtual directory. -::: - - -**Step 7 –** Click **Next** twice. - -**Step 8 –** Wait for Password Policy Enforcer/Web to install, then click **Finish**. - -#### Upgrading from PPE/Web V7.x - -Some planning is needed to ensure a smooth upgrade from PPE/Web V7.x. A trial run on a lab network -is recommended. - -#### Before You Begin - -The HTML templates and associated images are overwritten during an upgrade. You must back up and -customized HTML templates and images before upgrading. The HTML templates and images are installed -in the `\Inetpub\wwwroot\ppeweb\` folder by default. - -:::note -A full backup of the PPE/Web server is recommended. Use it to roll back to the -previous version if the upgrade can't be completed. You may need to restart Windows after -upgrading. -::: - - -:::warning -PPE/Web V7.11 is only compatible with Password Policy Enforcer V7.0 and later. Upgrade -Password Policy Enforcer to a compatible version if you have enabled Password Policy Enforcer -integration. -::: - - -#### Upgrading to V7.11 - -**Step 1 –** Start the PPE/Web Setup Wizard and follow the prompts. The Setup Wizard uninstalls the -previous version. There is no need to manually uninstall previous versions. - -**Step 2 –** Restore any customized HTML templates and images after upgrading. Don't restore -PPEWeb.dll from the backup as it belongs to the previous version. - -## Upgrading from PPW/Web V6.x - -Some planning is needed to ensure a smooth upgrade from PPE/Web V6.x. A trial run on a lab network -is recommended. - -#### Before You Begin - -The HTML templates and associated images are overwritten during an upgrade. You must back up any -customized HTML templates and iages before upgrading The HTML templates and images are installed in -the `\Inetpub\wwwroot\ppeweb\` folder by default. - -:::note -A full backup of the PPE/Web server is recommended. Use it to roll back to the -previous version if the upgrade can't be completed. You may need to restart Windows after -upgrading. -::: - - -:::warning -PPE/Web V7.11 is only compatible with Password Policy Enforcer V7.0 and later. Upgrade -Password Policy Enforcer to a compatible version if you have enabled Password Policy Enforcer -integration. -::: - - -#### Upgrading to V7.11Upgrading to V7.11 - -Complete the following steps to upgrade PPE/Web to V7.11. - -**Step 1 –** Start the PPE/Web Setup Wizard and follow the prompts The Setup Wizard uninstalls the -previous version. There is no need to manually uninstall previous versions. - -**Step 2 –** Restore any customized HTML templates and images after upgrading. Don't restore -PPEWeb.dll from the backup as it belongs to the previous version. - -**Step 3 –** Open the Configuration Console to import your PPE/Web configuration settings. If you have a perpetual license, also install your new license key. See the -[Configuration](/docs/passwordpolicyenforcer/10.2/web/configuration.md) -topic for additional information. - -## Upgrading from PPE/Web V3.x - -PPE/Web V3.x didn't include a Setup Wizard, so you should manually remove the old version before -upgrading. - -#### Removing PPE/Web V3.x - -Complete the following steps to manually remove PPE/Web V3.x. - -**Step 1 –** Open the IIS Manager console. - -**Step 2 –** Right-click the PPE/Web virtual directory in the left pane of the IIS Manager console, -then click Delete. Click Yes to confirm. - -**Step 3 –** Click the Web Service Extensions item in the left pane of the IIS Manager console. -Right-click the PPE/Web item in the right pane, then click Delete. Click Yes to confirm. - -**Step 4 –** Back up the PPE/Web V3.x files. - -:::note -the PPE/Web V3.x files are most likely located in the `\Inetpub\wwwroot\ppeweb\` folder. -::: - - -**Step 5 –** Delete the folder containing the PPE/Web V3.x files. - -#### Upgrading to V7.11 - -Complete the following steps to upgrade to PPE/Web V7.x. - -**Step 1 –** Start the PPE/Web Setup Wizard and follow the prompts. - -**Step 2 –** Open the Configuration console to configure PPE/Web and install your new license key. - -:::note -Any customizations to the PPE/Web V3.x user interface must be recreated after upgrading to PPE/Web V7.11. See the -[Editing HTML Templates](/docs/passwordpolicyenforcer/10.2/web/editing_html_templates.md) -topic for additional information. - -::: diff --git a/docs/passwordpolicyenforcer/10.2/web/securing_web.md b/docs/passwordpolicyenforcer/10.2/web/securing_web.md deleted file mode 100644 index 077ebe7c16..0000000000 --- a/docs/passwordpolicyenforcer/10.2/web/securing_web.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Securing Password Policy Enforcer Web" -description: "Securing Password Policy Enforcer Web" -sidebar_position: 50 ---- - -# Securing Password Policy Enforcer Web - -Password Policy Enforcer/Web is designed to operate securely, but you must ensure that the web -server is also secure. Follow Microsoft's recommendations to secure the web server, and always -install and use an SSL certificate if Password Policy Enforcer/Web is used on an unencrypted network. - -## Installing and Using an SSL Certificate - -Password Policy Enforcer/Web sends passwords to the domain controllers over a secure connection, but -you need to set up SSL (Secure Sockets Layer) encryption for the connection between the web browser -and the web server. - -:::warning -Don't use Password Policy Enforcer/Web on a production network without SSL encryption. -::: - - -You can use a self-signed certificate, but most organizations purchase certificates from a -certificate authority. This is a recurring cost, and you must complete forms for the certificate authority to verify your identity. You can install Password Policy Enforcer/Web on a server that already has an SSL certificate to avoid purchasing another one. - -The IIS documentation explains how request, install, and use SSL certificates. - -See the following documentation: - -- Windows 2012 & 2008 - - - See the - [Configure Server Certificates in IIS 7](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc732230(v=ws.10)?redirectedfrom=MSDN) - Microsoft knowledge base article for additional information. - -- Windows 2003 - - - Configure Server Certificates in IIS 6.0. See the - [Certificates (IIS 6.0)](http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/89c7ef2f-f7d6-483c-8b08-ae0c6584dd4d.mspx) - Microsoft knowledge base article for additional information. - -Ensure that users only access Password Policy Enforcer/Web over an encrypted connection after the -SSL certificate is installed. The URL should start with https://. Web browsers can be redirected to -always use the secure URL. diff --git a/docs/passwordpolicyenforcer/10.2/web/using_web.md b/docs/passwordpolicyenforcer/10.2/web/using_web.md deleted file mode 100644 index f6b45edc34..0000000000 --- a/docs/passwordpolicyenforcer/10.2/web/using_web.md +++ /dev/null @@ -1,79 +0,0 @@ ---- -title: "Using Password Policy Enforcer Web" -description: "Using Password Policy Enforcer Web" -sidebar_position: 30 ---- - -# Using Password Policy Enforcer Web - -The default URL for Password Policy Enforcer/Web is: `http://[server]/ppeweb/` - -Where [server] is the name or IP address of the server hosting Password Policy Enforcer/Web. - -![using_ppe_web](/images/passwordpolicyenforcer/10.2/web/using_ppe_web.webp) - -The default page is called the Welcome page. You can customize the information on this page by -editing en_default.htm, or you can bypass this page and send users directly to the Password Change -page: - -`http://[server]/ppeweb/ppeweb.dll` - -You can also include the username and/or domain in the URL: - -`http://[server]/ppeweb/ppeweb.dll?username=maryjones&domain=ANIXIS` - -:::info -Install the SSL Certificate the web server and use the HTTPS protocol if Password -Policy Enforcer/Web is used on an unencrypted network. See the -[Installing and Using an SSL Certificate](/docs/passwordpolicyenforcer/10.2/web/securing_web.md) -topic for additional information. -::: - - -:::note -A license reminder message is shown occasionally when Password Policy Enforcer/Web is used -without a license key. Contact Netwrix support if you would like to evaluate Password Policy -Enforcer/Web without the reminder message. -::: - - -## Changing a Password - -Complete the following steps to change a password with Password Policy Enforcer/Web. - -**Step 1 –** Click **Change Password** on the Welcome page. - -![using_ppe_web](/images/passwordpolicyenforcer/10.2/web/using_ppe_web.webp) - -**Step 2 –** Enter a **Username** and **Domain**, then click **Next**. - -![introduction_4](/images/passwordpolicyenforcer/10.2/web/introduction_4.webp) - -**Step 3 –** Enter the **Old Password**, **New Password**, and **Confirm Password**, then click -**Next**. - -:::note -Windows increments the bad password count in Active Directory every time a user enters -their old password incorrectly. This may trigger a lockout if the Windows account lockout policy is -enabled. -::: - - -## Error Messages - -Validation errors are shown in a yellow box below the page instructions. Validation errors are -normally caused by invalid user input. They can often be overcome by changing the value of one or -more input fields and resubmitting the form. - -![using_ppe_web_1](/images/passwordpolicyenforcer/10.2/web/using_ppe_web_1.webp) - -Critical errors are shown on their own page. These errors are mostly a result of configuration or -system errors. Users can sometimes overcome a critical error by following the instructions in the -error message, but most critical errors are beyond the user's control. - -![using_ppe_web_2](/images/passwordpolicyenforcer/10.2/web/using_ppe_web_2.webp) - -Validation and critical error messages are stored in the HTML templates. You can modify the default -messages by editing the templates. See the -[Editing HTML Templates](/docs/passwordpolicyenforcer/10.2/web/editing_html_templates.md) -topic for additional information. diff --git a/docs/passwordpolicyenforcer/10.2/web/web_overview.md b/docs/passwordpolicyenforcer/10.2/web/web_overview.md deleted file mode 100644 index 9eddf4b9ea..0000000000 --- a/docs/passwordpolicyenforcer/10.2/web/web_overview.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -title: "Web" -description: "Web" -sidebar_position: 40 ---- - -# Web - -Password Policy Enforcer/Web lets users change their Windows domain password from a web browser. It can optionally integrate with Password Policy Enforcer to enforce customizable password -policies and help users choose a compliant password. - -Click the following link to download a 30-day trial of Password Policy Enforcer/Web: - -[https://releases.netwrix.com/products/passwordpolicyenforcer/10.1/passwordpolicyenforcer-web-7.11.zip](https://www.netwrix.com/download/commercial/Password_Policy_Enforcer_WEB_7.11.zip) - -![introduction_4](/images/passwordpolicyenforcer/10.2/web/introduction_4.webp) - -Password Policy Enforcer/Web communicates directly with the domain controllers, so it works best -when both the web server and domain controllers are on the same network. If you need to put the web -server in a DMZ for extra security, then consider using Netwrix Password Reset instead of Password -Policy Enforcer/Web. - -Password Reset also lets users change their password from a web browser, but it has many other -features including the ability to work in a DMZ without any domain controllers. Use Password Reset -if you need to: - -- Users can reset a forgotten password or unlock their account by answering questions about - themselves, such as their date of birth, first pet's name, etc. Users can access APR from the web - browser, or from the Windows Logon and Unlock screens if the APR Client is installed. -- Send e-mail alerts to users whenever their account is used in the password management system. -- Keep a detailed, searchable audit log of all user activity. -- Separate the web server from he internal network for extra security. - -See the [Netwrix Password Reset](https://www.netwrix.com/active_directory_password_reset_tool.html) -page for additional information on the Password Reset product. diff --git a/docs/passwordpolicyenforcer/11.0/admin/administration_overview.md b/docs/passwordpolicyenforcer/11.0/admin/administration_overview.md deleted file mode 100644 index 52e5c7568f..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/administration_overview.md +++ /dev/null @@ -1,28 +0,0 @@ ---- -title: "Administration" -description: "Administration" -sidebar_position: 40 ---- - -# Administration - -Netwrix Password Policy Enforcer helps secure your network by ensuring users set strong passwords. -When a user enters a password that doesn't comply with the password policy, Password Policy -Enforcer immediately rejects the password and details why the password was rejected. - -![introduction_2](/images/passwordpolicyenforcer/11.0/evaluation/introduction_3.webp) - -Unlike password cracking products that check passwords after they are accepted by the operating -system, Password Policy Enforcer checks new passwords immediately to ensure that weak passwords do -not jeopardize network security. - -You can also use Password Policy Enforcer to ensure that passwords are compatible with other -systems, and to synchronize passwords with other networks and applications. - -:::note -The [Evaluate Password Policy Enforcer](/docs/passwordpolicyenforcer/11.0/evaluation/evaluation_overview.md) contains -step-by-step instructions to help you quickly install, configure, and evaluate Password Policy -Enforcer. Consider using the Evaluation Guide if you are using Password Policy Enforcer for the -first time, before installing and deploying on your domains. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppebulkpasswordtest.md b/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppebulkpasswordtest.md deleted file mode 100644 index 89c7ec58df..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppebulkpasswordtest.md +++ /dev/null @@ -1,47 +0,0 @@ ---- -title: "Get-PPEBulkPasswordTest" -description: "Get-PPEBulkPasswordTest" -sidebar_position: 50 ---- - -# Get-PPEBulkPasswordTest - -The **Get-PPEBulkPasswordTest** cmdlet runs the Password Policy Enforcer bulk password test of the -specified policy. - -**SYNTAX** - -**Get-PPEBulkPasswordTest** **-PasswordFile** `<_string_>` **-Policy** `<_string_>` -**-ResultFolder** `<_string_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PasswordFile** `<_string_>` - -Path and name of the text file containing the passwords to test. Passwords in your test file are 1 -per line. - -**-Policy** `<_string_>` - -The name of the policy to enforce for the test. - -**-ResultFolder** `<_string_>` - -The folder for the created html report. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEBulkPasswordTest -PasswordFile C:\PPE\password.txt -Policy "Eval Policy" --resultFolder C:\PPE - -Bulk test is running... - -The report is created: "C:\PPE\password.txt_Result_2209222024122350.html". - -![Results of the Get-PPEBulkPasswordTest cmdlet](/images/passwordpolicyenforcer/11.0/administration/cmdletgetppebulkpasswordtest.webp) diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeserverversion.md b/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeserverversion.md deleted file mode 100644 index 72b0cfd479..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeserverversion.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Get-PPEServerVersion" -description: "Get-PPEServerVersion" -sidebar_position: 140 ---- - -# Get-PPEServerVersion - -The **Get-PPEServerVersion** cmdlet returns the Password Policy Enforcer server version. - -**SYNTAX** - -**Get-PPEServerVersion** [__-DC__] `<_string_>`] [`<_CommonParameters_>`] - -**PARAMETERS** - -**-DC** `<_string_>` - -Name of the domain controller running the PPE Server. If not specified, the current domain -controller is used. - -**-Local** `<_SwitchParameter_>` - -Connect to PPE Server installed locally. Can also use **-L** or **-l**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEServerVersion -DC NT-DC03.NWXTECH.COM - -**Version: 11.0.0.74** diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeversion.md b/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeversion.md deleted file mode 100644 index 1199d97c9b..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeversion.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: "Get-PPEVersion" -description: "Get-PPEVersion" -sidebar_position: 150 ---- - -# Get-PPEVersion - -The **Get-PPEVersion** cmdlet returns the version of the Password Policy Enforcer PowerShell module. - -**SYNTAX** - -**Get-PPEVersion** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEVersion - -**Version: 11.0.0.74** diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdlets.md b/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdlets.md deleted file mode 100644 index c1253b2fde..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdlets.md +++ /dev/null @@ -1,53 +0,0 @@ ---- -title: "PPE cmdlets" -description: "PPE cmdlets" -sidebar_position: 60 ---- - -# PPE cmdlets - -The PPE Cmdlets are available to manage Password Policy Enforcer from a Windows PowerShell. The -cmdlets aren't case-sensitive. - -To establish the connection: - -**Step 1 –** Open a Windows PowerShell. Some cmdlets require administrative permissions. You can use -the **Run as Administrator** option. - -**Step 2 –** Import the PPE cmdlets module: -**Import-Module "C:\Program Files\Password Policy Enforcer\PS\PPEConf.PowerShell.dll"** - -**Step 3 –** Connect to your domain: -**Connect-PPE -d "_domain_"** where _domain_ is the full name of your domain controller. -**NT-DC03.NWXTECH.COM** in this example. - -**Get-PPEHelp** with no parameters, displays a list of available cmdlets. Use the PowerShell -**get-help** _Cmdlet_ for information about the cmdlet. - -![PPE cmdlets Connect](/images/passwordpolicyenforcer/11.0/administration/cmdletconnect.webp) - -Click a PPE cmdlet name for details. - -- [Connect-PPE](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdconnectppe.md) -- [Copy-PPEPolicy](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdcopyppepolicy.md) -- [Export-PPEConfig](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdexportppeconfig.md) -- [Export-PPEPolicy](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdexportppepolicy.md) -- [Get-PPEBulkPasswordTest](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppebulkpasswordtest.md) -- [Get-PPEConfigReport](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeconfigreport.md) -- [Get-PPEDefaultPolicy](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppedefaultpolicy.md) -- [Get-PPEEnabled](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeenabled.md) -- [Get-PPEHelp](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppehelp.md) -- [Get-PPELicenseInfo](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppelicenseinfo.md) -- [Get-PPEPasswordTest](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppepasswordtest.md) -- [Get-PPEPolicies](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppepolicies.md) -- [Get-PPEPolicyEnabled](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppepolicyenabled.md) -- [Get-PPEServerVersion](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeserverversion.md) -- [Get-PPEVersion](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeversion.md) -- [Import-PPEConfig](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdimportppeconfig.md) -- [Import-PPEPolicy](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdimportppepolicy.md) -- [Remove-PPEPolicy](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdremoveppepolicy.md) -- [Set-PPEDefaultPolicy](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdsetppedefaultpolicy.md) -- [Set-PPEEnabled](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdsetppeenabled.md) -- [Set-PPEPolicyEnabled](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdsetppepolicyenabled.md) -- [Start-PPECompromisedPasswordChecker](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md) -- [Start-PPEHibpUpdater](/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdstartppehibpupdater.md) diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdstartppehibpupdater.md b/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdstartppehibpupdater.md deleted file mode 100644 index ca878fde91..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdstartppehibpupdater.md +++ /dev/null @@ -1,48 +0,0 @@ ---- -title: "Start-PPEHibpUpdater" -description: "Start-PPEHibpUpdater" -sidebar_position: 230 ---- - -# Start-PPEHibpUpdater - -The **Start-PPEHibpUpdater** cmdlet starts an update of the Hibp database. - -**SYNTAX** - -**Start-PPEHibpUpdater** [[__-Web__] `<_SwitchParameter_>`] **-Folder** `<_string_>` [__-File__ -`<_string_>`] **[-Inc** `<_SwitchParameter_>`] - -[`<_CommonParameters_>`] - -**PARAMETERS** - -**-Web** `<_SwitchParameter_>` - -Specify the update uses the NTLM Hashes file from the netwrix website. - -**-Folder** `<_string_>` - -Folder with the HIBP database. Can also use **-D** or **-d**. - -**-Inc** `<_SwitchParameter_>` - -Type of update. Specify **full** to update the entire database or **incremental**to add new entries -to the existing database. Can also use **-I** or **-i**. - -**-File** `<_string_>` - -File with list of NTLM hashes. Can also use **-S** or **-s**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Start-PPEHibpUpdater -Folder "C:\HIBP\DB" -File "C:\Users\Administrator\Desktop\db for HIBP -Updater not real small\stealthintercept-hibp-database-1.0.0.zip - -![HIBP Update](/images/passwordpolicyenforcer/11.0/administration/cmdletstartppehibpupdater.webp) diff --git a/docs/passwordpolicyenforcer/11.0/admin/command_line_interface.md b/docs/passwordpolicyenforcer/11.0/admin/command_line_interface.md deleted file mode 100644 index d279fb0fc4..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/command_line_interface.md +++ /dev/null @@ -1,52 +0,0 @@ ---- -title: "Command Line Interface" -description: "Command Line Interface" -sidebar_position: 70 ---- - -# Command Line Interface - -## Silent Installation - -Replace _version_ with the complete version and build number of the **msi** file. For example, -11.0.0.74. - -Install only PPE Server: msiexec /i Netwrix_PPE_Server**version**x64.msi ADDLOCAL=FeatureServerPPE -/q - -Install only Console: msiexec /i Netwrix_PPE_Server**version**x64.msi ADDLOCAL=FeatureConsole /q - -Install only Mailer Server: msiexec /i Netwrix_PPE_Server**version**x64.msi -ADDLOCAL=FeaturePPEMailerServer /q - -Install all 3 components: - -msiexec /i Netwrix_PPE_Server**version**x64.msi -ADDLOCAL=FeaturePPEMailerServer,FeatureConsole,FeatureServerPPE /q - -By default Console only installed: msiexec /i Netwrix_PPE_Server**version**x64.msi /q - -Uninstall all: msiexec /uninstall Netwrix_PPE_Server**version**x64.msi /q - -Uninstall only particular feature: msiexec /i _path_to_your_msi_file.msi_ REMOVE=_FeatureName_ /qn - -If a reboot wasn't done, add **/forcerestart** at the end - -## Mailer - -You can run the Password Policy Enforcer Mailer from the command line to deliver email immediately, -or to troubleshoot problems. PPEMail.exe is copied into the \Program Files (x86) - -\Password Policy Enforcer\ folder when the Password Policy Enforcer Mailer is installed. - -PPEMail.exe starts a simulation when run without any parameters. It finds users whose password will -expire soon, but no email is sent or saved to the pickup folder. Use the simulation mode to find -common configuration errors that may stop the Password Policy Enforcer Mailer from delivering email. - -Running PPEMail.exe with the /send parameter disables simulation mode. Any emails that are due to be -sent today are sent immediately. PPEMail.exe can identify a wider range of configuration errors when -run in this mode. Use the /send parameter judiciously to avoid sending duplicate emails to users. - -To test email delivery options without sending any emails to users, run PPEMail.exe with the /test -parameter followed by your email address. For example, PPEMail.exe /test johnsmith@netwrix.com. This -sends one test email to your mail server or pickup folder. diff --git a/docs/passwordpolicyenforcer/11.0/admin/compromisedpasswordcheck.md b/docs/passwordpolicyenforcer/11.0/admin/compromisedpasswordcheck.md deleted file mode 100644 index 012e6f0f7a..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/compromisedpasswordcheck.md +++ /dev/null @@ -1,81 +0,0 @@ ---- -title: "Compromised Password Check" -description: "Compromised Password Check" -sidebar_position: 30 ---- - -# Compromised Password Check - -The Compromised Password Checker finds compromised passwords. Users can be notified via email and -advised or forced to change their password. The check can be scheduled to check existing passwords -against a compromised hash list at any time. - -:::note -Create the **Compromised Passwords Base** file before enabling the Compromised Password -Check. See the [HIBP Updater](/docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md) topic for instructions. -::: - - -The Compromised Password Checker is launched from the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -Click the **Compromised Passwords** tile on the Configuration Console dashboard. This feature is -only available when **domain** is selected with the [Connected To](configconsole.md#connected-to) -configuration setting. The Compromised Password Check is disabled by default, and the schedule is -set to **None**. - -Click the **Compromised Password Check** toggle to enable/disable the feature. - -![Compromised Password Check](/images/passwordpolicyenforcer/11.0/administration/compromisedpasswords.webp) - -- **Compromised Passwords Base** specify the database to use when checking for compromised - passwords. Netwrix recommends using the [HIBP Updater](/docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md) to create this database. - Click **Browse** to navigate to the folder. Default is **C:\HIBP\DB** -- **Domain Controller (FQDN)** specify the fully qualified domain controller name where you want to - run the password check. Click **Browse** and select from the list. -- **Log events in Windows Application Event Viewer** select this option if you want to log events. -- **Force users to change password** select this option to force users to change compromised - passwords. -- **Recipient of the full report on the found compromised passwords** specify the email address of - the administrator who should receive the full report. -- **From** specify the email sender. -- **Notify users whose passwords are compromised by email** select this option to send email - notification to users their password appears in the compromised list. -- **Set up email** click to set up the email message for users. Enter the **From** address and edit - the subject and body template as needed. Click **Apply** to save changes. - - ![Email user notification of compromised password](/images/passwordpolicyenforcer/11.0/administration/emailusernotification.webp) - -Click **Save** to save your settings before running the check or setting up a schedule. - -Click **Run now** to run the check. Depending on your network, the check can take quite a while to -complete. You can schedule it for off hours instead of running it now. - -Here is an example of the compromised passwords list: - -|User | Account | Sid | Email | Description | -| --- | --- | --- | --- | --- | -| admin | Administrator | S-1-5-21-1006207104-1546379664-2458629591-500 | | Sending emails isn't possible due to the lack of an email address in the account. | -| user2 | user2 | S-1-5-21-1006207104-1546379664-2458629591-1118 | user2@company.com | Email has been sent | - -#### Schedule the Compromised Password Check - -Click **Schedule** to set up a schedule to run the Compromised Password Check. - -![Schedule the Compromised Password Policy Check](/images/passwordpolicyenforcer/11.0/administration/compromisedpasswordsschedule.webp) - -Select the **Frequency**: - -- None: no scheduled runs. -- Run now: run the check now. No scheduled runs. -- Once: set the **Start date** and **Start time** to run the check a single time. -- Daily: set the **Start date** and **Start time** to run the check daily. -- Weekly: set the **Start date**, **Start time** and select the day of the week to run the check - weekly. -- Monthly: set the **Start date**, **Start time** and select the day of the month to run the check - monthly. - -Click **Apply**. diff --git a/docs/passwordpolicyenforcer/11.0/admin/configconsole.md b/docs/passwordpolicyenforcer/11.0/admin/configconsole.md deleted file mode 100644 index d0b575cae1..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/configconsole.md +++ /dev/null @@ -1,231 +0,0 @@ ---- -title: "Configuration Console" -description: "Configuration Console" -sidebar_position: 10 ---- - -# Configuration Console - -The PPE Configuration Console manages Password Policy Enforcer across your domain. It can be -installed on multiple servers/workstations as convenient. - -Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -![Configuration Console Dashboard](/images/passwordpolicyenforcer/11.0/evaluation/ppedashboard.webp) - -## Dashboard Controls - -The Configuration Console dashboard has all the tools you need to set up and manage Password Policy -Enforcer. - -- Enable/Disable Password Policy Enforcer -- Connected To -- Help -- Settings - General, Notifications, License - -In addition, there are tiles to access Password Policy Enforcer major features: - -- [Manage Policies](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/manage_policies.md) -- [Compromised Password Check](/docs/passwordpolicyenforcer/11.0/admin/compromisedpasswordcheck.md) -- [System Audit and Support](/docs/passwordpolicyenforcer/11.0/admin/systemaudit.md) - Version Tracker, Support Tools, Property Editor - -See the specific topics for details. - -### Enable/Disable Password Policy Enforcer - -The toggle enables/disables Password Policy Enforcer on all domain controllers. It is enabled by -default. - -![Enable/Disable PPE](/images/passwordpolicyenforcer/11.0/administration/enabledisableppeconsole.webp) - -Click the toggle to disable PPE: - -![Disable PPE](/images/passwordpolicyenforcer/11.0/administration/disable.webp) - -If PPE  is disabled, click the toggle to enable: - -![Enable PPE](/images/passwordpolicyenforcer/11.0/administration/disabled.webp) - -### Connected To - -Sets the configuration for **Domain** (default) or **Local**. Password Policy Enforcer's -configuration settings are stored in Active Directory or the registry. An Active Directory -configuration is called a domain configuration, and it defines the password policies for domain user -accounts. A registry configuration is called a local configuration, and it defines the password -policies for local user accounts. - -Domain configurations are stored in the **CN=Password Policy Enforcer** _version\*\*_,CN=System -object\*\*. - -Local configurations are stored in the **HKLM\SOFTWARE**ANIXIS**\Password Policy Enforcer** -_version\*\*_\ registry key\*\*. - -:::note -Users with write permission to these objects can configure Password Policy Enforcer. -::: - - -**Domain** - -- Defines policies for domain user accounts. -- Select a Domain Controller from the list of domain controllers where PPE is installed. -- Configuration is replicated to all the domain controllers in the domain. - -![Connect To Domain Configuration](/images/passwordpolicyenforcer/11.0/administration/connecttodomain.webp) - -**Local** - -- Defines policies for local user accounts. -- Only affects the computer where it is set. -- You can copy a local configuration to another computer by exporting the configuration from the - registry, and then importing it into the registry of the other computer. You can also use Group - Policy to distribute a local configuration to many computers. See the - [Domain and Local Policies](/docs/passwordpolicyenforcer/11.0/installation/domain_and_local_policies.md) topic for additional information. - -![Connected To Local Configuration](/images/passwordpolicyenforcer/11.0/administration/connecttodomain.webp) - -### Help - -Links to documentation and support tools. - -- **Netwrix Help Center** launches the Password Policy Enforcer help. -- **About** displays the Configuration Console version. -- **Export Configuration Report** opens an export dialog. You can export the configuration as an - html or txt file. Browse to the folder where you want the report. -- **Open Property Editor** launches the Property Editor. - - :::note - Properties should only be changed when advised by Netwrix Support. - ::: - - -### Settings - -There are three tabs: - -- General -- Notifications -- License - -#### General - -Open the **Settings** > **General** tab to set up policy and log settings. The general settings -apply to either the domain or to a local computer, depending on your Connected To configuration -setting. - -If you make changes, click **Save** to keep your changes or **Discard** to cancel. - -Here are the default settings. - -![General Settings PPE](/images/passwordpolicyenforcer/11.0/administration/settingsgeneral.webp) - -- **Default policy** sets the policy to be enforced on the domain or local computer unless users - have a different policy assigned to them. -- **Enforce policy when password is reset** requires users, administrators, and helpdesk operators to - comply with the password policy when resetting a password or creating a new user account. Default - is checked. - - - Minimum Age rule is never enforced during a reset. - - History rule is enforced if this option is selected and the **Enforce this rule when a - password is reset** option is selected on the [History Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/history_rule.md) Properties. - -- **Accept encrypted client request only** specifies requests from Password Policy Client, Netwrix - Password Reset and Password Policy/Web must be encrypted. Client requests don't contain passwords - or password hashes. See the [Password Policy Client](/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/password_policy_client.md) topic for - additional information. Default is checked. -- **Log event when password not checked by service** adds an entry to the Windows Application Event - Log whenever it accepts a password without checking it. Default is checked. This can occur if: - - - Password Policy Enforcer is disabled. - - The policy assigned to a user is disabled. - - No policy is assigned to a user or an error occurs when determining the assigned policy, and a - Default Policy isn't specified. - - A password is reset, and the **Enforce policy when password is reset** isn't selected. - -- **Log event when password rejected by service** adds an entry to the Windows Application Event Log - whenever a password is rejected. Default isn't checked. The logged event includes: - - - Username - - Source (client or server) - - Rules the password doesn't meet. - - :::note - Passwords or password hashes aren't sent over the network. - ::: - - - Most rules are enforced by both the Password Policy Client and Password Policy Server. If the - Password Policy Enforcer Client is installed, a non-compliant password can be rejected before - Windows sends it to the domain controller. The following limitations apply when a password is - rejected by the Password Policy Client: - - - An event is only logged if the Password Policy Enforcer Client version is 9.0 or later. If a - password is rejected by the Password Policy Server, then the event is logged. - - Client logged events only show the local rules the password violated. For example, the - Compromised rule is only enforced by the Password Policy Server. See the [Rules](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/rules.md) - topic for additional information. - - Client rejections can be lost or duplicated if there are communication issues between the - Password Policy Client and Password Policy Server. - -- **Log event when password accepted by service** adds an entry to the Windows Application Event Log - whenever a password is accepted. The logged event includes the username. Default isn't checked. - -#### Notifications - -Open the **Settings** > **Notifications** tab to set up notifications. Notifications are only -available when **domain** is selected with the Connected To configuration setting. - -If you make changes, click **Save** to keep your changes or **Discard** to cancel. - -Here are the default settings. - -![Notifications Settings](/images/passwordpolicyenforcer/11.0/administration/settingsnotifications.webp) - -- **Send email reminders**: check this option to send reminders. Default isn't checked. - - - **SMTP Server**: enter IP address. - - **Port**: enter port number. - - **Username**: enter your username. - - **Password**: enter your password. - - **Use TLS**: check this option to enable TLS email encryption. - -- **Save email to a pickup folder**: check this option to have the Mailer save emails to a folder - for later delivery by a mail server. The mail server must monitor this folder for new email. - - - **Path**: Click **Browse** and select the path to the pickup folder. - -:::note -Saving email to a pickup folder is the fastest and most reliable delivery method. Use this -option if your mail server supports pickup folders. -::: - - -The Password Policy Enforcer Mailer sends emails at 2:00 AM every day (local time on your server). -Check the Windows Application Event Log to monitor its progress. You can also run the Password -Policy Enforcer Mailer from the command line to send email immediately, or to troubleshoot problems. - -:::note -You can change the time the mailer runs. Set the **PPE Mailer** service startup to -**Disabled** or **Manual**, then stop the service. Create a task to run "**PPEMail /send**" at the -desired time. -::: - - -#### License - -Open the **Settings** > **License** tab to view your current license. The license settings apply to -either the domain or to a local computer, depending on your Connected To configuration setting. - -To add or update your license, copy it from the email or file, then click **Paste license from -clipboard**. - -![License Settings Tab](/images/passwordpolicyenforcer/11.0/administration/settingslicense.webp) - -- **License type** and **Licensed to** are set based on your sales agreement. -- **Users** is the total number of available licenses. -- **AD Users** is the total number of Active Directory user accounts. -- **In use pertains** to active AD user accounts, disregarding disabled accounts. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/_category_.json b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/_category_.json deleted file mode 100644 index eed0fd644e..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Policies", - "position": 20, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "manage_policies" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/manage_policies.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/manage_policies.md deleted file mode 100644 index aa3712a5f3..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/manage_policies.md +++ /dev/null @@ -1,206 +0,0 @@ ---- -title: "Manage Policies" -description: "Manage Policies" -sidebar_position: 20 ---- - -# Manage Policies - -Netwrix Password Policy Enforcer can enforce up to 256 different password policies. You can assign -policies to users directly, or indirectly through Active Directory security groups and containers -(Organizational Units). See the [Assign Policies to Users & Groups](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/usersgroups.md) topic for -additional information. - -Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -![Configuration Console Dashboard](/images/passwordpolicyenforcer/11.0/evaluation/ppedashboard.webp) - -The Configuration Console dashboard shows **No password policies have been set up** when you are -getting started with Password Policy Enforcer. After you **Add a policy**, the dashboard shows the -defined policies and tool links. In this example, the Default Password Policy and CIS Password -Policy Guide have been added. - -![Dashboard with Policies](/images/passwordpolicyenforcer/11.0/administration/ppedashboardpolicies.webp) - -The policy management links are all on the Password Policies tile: - -- Add a Policy. -- Set Up a Policy (click existing policy name). -- Test Policy. -- Set Priorities. -- Export. -- Context menu (3 stacked dots) beside each defined policy Make Copy, Make Default/Remove Default, - Rename and Delete . - -## Add a Policy - -**Step 1 –** Click **Add policy** from the Configuration Console. - -**Step 2 –** Enter a unique policy name. Maximum is 32 characters. - -**Step 3 –** Select a Policy template or **None** if you are creating your own. - -**Step 4 –** Click **Create policy**. - -Alternatively, you can select an existing policy and use the Context menu Make Copy option to start -with the selected policy. - -### Policy Templates - -Password Policy Enforcer contains Built-in Policy Templates based on the requirements of the -most popular regulatory frameworks. - -- Center for Internet Security (CIS) Password Policy Guide – See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- Center for Internet Security (CIS) Password Policy Guide MFA – See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- Cybersecurity Information Sharing Act (CISA) -- Criminal Justice Information Services (CJIS) Security Policy -- Cybersecurity Maturity Model Certification (CMMC) -- Defense Federal Acquisition Regulation Supplement (DFARS) -- Gramm-Leach-Bliley Act (FedRAMP) -- Federal Information Security Management Act (FISMA) -- Health Insurance Portability and Accountability Act (HIPPA) – HIPAA Security Rule requires that - organizations must implement procedures for creating, changing, and safeguarding passwords. - - - It also recommends training the workforce on ways to safeguard password information and - establish guidelines to create and change passwords in a periodic cycle. - - HIPAA doesn’t offer any specific password complexity guidelines. To comply with HIPAA, - organizations are better off following NIST password guidelines. - - Most of healthcare institutions use the NIST framework. - -- International Organization for Standardization (ISO/IEC) 27002 – See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. -- North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) – - See the - [CIP-007-6 — Cyber Security – Systems Security Management](https://www.nerc.com/_layouts/15/PrintStandard.aspx?standardnumber=CIP-007-6&title=Cyber%20Security%20-%20System%20Security%20Management&Jurisdiction=United%20States) article - for additional information. -- National Institute of Standards and Technology (NIST) Special Publication 800-171 -- National Institute of Standards and Technology (NIST) Special Publication 800-53 -- National Institute of Standards and Technology (NIST) Special Publication 800-63b – See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. -- Payment Card Industry Data Security Standard (PCI DSS) – See the - [PCI Document Library](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss) web - site for additional information. -- Payment Card Industry Data Security Standard (PCI DSS) (version 4) - -## Set Up a Policy - -After you add a policy, it needs to be set up or reviewed if you used a template. Click the policy -name to edit the policy. For each policy: - -- Set up [Rules](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/rules.md). -- [Assign Policies to Users & Groups](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/usersgroups.md). -- Enable the use of an optional [Passphrase](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/passphrases.md). -- Set up [Policy Properties](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/policy_properties.md). -- Set up [Messages](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/messages.md) for your users. - -## Test Policy - -Launches the Test policy tool in a separate window. You can test **By user** and by **Password bulk -test**. See the [Test Policy](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/testpolicy.md) topic for additional information. - -## Set Priorities - -Set priorities determines which policy to enforce if users have more than one policy. Click **Apply -priorities** to save the new order. - -![Set priorities](/images/passwordpolicyenforcer/11.0/administration/policypriority.webp) - -### Policy Selection Flowchart - -This flowchart shows how Password Policy Enforcer determines a policy for each user. Use the -[Test Policy](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/testpolicy.md) tool to quickly determine which policy Password Policy Enforcer is -enforced for a particular user. - -![managing_policies](/images/passwordpolicyenforcer/11.0/administration/managing_policies.webp) - -## Export - -Exports your policy configuration to **C:\Program Files\Password Policy -Enforcer\Report\report.html** - -## Make Copy - -Duplicates a policy. This context menu item is also available when you are editing a policy. - -**Step 1 –** Click the context menu next to the policy to copy. - -**Step 2 –** Select **Make copy** from the context menu. - -**Step 3 –** Enter a unique name for the policy. - -**Step 4 –** Click **Make copy**. - -## Make Default/Remove Default - -Assigns the selected policy as the default, or removes the selected policy as the default. These -context menu items are also available when you are editing a policy. - -**Step 1 –** Click the context menu next to the policy to set as the default. - -**Step 2 –** Select **Make default** from the context menu. The policy is assigned to all domain -users who don't have a specific policy assigned. **Default** is indicated in the policy list. The -context menu changes to **Remove Default**. - -:::note -If you assign a different policy as the default you are prompted that an existing default -is set. -::: - - -## Rename - -Renames a policy. - -**Step 1 –** Click the context menu next to the policy to rename. - -**Step 2 –** Select **Rename** from the context menu. - -**Step 3 –** Enter a unique name for the policy. - -**Step 4 –** Click **Rename**. - -## Delete - -Deletes a policy. This context menu item is also available when you are editing a policy. - -**Step 1 –** Click the context menu next to the policy to delete. - -**Step 2 –** Select **Delete** from the context menu. - -**Step 3 –** Click **Delete**. A warning confirmation is displayed if you delete the default policy. - -## Exempt Users from a Password Policy - -You can exempt users from having to comply with the password policy when a default policy is -specified. - -**Step 1 –** Create a new policy for these users. - -**Step 2 –** Leave all the rules disabled for this policy. - -**Step 3 –** Assign this policy to the users who don't have to comply with any Password Policy -Enforcer rules. - -:::warning -If Password Policy Enforcer has only one policy and that policy is also the default -policy, then Password Policy Enforcer enforces the policy for all users. -::: - - -The Password Policy Client and Password Policy Server communicate over UDP port 1333 by default. If -you need to change the default port, then enter the new port number in the **Password Policy Server -Port** text box. Setting the port number to zero stops Password Policy Enforcer from accepting -client requests. If you change the port number, then you must also: - -- Restart all the Password Policy Server computers. -- Configure the Password Policy Client to use the new port. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/messages.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/messages.md deleted file mode 100644 index 6ff78f5030..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/messages.md +++ /dev/null @@ -1,66 +0,0 @@ ---- -title: "Messages" -description: "Messages" -sidebar_position: 50 ---- - -# Messages - -Each Password Policy Enforcer password policy has multiple message templates, one for each of the -Password Policy Client messages. - -- Password Policy – Displays the password policy guidelines on clients that have the Netwrix - Password Policy Enforcer Client installed. -- [POLICY] – Customize the text for the active rules. -- [LIVE_POLICY] – Password Policy Client (10.2 and above) messages can be configured to display live - feedback for the active rules to users as they enter their passwords. This feature enables users - to see if their passwords meet the requirements of the policy set by the organization. Here is an - example of a live policy message. - - ![Messages](/images/passwordpolicyenforcer/11.0/administration/mesages2.webp) - - :::note - Start each custom message with two spaces, a hypen, and a space before your message so - the X and checks can appear for the rule. For example: " **- Include an upper case alpha - character.**" The quotes are only there to illustrate the message. - ::: - - -- Rejection Reason – Displays why an intended password was rejected on clients that have the Netwrix - Password Policy Enforcer Client installed -- Generic Rejection – Displays if Password Policy Enforcer doesn't have a specific reason for the - rejection, generally because the password doesn't comply with the Windows password policy - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -**Step 2 –** Click a policy name to open the policy configuration page. - -**Step 3 –** Open the **Messages** tab. - -![Set up messages](/images/passwordpolicyenforcer/11.0/administration/messages.webp) - -**Step 4 –** Select the message language from the dropdown list. You can set messages for multiple -languages. You don't have to create a Password Policy Enforcer policy for each language. To set -multiple languages, pick one, edit the message templates. Select another language, and edit the -message templates. Repeat for each language you want to implement. The correct message is displayed -to users based on their selected language. - -**Step 5 –** Edit the message templates in the Password policy, [POLICY], [LIVE_POLICY], Rejection -Reason, and Generic rejection messages for any of the components you want to use. - -**Step 6 –** Insert the macros into your message. Click **Macro** and pick one to insert it. - -![Use macros for your message](/images/passwordpolicyenforcer/11.0/administration/messagesmacros.webp) - -**Step 7 –** Click **Save** and review your changes in the Preview area. Click **Save** f you edit -the message. - -:::note -If you don't see the **Preview**, contact your network administrator to set up the -firewall to allow Password Policy Enforcer to communicate. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/passphrases.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/passphrases.md deleted file mode 100644 index aafca3229c..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/passphrases.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Passphrase" -description: "Passphrase" -sidebar_position: 30 ---- - -# Passphrase - -Passphrases have gained popularity in recent years as they can be more difficult to crack and easier -to remember than passwords. The difference between passwords and passphrases is their length. -Passwords are rarely longer than 15 characters, but passphrases commonly contain 20 or more -characters. - -Complexity and dictionary rules are less important for passphrases as passphrases rely primarily on -length for security. You may want to relax some password policy requirements for passphrases. - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -**Step 2 –** Click a policy name to open the policy configuration page. - -**Step 3 –** Open the **Passphrase** tab. - -![Enable Passphrases](/images/passwordpolicyenforcer/11.0/administration/passphrase.webp) - -**Step 4 –** Select the number of characters the password must contain before the selected rules are -disabled. - -**Step 5 –** Select the rules to be disabled. - -Disabled rules aren't counted when calculating the compliance level, but Password Policy Enforcer -accepts passphrases that comply with all enabled rules, irrespective of the compliance level. This -ensures that passphrases can be used, even if they don't meet the compliance level when Password -Policy Enforcer is configured to disable one or more rules for passphrases. - -:::note -Opinions differ on how long a passphrase needs to be. Even a 30 character passphrase can -be weaker than a well-chosen password. Don't disable too many rules under the assumption that -length alone makes up for the reduced complexity. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/policy_properties.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/policy_properties.md deleted file mode 100644 index 8e8c8ec87e..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/policy_properties.md +++ /dev/null @@ -1,87 +0,0 @@ ---- -title: "Policy Properties" -description: "Policy Properties" -sidebar_position: 40 ---- - -# Policy Properties - -Sets the properties for the selected policy. - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -**Step 2 –** Click a policy name to open the policy configuration page. - -**Step 3 –** Open the **Properties** tab. - -![Set the Policy Properties](/images/passwordpolicyenforcer/11.0/administration/properties.webp) - -Each policy must have a unique name. To change the name of a policy, enter the new name in the text -box. - -Enter any **Notes** about the policy - -Select the **Default characters set**. The default value (Netwrix Password Policy Enforcer) requires -users to comply with rules that use the Password Policy Enforcer character set. Choose the alternate -option (Windows) to have users comply with rules that use the Windows character set. - -:::note -Only Password Policy Enforcer 10.0 and higher contain the Windows character set. Password -Policy Enforcer 9, Netwrix Password Reset and Password Policy Enforcer/Web 7 (and older for all -products) always use the Password Policy Enforcer character set. -::: - - -- Some languages such as Japanese don't distinguish between uppercase and lowercase. These - characters are in the Windows Alpha set, but not in the Upper or Lower sets. -- Characters classified as a space, punctuation, control, or blank by Windows are included in the - Special character set. If these characters are also included in some other set by Windows (for - example, a superscript one is both a decimal digit and punctuation), then Password Policy Enforcer - only includes them in the Special character set when the Windows character set is selected. -- When using the Password Policy Enforcer character set, all characters above ANSI 126 are included - in the High set. When using the Windows character set, a character is only included in the High - set if it is above ANSI 126 and not included in any other set by Windows. - -Select the number of rules for **Passwords must comply with** from the dropdown list to specifiy -the required compliance level for this policy. The default value **(all the rules**) requires users -to comply with all enabled rules. Choose an alternative option if Password Policy Enforcer should -enforce a more lenient password policy. The Minimum Age and Maximum Age rules are excluded from -compliance level calculations. See the [Rules](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/rules.md) topic for additional information. - -When setting the compliance level, consider that some rules may be disabled when a user enters a -passphrase. See the [Passphrase](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/passphrases.md) topic for additional information. Password Policy -Enforcer accepts passphrases that comply with all enabled rules, irrespective of the compliance -level. This ensures that passphrases can be used, even if they don't meet the compliance level when -Password Policy Enforcer is configured to disable one or more rules for passphrases. - -Password Policy Enforcer can start a password synchronization application or script whenever a user -successfully changes their password. Enter the full path to the executable in the **Execute the -program when password is changed** text box. The path can contain environment variables like -`%SystemRoot%`. Every computer running Password Policy Enforcer should have a local copy of the -program, and only authorized users should have access to it, or any of its components. - -The user logon name and new password are sent to the program as command-line parameters. For -example, if you add the following commands to a batch file, Password Policy Enforcer records each user's -logon name and new password in a text file named **passwords.txt**: - -**echo Username: %1 >> c:\passwords.txt** - -echo Password: %2 >> c:\passwords.txt - -:::warning -This script is shown as an example only. You shouldn't store user passwords. -::: - - -The command can now include the [USERNAME] and [PASSWORD] macros. If neither is specified, then the -command is executed with both parameters to maintain compatibility with existing programs/scripts. - -:::info -Use the [USERNAME] parameter if the password isn't needed by the program/script -so that the password isn't unnecessarily sent to the change notification command/script. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/character_rules.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/character_rules.md deleted file mode 100644 index a5b2351e37..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/character_rules.md +++ /dev/null @@ -1,102 +0,0 @@ ---- -title: "Character (Granular) Rules" -description: "Character (Granular) Rules" -sidebar_position: 40 ---- - -# Character (Granular) Rules - -Password Policy Enforcer has seven Character rules that reject passwords if they contain, or don't -contain certain characters. These rules can increase password strength or ensure password -compatibility with other systems. - -![Character (Granular) Rule](/images/passwordpolicyenforcer/11.0/administration/chargranular.webp) - -All the Character rules work identically, but each has their own default character set. A character -set is the collection of characters that each rule searches for when checking a password. You can -use the Character rules with their default character sets, or define your own. By default, the -Password Policy Enforcer selects the Password Policy Enforcer character on the -[Set Priorities](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/manage_policies.md#set-priorities) page. - -:::note -Only Password Policy Enforcer 11 and later contain the Windows character set. -Password Policy Enforcer 9, Netwrix Password Reset3 and Password Policy Enforcer Web 7 (and older -for all products) use the Password Policy Enforcer character set. -::: - - -Select the **Characters (Granular)** checkbox to enable the Characters rule. - -For each selected character set, select whether they **Contain** or **Not contain** the specified -number of characters. - -Select the **contain** option if this rule should ensure that new passwords contain certain -characters. Only one character is required by default, but you can specify a different value by -choosing the required number of characters from the dropdown list beside the **contain** option. - -Select the **not contain any...** option if this rule should ensure that new passwords don't -contain certain characters. - -You can further restrict the rule by defining positions or embedding characters. - -Click the + sign by the character set. - -Select **In position**. - -![Restricting Characters](/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict.webp) - -If you want to restrict this rule to certain character positions, choose the starting position from -the first entry box and the ending position from the second entry box. For example, you may want to -enforce a rule that requires a numeric character in the second character position to maintain -compatibility with some other system. - -![Require a number in position 2](/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict2.webp) - -Click the + sign by the character set. - -Select **Embedded**. - -Select the **Embedded** checkbox if users are required to embed these characters within their -passwords. For example, the passwords "12hello", "1hello", and "hello$987" don't contain any -embedded numeric characters, but these passwords do contain embedded numeric characters (shown in -bold type): "he**7**llo", "4he**3**llo", "23hello**7**$45". Embedded numeric and special characters -can help to protect passwords from cracking attacks. - -:::note -The First Character, Last Character, and Complexity rules are easier to configure, and -easier for users to understand. Use these rules instead of the Character rules if they can enforce -your desired policy. -::: - - -You can customize character sets with the Characters option for a selected set. - -**Step 1 –** Click **Characters** beside a selected Character set. - -**Step 2 –** Enter a **Name**. This example uses **vowels**. - -![Set up custom character set](/images/passwordpolicyenforcer/11.0/administration/chargranularvowel.webp) - -**Step 3 –** Enter the **Characters**. This example uses **AaEeIiOoUu**. - -**Step 4 –** Click **Apply**. - -If you save and test the policy, you see **vowels** is listed as a requirement. - -To remove a custom set, click **Characters** and delete the information. Click **Apply**. - -### Enforcing Complex Character Requirements - -Character rules can be combined to enforce complex password requirements. For example, you may need -to enforce a policy such as "passwords must contain a numeric character, but not in the first two -positions" to ensure compatibility with some other system. - -This is done by using two of the Character rules: - -Set **Characters (Complexity)** to require 1 Numeric character. - -![Require a numeric value](/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict3.webp) - -Set **Characters (Granular)** to not contain numeric values in the first two positions. - -![Don't allow numeric values in first two positions](/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict4.webp) diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/complexity_rule.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/complexity_rule.md deleted file mode 100644 index ef45a3b908..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/complexity_rule.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Characters (Complexity) Rule" -description: "Characters (Complexity) Rule" -sidebar_position: 30 ---- - -# Characters (Complexity) Rule - -The Complexity rule rejects passwords that don't contain characters from a variety of character -sets. Using several character types can make passwords more difficult to crack. - -![Character Complexity Rule](/images/passwordpolicyenforcer/11.0/administration/charcomplexity.webp) - -Select the **Characters (Complexity)** checkbox to enable the Character Complexity rule. - -Select the number of required character sets. Passwords are rejected if they don't contain -characters from at least the specified number of character sets. - -Select the available character sets. The number of available character sets must be equal to or -greater than the number of required character sets. - -Select the **Passwords must always comply with this rule** checkbox to make the Complexity rule -mandatory. Password Policy Enforcer rules are mandatory by default, but can be made optional by -changing the Reject passwords that don't comply with value in the Policy Properties page. A -mandatory rule can still be disabled when a passphrase is used. See the [Passphrase](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/passphrases.md) -topic for additional information. - -:::note -The Complexity rule uses custom character set definitions from the Character rules, even -if the Character rules are disabled. -::: - - -This default character set contains the following: - -| Rule | Default character set | -| ----------- | ------------------------------------------------------------------------ | -| Alpha Lower | Lowercase alphabetic (a-z) | -| Alpha Upper | Uppercase alphabetic (A-Z) | -| Alpha | Uppercase and lowercase alphabetic (a-z & A-Z) | -| Numeric | Numerals (0-9) | -| Special | All characters not included above | -| High | All characters above ANSI 126 | -| Custom | No default characters | diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/compromised_rule.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/compromised_rule.md deleted file mode 100644 index 3b1ec8512b..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/compromised_rule.md +++ /dev/null @@ -1,26 +0,0 @@ ---- -title: "Compromised Rule" -description: "Compromised Rule" -sidebar_position: 50 ---- - -# Compromised Rule - -The Compromised rule rejects passwords from prior breaches. These passwords shouldn't be used as -they are vulnerable to credential stuffing attacks. - -![Compromised password rule](/images/passwordpolicyenforcer/11.0/administration/compromised.webp) - -Select the **Compromised** checkbox to enable the Compromised rule. - -You can browse to your compromised passwords base files or enter a path into the text box. The path -can contain environment variables like - -:::warning -%SystemRoot%. hash files should only be read from a local disk. Using shared hash files -degrades performance, and could jeopardize security. -::: - - -See the [HIBP Updater](/docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md) topic for the information about the Have I Been Pwnd (HIBP) -database usage. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/dictionary_rule.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/dictionary_rule.md deleted file mode 100644 index f9a9be0b05..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/dictionary_rule.md +++ /dev/null @@ -1,157 +0,0 @@ ---- -title: "Dictionary Rule" -description: "Dictionary Rule" -sidebar_position: 60 ---- - -# Dictionary Rule - -The Dictionary rule rejects passwords that are vulnerable to guessing, hybrid, and precomputed -attacks. These attacks can crack weak passwords in seconds, and they can be very effective if -passwords are based on common words. - -![Dicitonary Rule](/images/passwordpolicyenforcer/11.0/administration/dictionary.webp) - -There are two Dictionary rules in each password policy. You can use the second rule with a different -dictionary file, or to enforce a more tolerant policy for passphrases by disabling the primary rule -for long passwords. - -Select the **Dictionary** checkbox to enable the Dictionary rule. - -Browse to a dictionary file. A sample file **Dict.txt** is installed in the **\Program -Files\Password Policy Enforcer** folder. This file is sorted and ready to use. It contains -approximately 257,000 words, names, and acronyms. - -Select the **Detect inclusion of non-alpha characters** checkbox if Password Policy Enforcer should -remove all non-alphabetic characters during analysis. This allows Password Policy Enforcer to reject -passwords such as "myp8asswor8d." - -Select the **Detect character substitution** checkbox if Password Policy Enforcer should reject -passwords that rely on character substitution to comply with this rule. - -Select the **Detect words typed backwards** checkbox if Password Policy Enforcer should -additionally test passwords with their characters reversed. Enabling bi-directional analysis stops -users from circumventing this rule by reversing the order of characters in their password. For -example, a user may enter "drowssapym" instead of "mypassword". - -Select the **Wildcard analysis** checkbox if Password Policy Enforcer should search for wildcard -templates in the dictionary file. Wildcard templates are specially formatted dictionary words that -Password Policy Enforcer uses to reject a range of passwords. The Dictionary rule supports two -wildcard template formats: - - - - - - - - - - - - - - - - - - - - - -
FormatExampleDescription
Prefix - - - - - - - - - -
!!BAN*!!
!!2*!!
-
- - - - - - - - - -
Rejects passwords that start with BAN. For example: band, banish, ban, bank, etc.
Rejects passwords that start with the numeric character 2. For example: 2ABC, 2123, etc.
-
- Suffix - - !!*ING!! - - Rejects passwords that end with ING. For example: pushing, howling, trying, etc. -
- - -Partial matching is performed even if Wildcard analysis is disabled. For example, the dictionary -word "password" rejects the passwords "My**Password**$", "**Password**100", and -"12**password**34" even if Wildcard analysis is disabled. - -Wildcard analysis should only be used to limit matching to the characters at the start or end of a -password. - -Enabling Wildcard analysis slightly increases search times, so only enable this option if the -dictionary file contains wildcard templates. The sample dictionary file included with Password -Policy Enforcer doesn't contain any wildcard templates. - -Choose a value from the Tolerance dropdown list to specify the maximum number of consecutive matching characters that Password Policy Enforcer tolerates before rejecting a password. For example, the dictionary word "**sword**" and the password "4my**sword**%" contain five consecutive matching characters (shown in bold). Password Policy Enforcer rejects this password if the tolerance is four or lower, and accepts it if the tolerance is five or higher. - -Click the **Browse** button to select a dictionary file, or enter a path into the text box. The path -can contain environment variables like %SystemRoot%. A sample dictionary is installed in the -\Program Files (x86)\Password Policy Enforcer\ folder. The dictionary file should be read from a -local disk. Using a shared dictionary degrades performance, and could jeopardize security. - -:::note -The `\Program Files (x86)\` folder doesn't exist on 32-bit Windows, so move the -dictionary into the `\Program Files\Password Policy Enforcer\` folder if you have 32-bit and 64-bit -computers sharing a common Password Policy Enforcer configuration. -::: - - -Click the **Sort** button if the dictionary file is being used with Password Policy Enforcer for the -first time, or if words have been added to the file since it was last sorted. The Password Policy -Enforcer management console will sort and reformat the file so that Password Policy Enforcer can use -it. Sorting also removes duplicate words, so the sorted file may be smaller than the original. - -Click the **Messages** tab to customize the Password Policy Client rule inserts. If both Dictionary -rules have identical inserts, then only one of the inserts is shown in the corresponding Password -Policy Client message if the password is rejected by both rules. - -## Creating a Custom Dictionary - -You can add words to the sample dictionary file, or download larger dictionary files from the -Internet. Always sort a dictionary file before using it with Password Policy Enforcer, and ensure -that all computers have a local copy of the updated and sorted file. - -The custom dictionary should meet the following requirements: - -1. The dictionary should begin and end with a blank line. -2. All words are capitalized. -3. The sort button is pressed after pointing to a file in the dictionary rule. - -:::note -If you are using a custom dictionary, use a different filename. The default -dictionary file (dict.txt) may be replaced during an upgrade. -::: - - -## Dictionary File Replication - -Password Policy Enforcer doesn't distribute dictionary file updates to other computers, but you can -use the Windows Distributed File System to ensure that all domain controllers have the latest -dictionary file. Copy the dictionary file into the Sysvol share on one domain controller, and the -Distributed File System will copy the file into the Sysvol share of all other domain controllers. -Configure the Dictionary rule to read the file from \\127.0.0.1\sysvol\your.domain\filename.txt - -This path only works if the computer has a Sysvol share. This won't be the case if you are -using a workstation for policy testing, or if you are using Password Policy Enforcer to enforce -local polices. If you are using Password Policy Enforcer for local policies and want all computers -to receive dictionary file updates, then use the Sysvol share for file replication and a script or -scheduled task to copy the file to a local folder. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/history_rule.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/history_rule.md deleted file mode 100644 index a52d502526..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/history_rule.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "History Rule" -description: "History Rule" -sidebar_position: 70 ---- - -# History Rule - -The History rule rejects passwords that are identical to recently used passwords. Password reuse -should be avoided because it defeats the purpose of regular password changes. Password Policy -Enforcer can stop users from reusing passwords for a specified number of password changes or a -number of days. - -![History rule](/images/passwordpolicyenforcer/11.0/administration/history.webp) - -Select the **History** checkbox to enable the History rule. - -Select one of the options: - -**One of the last** option to stop passwords from being reused for a specified number of password -changes. Choose the number of password changes from the dropdown list. - -**A password used in the last** option to stop passwords from being reused for a specified number of -days. Enter the number of days in the text box. - -Choose an item from the **Hash function** dropdown list. Argon2 is recommended for best security. -The Argon2 option uses 100,000 times more computing power to create a hash, so an attacker needs -100,000 more computing power to crack Argon2 hashes. Argon2 increases password change times by 400%, -so a domain controller that can handle 1,000 password changes a minute with SHA-256 can be expected -to handle 250 password changes a minute with Argon2. All numbers are approximate. Use Argon2 if your -domain controllers can handle the load. - -:::note -Changing the **Hash function** doesn't modify existing history records. It sets the -function to be used for new password history records. If a user has Argon2 and SHA-256 hashes in -their password history, then Password Policy Enforcer calculates both the Argon2 and SHA-256 hashes -during a password change to ensure the new password isn't in the password history. -::: - - -The History rule is normally not enforced when a password is reset. Select the **Enforce this rule -when a password is reset** checkbox to override the default behavior. You must also select the -**Enforce policy when password is reset** option in the PPS Properties page to enforce this rule -when a password is reset. - -Click the **Messages** tab to customize the Password Policy Client rule inserts. - -:::note -The History rule isn't enforced when testing passwords from the Test Policies page. -::: - - -Password Policy Enforcer updates a user's password history whenever their password changes. The -password history is updated even if Password Policy Enforcer or the assigned policy is disabled. A -user's password history is deleted if the user doesn't have an assigned policy, or if the History -rule is disabled at the time of the password change. - -Password Policy Enforcer's password history is stored in Active Directory for domain user accounts, -and in the registry for local user accounts. You can create a new Active Directory attribute for the -password history, or configure Password Policy Enforcer to use an existing attribute. - -Disable Password Policy Enforcer's History rule if you don't want Password Policy Enforcer to store -the password history. - -:::note -Password Policy Enforcer doesn't store passwords in the password history, it only stores -the Argon2 or SHA-256 hashes. A salt protects the hashes from precomputed attacks, including rainbow -tables. If you don't want Password Policy Enforcer to store a password history, then leave the -History rule disabled. You can use the Windows History rule together with Password Policy Enforcer's -other rules to enforce your password policy. -::: - - -Password Policy Enforcer can store up to 100 password hashes for each user, but it only stores the -minimum needed to enforce the current password policy. For example, if Password Policy Enforcer is -configured to reject the last 24 passwords, then only the last 24 password hashes are stored. -Reconfiguring Password Policy Enforcer to reject the last 30 passwords won't have an immediate effect because only 24 password hashes are stored. The full effect of the new configuration is realized after users change their passwords six more times, at which point Password Policy Enforcer has 30 stored password hashes for each user. - -Leave both the Windows and Password Policy Enforcer History rules enabled when transitioning from -one to the other. This allows the old rule to enforce the policy until the new rule has built up its -password history. The old rule can be disabled after users have completed the required number of -password changes to enforce the new rule. - -As Password Policy Enforcer is limited to storing the last 100 password hashes, it is possible for -the History rule to run out of storage space before the specified number of days. Use the Minimum -Age rule to avoid this problem. For example, if the History rule is configured to not allow password -reuse for 365 days, then set the minimum password age to four or more days. Even if a user changes -their password every four days, they can only perform 91 password changes in 365 days. - -## Creating a New Attribute for the Password History - -Windows stores a domain user's password history in two Active Directory attributes, but these -attributes can't be used by other applications. Password Policy Enforcer can store the password -history in a new or existing attribute. A new attribute is recommended, but you can use an existing -attribute if you don't want to extend the AD schema. An AD attribute is only needed for domain user -accounts because the password history for local user accounts is stored in the registry. - -:::warning -Password Policy Enforcer's password history attribute is confidential to stop -authenticated users from accessing the password history of other users. See the Microsoft Article -[Mark an attribute as confidential in Windows Server 2003 Service Pack 1](http://support.microsoft.com/kb/922836) -Microsoft article for additional information. Confidential attributes have additional protection in -Active Directory, but they aren't as well protected as the Windows password history attributes. -There is a higher risk of unauthorized access to the password history if it is stored outside the -Windows password history attributes. -::: - - -Follow the following steps to create a new Active Directory attribute for the password history. - -**Step 1 –** Log on to the server holding the Schema Operations Master role with an account that is -a member of the Schema Admins group. - -**Step 2 –** Open a Command Prompt window to the Password Policy Enforcer installation folder. - -**(\Program Files (x86)\Password Policy Enforcer\)** - -**Step 3 –** Enter the following command: - -**: ldifde -i -f History.ldf -c "DC=X" "DC=yourdomain,DC=yourdomain"** - -Replacing the last parameter with your domain's DN. - -**Step 4 –** Press **ENTER** and check the output for errors. - -![ppe_rules_8](/images/passwordpolicyenforcer/11.0/administration/ppe_rules_8.webp) - -## Using an Existing Attribute for the Password History - -Password Policy Enforcer can store the password history in an existing attribute. The desktopProfile -attribute is well suited because it isn't used by Windows. Other attributes are also suitable if -they aren't being used. Contact [Netwrix Support](https://www.netwrix.com/support.html) if you -would like to use an existing attribute for the password history. - -## Password Histories for Local User Accounts - -The password histories of local user accounts are stored in the HKLM\SECURITY\PPE Password History\ -registry key. Users aren't granted access the HKLM\SECURITY\ registry key by default, so a user -can't read the password history of any user (including themselves). This is also true for members -of the Administrators group, but administrators can change the default permissions. If an -administrator accesses the password history they might be able to extract the hashes for cracking, -but they can't extract the passwords directly because the password history doesn't contain any -passwords. - -:::warning -The password history of a local user account isn't automatically deleted when the user -account is deleted. If a local user account is deleted, then another local user account is created -on the same computer with the same username, the new user will inherit the deleted user's password -history. The default registry permissions stop users from accessing their own password history, so -it is difficult for the new user to use this information. They could try to guess the deleted user's -password during a password change to see if it is rejected by the History rule, but they would only -have a few attempts to guess correctly before the old hashes are overwritten with new hashes. The -user's current password is validated, and the Windows Minimum Age rule is enforced before the -password history is checked, so every compliant and incorrect password guessed will overwrite one -hash in the password history. This information applies only to local user accounts. The password -history for domain user accounts is deleted when users are deleted. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/length_rule.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/length_rule.md deleted file mode 100644 index d845e287c3..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/length_rule.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: "Length Rule" -description: "Length Rule" -sidebar_position: 80 ---- - -# Length Rule - -The Length rule rejects passwords that contain too few or too many characters. Longer passwords are -generally stronger, so only specify a maximum password length if password compatibility must be -maintained with a system that can't accept long passwords. - -![Length rule](/images/passwordpolicyenforcer/11.0/administration/length.webp) - -Select the **Length** checkbox to enable the Length rule. - -Select one of the options: - -**At least** specifies the minimum number of characters that passwords must contain. Choose the -minimum number of characters from the dropdown list. - -**No more than** specifies the maximum number of characters that passwords can contain. Choose the -maximum number of characters from the dropdown list. - -**Between** specifies the minimum and maximum number of characters that passwords can contain. -Choose the minimum number of characters from the first dropdown list, and the maximum from the -second drop- down list. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/maximum_age_rule.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/maximum_age_rule.md deleted file mode 100644 index 30d48cbc2b..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/maximum_age_rule.md +++ /dev/null @@ -1,117 +0,0 @@ ---- -title: "Age (Max) Rule" -description: "Age (Max) Rule" -sidebar_position: 10 ---- - -# Age (Max) Rule - -The Maximum Age rule forces users to change their passwords regularly. This decreases the likelihood -of an attacker discovering a password before it changes. This rule can only be enforced by domain -policies. - -![Maximum Age rule](/images/passwordpolicyenforcer/11.0/administration/agemax.webp) - -Select the **Age (Max)** checkbox to enable the Maximum Age rule. - -Choose a value from the first days dropdown list to specify how many days must elapse before -passwords expire. - -You can encourage users to choose longer passwords by extending the lifetime of their password if it -exceeds a certain length. To enable this feature, choose a higher value from the second days -dropdown list and a minimum length from the contains dropdown list. Passwords that contain the -required number of characters don't expire until the second (higher) days value. If both days -values are identical, then passwords will expire after the specified number of days, irrespective of -length. - -:::note -When the Maximum Age rule is configured to delay the expiry of longer passwords, it -creates an Active Directory security group called "PPE Extended Maximum Age Users". Password Policy -Enforcer uses this group to identify which users are eligible for a delayed password expiry. Users -are added and removed from the group automatically. You can move and rename this group, but don't -change the pre-Windows 2000 name. Contact Netwrix support if you must change the pre-Windows 2000 -name. Change a Password Policy Enforcer configuration setting (any setting) after moving or renaming -the group to trigger a cache update in Password Policy Enforcer. Password Policy Enforcer recreates -this group if you delete it. To stop creating a group, make the two days values equal in all -policies. -::: - - -Choose a value from the Mode dropdown list to specify how Password Policy Enforcer handles expired -passwords. The Standard mode forces all users with expired passwords to change their password during -logon. The Transitional modes force a percentage of users with expired passwords to change their -password during logon. The Warning mode warns users that their password has expired without forcing -them to change it. - -Use the Warning and Transitional modes to gradually introduce a new password policy. These modes -reduce the number of forced password changes, allowing the help desk to deal with any extra calls -relating to the new policy. Switch to the Standard mode after most users have had a chance to change -their password. - -It takes approximately 50 days for all users with expired passwords to be forced to change them in -the 2% Transitional mode (2% every day). The 5% Transitional mode reduces this to 20 days, and the -10% Transitional mode further reduces it to 10 days. The selection algorithm is randomized, so these -are estimates only. You must switch to the Standard mode to ensure that all old passwords will -expire. - -Users with expired passwords are always prompted to change their password, even in the Transitional -and Warning modes. Users can ignore the prompt to change their password unless they are being forced -to change it. - -:::note -The password expiry prompt is a Windows client feature, and is displayed even if the -Password Policy Client isn't installed. Windows clients display the prompt 5 days before passwords -expire by default. You can alter this behavior in the Windows Group Policy security settings. See -the -[Interactive logon: Prompt user to change password before expiration](https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/interactive-logon-prompt-user-to-change-password-before-expiration) -Microsoft article for additional information. -::: - - -Password Policy Enforcer expires passwords at 1:00 AM every day on the domain controller holding the -PDC emulator operations master role. It sets "User must change password at next logon" for users -whose password has expired, or is due to expire on that day. Password Policy Enforcer doesn't -expire passwords if the Maximum Age rule is in Warning mode, or for users with "Password never -expires" set in Active Directory. Some passwords won't expire immediately when the Maximum Age -rule is in a Transitional mode. - -### Set up Email - -Click the **Set up email** to configure the e-mail message options. - -Enter the name and email address you want to appear in the email's From field in the **From** text -box. The correct format is "Display Name" `` - -Enter the text for the email's Subject field in the **Subject** text box. - -Enter the body of the email in the large text box. The email is sent as plain text unless the body -includes the `` tag. If sending email as HTML, you must include the complete HTML document -starting with `` and ending with ``. If the body is too long to fit in the text box, -enter a path to a file like this: - -`file:C:\path\filename.ext` - -The path can contain environment variables like %SystemRoot%. Don't use quotes for long filenames -and don't include any other text. The Password Policy Enforcer Mailer will read the email body from -the specified file. - -The email's subject and body can contain various macros. Use these macros to personalize the email. - -| Macro | Replaced with | -| ------------------- | ------------------------------------- | -| [LOGON_NAME] | User's logon name | -| [FIRST_NAME] | User's first name | -| [LAST_NAME] | User's last name | -| [DAYS_TO_EXPIRY] | Days until password expires | -| [EXPIRY_DATE] | Expiry date in short format | -| [EXPIRY_DATE_LONG] | Expiry date in long format | -| [EXPIRY_DAY] | Expiry day (1 to 31) | -| [EXPIRY_DAY_NAME] | Expiry day (Monday, Tuesday, ...) | -| [EXPIRY_MONTH] | Expiry month (1 to 12) | -| [EXPIRY_MONTH_NAME] | Expiry month (January, February, ...) | -| [EXPIRY_YEAR] | Expiry year (2021, 2022, ...) | - -### Set up SMTP - -Opens the Notification settings. See the [Configuration Console](/docs/passwordpolicyenforcer/11.0/admin/configconsole.md) topic for -additional details. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/minimum_age_rule.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/minimum_age_rule.md deleted file mode 100644 index a9f0560ec2..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/minimum_age_rule.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: "Age (Min) Rule" -description: "Age (Min) Rule" -sidebar_position: 20 ---- - -# Age (Min) Rule - -The Minimum Age rule stops users from quickly cycling through a series of passwords to -evade the History and Similarity rules. This rule can only be enforced by domain policies. - -![Minimum age rule](/images/passwordpolicyenforcer/11.0/administration/agemin.webp) - -Select the **Age (Min)** checkbox to enable the Minimum Age rule. - -Select the number of days before a user can change their password. - -:::note -The Minimum Age rule is unique because users can't comply with it by choosing a different -password; they must wait until the required number of days has elapsed. The Password Policy Client -consequently handles rejections by this rule differently to other rules. Rather than displaying the -usual message components, the Password Policy Client only displays the Minimum Age rule's Reason -insert. See [Password Policy Client](/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/password_policy_client.md) topic for additional information. -The Rejection Reason template, macros, and inserts from other rules aren't displayed when a -password change is denied by the Minimum Age rule. -::: - - -The Minimum Age rule isn't enforced during policy testing, but the test log does show the user's -password age. A log entry is also added if the Minimum Age rule would have rejected the password -change. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/patterns.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/patterns.md deleted file mode 100644 index 88b8867c07..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/patterns.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "Patterns Rule" -description: "Patterns Rule" -sidebar_position: 90 ---- - -# Patterns Rule - -The Patterns rule rejects passwords that contain character patterns such as "abcde". Character -patterns weaken the password. - -![Patterns rule](/images/passwordpolicyenforcer/11.0/administration/patterns.webp) - -Select the **Patterns** checkbox to enable the Patterns rule. - -Select **Reject character patterns like "abcde"** to check for character patterns. - -Select **Character patterns** to set the patterns to apply. Default is both **English alphabet -(a-z)** and **Numbers (0-9)**. - -Select **Detect character substitution** if Password Policy Enforcer should reject passwords that -rely on character substitution to comply with this rule. - -Select **Detect words typed backwards** if Password Policy Enforcer should additionally test -passwords with their characters reversed. Enabling this analysis stops users from circumventing this -rule by reversing the order of characters in their password. For example, a user may enter "edcba" -instead of "abcde". - -Choose a value from the **Tolerance** dropdown list to specify the longest pattern that Password -Policy Enforcer allows before rejecting a password. For example, the password "password**wxyz**" -contains a four-character pattern (shown in bold type). Password Policy Enforcer rejects this -password if the tolerance is set to three (or lower), and accept it if the tolerance is set to four -(or higher). Choose the **Auto** value if passwords should be rejected if they only contain a -single, continuous, character pattern. For example, "abcde" would be rejected, but "abcdz" and -"abc123" wouldn't. - -Select **Reject keyboard patterns like "qwerty"** to check for keyboard patterns. - -Select **Keyboard layouts** to set the keyboard type. Default is **United States**. - -Select the type of keyboard pattern: **Horizontal**, **Vertical**, or **Horizontal and Vertical**. - -Select **Detect direction change** for entries that change direction. For example, **qweewq**. - -Select **Detect key repeat** for repeated keys, based on the **Tolerance** value. If Tolerance is 4, -**aaaa** is accepted and **aaaaa** is rejected. - -Select **Detect key skip** for skipped keys, such as **qetuo**. - -Set **Tolerance** for the number of characters in a keyboard pattern is allowed before the password -is rejected. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/repetition.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/repetition.md deleted file mode 100644 index 299c470007..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/repetition.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -title: "Repetition Rule" -description: "Repetition Rule" -sidebar_position: 100 ---- - -# Repetition Rule - -The Repetition rule rejects passwords that contain excessive character or pattern repetition. -Reducing repetition increase resistance to both brute-force and dictionary cracking algorithms. The -Repetition rule isn't case sensitive, so "mypaSssSword" contains four consecutive repeating -characters (SssS). - -![Repetition Rule](/images/passwordpolicyenforcer/11.0/administration/repetition.webp) - -Select the **Repetition** checkbox to enable the repetition rule. - -Select the **Reject repetition** option and set the maximum number of consecutive repeating -characters that passwords can contain. - -Select the **Reject repetition like "wordword" or "p@$s_p@$s"** option to enable pattern repetition. - -Select **Detect character substitution** if Password Policy Enforcer should reject passwords that -rely on character substitution to comply with this rule. - -Select **Detect words typed backwards** if Password Policy Enforcer should additionally test -passwords with their characters reversed. Enabling this analysis stops users from circumventing this -rule by reversing the order of characters in their password. For example, a user may enter "edcba" -instead of "abcde". - -Choose a value from the **Tolerance** dropdown list to specify the longest pattern that Password -Policy Enforcer allows before rejecting a password. For example, the password "password**wxyz**" -contains a four-character pattern (shown in bold type). Password Policy Enforcer rejects this -password if the tolerance is set to three (or lower), and accept it if the tolerance is set to four -(or higher). Choose the **Auto** value if passwords should be rejected if they only contain a -single, continuous, character pattern. For example, "abcde" would be rejected, but "abcdz" and -"abc123" wouldn't. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/rules.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/rules.md deleted file mode 100644 index 0a7b6bce49..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/rules.md +++ /dev/null @@ -1,258 +0,0 @@ ---- -title: "Rules" -description: "Rules" -sidebar_position: 10 ---- - -# Rules - -Netwrix Password Policy Enforcer uses rules to decide if it should accept or reject a password. Each -policy has rules that are configured independently of the rules in other policies. To display the -rules for a policy: - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -**Step 2 –** Click a policy name to open the policy configuration page. - -The **Rules** tab opens by default. A check mark beside a rule indicates that the rule is enabled -(being enforced). Click a rule to set the rule's properties. - -![Enabled rules are checked](/images/passwordpolicyenforcer/11.0/administration/enabledrules.webp) - -Review the sections on **Detecting Character Substitution** and **Tolerance** before setting up -the rules for your policy. - -You can **Save** each rule and use **Test Policy** as you are setting your rules. Turn on **Verbose -logging** on the **Test Policy** window to see which rules you have tested. - -Rules: - -- [Age (Max) Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/maximum_age_rule.md) -- [Age (Min) Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/minimum_age_rule.md) -- [Characters (Complexity) Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/complexity_rule.md) -- [Character (Granular) Rules](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/character_rules.md) -- [Compromised Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/compromised_rule.md) -- [Dictionary Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/dictionary_rule.md) -- [History Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/history_rule.md) -- [Length Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/length_rule.md) -- [Patterns Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/patterns.md) -- [Repetition Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/repetition.md) -- [Similarity Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/similarity_rule.md) -- [Unique Characters Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/unique_characters.md) - -## Detecting Character Substitution - -Character substitution is a technique used by some users to improve password quality. They replace -some alphabetic characters with non-alphabetic characters that have a similar appearance. For -example, "sold" becomes "$old". Many of these substitutions are well known and do little to improve -password strength. - -Some Password Policy Enforcer rules have a Detect Character Substitution checkbox. When this check -box is selected, Password Policy Enforcer tests passwords with, and without character substitution. -This stops users from circumventing the rule by substituting some characters. Password Policy -Enforcer detects these common character substitutions: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Original - - Substituted -
- A - - a - - ^ @ -
- B - - b - - 8 -
- C - - c - - - - - - - - - -
- ( or { - <[
-
- D - - d - - - - - - - - - -
- ) or } - >]
-
- E - - e - - 3 -
- G - - g - - 6 or 9 -
- I - - i - - - - - - - - -
- ! or | -   1
-
- O - - o - - 0 or (zero) -
- S - - s - -

$ or 5

-
- T - - t - - + or 7 -
- Z - - z - - 2 -
- - -## Tolerance - -Some Password Policy Enforcer rules have a Tolerance dropdown list. Use it to control how strictly the rule is enforced. Tolerance is normally expressed as the maximum allowable number of -consecutive matching characters in the password and some other parameter. Password Policy Enforcer -rejects a password if the specified tolerance is exceeded. For example, the logon name -"mary**jones**", and the password "**Jones**town" contain five consecutive matching characters -(shown in bold type). Password Policy Enforcer rejects this password if the tolerance for the -User Logon Name rule is four or lower, and accepts it if the tolerance is five or higher. - -The User Logon Name, User Display Name, Similarity, and Character Patter rules have an Auto -tolerance option. Setting the tolerance to Auto instructs Password Policy Enforcer to only reject -passwords that contain the entire parameter being compared. This is very useful when the length of -the comparison parameter is unknown. For example, if you want Password Policy Enforcer to reject -passwords that contain the user's entire logon name, then you can't specify a fixed tolerance -unless all logon names have the same length. Setting the tolerance to Auto allows Password Policy -Enforcer to calculate an appropriate tolerance during every password change. - -Password Policy Enforcer sets the tolerance to the length of the comparison parameter minus one. The -following table shows some parameter values and the calculated tolerance. Password Policy Enforcer -rejects a password if it contains all the text in the Value column (or a derivative of it if -character substitution detection or bi-directional analysis is enabled). - -| Rule | Parameter | Value | Tolerance | -| ----------------- | ----------------- | ---------- | --------- | -| User Logon Name | Logon name | maryjones | 8 | -| User Display Name | Display name | Mary Jones | 9 | -| Similarity | Current password | oldpass | 6 | -| Character Pattern | Character pattern | abcdefgh | 7 | - -Password Policy Enforcer's Auto tolerance calculation has a minimum limit to stop passwords from -being rejected when the comparison parameter is very short. The limit is set to two characters by -default, so Password Policy Enforcer accepts passwords that contain the parameter value if the -comparison parameter only contains one or two characters. Contact Netwrix support if you need to -change the minimum limit. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/similarity_rule.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/similarity_rule.md deleted file mode 100644 index a73b44631e..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/similarity_rule.md +++ /dev/null @@ -1,39 +0,0 @@ ---- -title: "Similarity Rule" -description: "Similarity Rule" -sidebar_position: 110 ---- - -# Similarity Rule - -The Similarity rule rejects passwords that are similar to a user's current password. Password -similarity may indicate that a user is serializing their passwords. For example, "password1", -"password2", "password3". Password serialization allows an attacker to guess the new password. - -![Similarity Rule](/images/passwordpolicyenforcer/11.0/administration/similarity.webp) - -Select the **Similarity** checkbox to enable the Similarity rule. - -Select **Current password** to apply the similarity rules the user's existing password. The Password -Policy Enforcer client must be installed on the user's machine to enforce this rule. - -Select **User display name** to reject passwords that are similar to a user's Active Directory -display name (full name for local accounts). - -Select **User logon name** to reject passwords that are similar to a user's logon name (user name). - -For each option enabled, set the rules: - -Set **Character substitution** to **Yes** to reject passwords that rely on character substitution to -comply with this rule. - -Set **Words typed backward** to **Yes** to additionally test passwords with their characters -reversed. Enabling bi-directional analysis stops users from circumventing this rule by reversing the -order of characters in their password. For example, a user may enter "drowssapdloym" instead of -"myoldpassword". - -Set a **Tolerance** value to specify the maximum number of matching characters that Password Policy -Enforcer allows before rejecting a password. For example, the two passwords "old**passwd**" and -"new**passwd**" contain six consecutive matching characters (shown in bold type). Password Policy -Enforcer rejects the new password if the tolerance is five (or lower), and accepts it if the -tolerance is six (or higher). diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/unique_characters.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/unique_characters.md deleted file mode 100644 index c851cad105..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/unique_characters.md +++ /dev/null @@ -1,20 +0,0 @@ ---- -title: "Unique Characters Rule" -description: "Unique Characters Rule" -sidebar_position: 120 ---- - -# Unique Characters Rule - -The Unique Characters rule rejects passwords that don't contain a minimum number of unique -characters. For example, the password "aaaaaaaa" only contains one unique character (a), whereas -"mypassword" contains nine unique characters (mypasword). Increasing the number of unique characters -in a password increases password strength by avoiding repetitive sequences that are easy to guess. -The Unique Characters rule is case sensitive, so "LoOpHole" contains seven unique characters -(LoOpHle). - -![Unique characters rule](/images/passwordpolicyenforcer/11.0/administration/unique.webp) - -Select the **Unique characters** checkbox to enable the Unique Characters rule. - -Select the minimum number of unique characters that passwords must contain from the dropdown list. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/testpolicy.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/testpolicy.md deleted file mode 100644 index 67e8ce97e7..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/testpolicy.md +++ /dev/null @@ -1,109 +0,0 @@ ---- -title: "Test Policy" -description: "Test Policy" -sidebar_position: 60 ---- - -# Test Policy - -You can quickly test your Password Policy Enforcer configuration by simulating a password change. -Click **Test Policy** from the Configuration Console dashboard or when you are setting up a policy. -Test policy opens in a separate window. Remember to **Save** your rules and changes before -testing. - -Test policy opens on the **By user** tab. - -![Test by User](/images/passwordpolicyenforcer/11.0/administration/testuser.webp) - -## By User - -Policy testing simulates a password change, but it doesn't change the password. - -**Step 1 –** Click **Test policy** from the Configuration Console dashboard or when you are setting -up a policy. - -**Step 2 –** Select a **user**. - -**Step 3 –** **Type in a password to simulate its change**. As you type, the new password is -evaluated and the results are displayed. - -![Failing Password](/images/passwordpolicyenforcer/11.0/administration/testuserfail.webp) - -The entered password is failing in this example, due to not meeting the length requirement. There is -a red x indicating the failure. You can hover over the requirements to see the rule name. - -In this example, the password passes. Notice the green check beside the entered password. - -![Passing password](/images/passwordpolicyenforcer/11.0/administration/testuserpass.webp) - -Expand the **View log** for details: - -- Computer the configuration was read from. -- Policy was assigned to the user, and why. -- Dictionary word or keyboard pattern matched with the password. -- Errors or warnings occurred during testing. - -Turn on **Verbose Logging** to view the performed tests and results. - -![Verbose logging](/images/passwordpolicyenforcer/11.0/administration/testuserverbose.webp) - -## Bulk Password Test - -Bulk Password Test feature allows to check a large number of passwords against a selected policy and -a get a report of the accepted and rejected passwords. - -**Step 1 –** Click **Test policy** from the Configuration Console dashboard or when you are setting -up a policy. - -**Step 2 –** Open the **Password bulk test** tab. - -![Password bulk test](/images/passwordpolicyenforcer/11.0/administration/testbulk.webp) - -**Step 3 –** Select a policy for the test. - -**Step 4 –** **Browse** to the text file containing the passwords to test. Processing is faster if -the file isn't on a shared drive. - -**Step 5 –** Click **Test passwords**. The **Statistics** are displayed. - -![Test results](/images/passwordpolicyenforcer/11.0/administration/testbulkresult.webp) - -| Statistics of the Bulk Password Testing | | -| --------------------------------------- | --------------------------------------------------------------------------------------- | -| Status | Shows whether the operation is ready for scanning, processing, terminated, or finished. | -| Tested | Number of tested passwords. | -| Accepted | Number of accepted passwords. | -| Rejected | Number of rejected passwords. | -| Number of lines | Number of lines within the file. | -| Lines processed | Shows the number of the processed lines. | - -Click **Show full report** to view the test details. - -![Test Bulk Report](/images/passwordpolicyenforcer/11.0/administration/testbulkreport.webp) - -You can use the **Report settings** to customize the report: - -- Result report folder. Processing is faster if this isn't a shared drive. -- Show accepted passwords -- Show rejected passwords - -## Policy Testing vs. Password Changes - -- Policy testing simulates a password change, but it may not always reflect what happens when a user - changes their password. A password change may yield different results to a policy test because: -- Policy testing doesn't simulate the Windows password policy rules. If the Windows password rules - are enabled, then Windows may reject a password even though it complies with all the Password - Policy Enforcer rules. -- Policy testing doesn't enforce the Minimum Age rule. -- Policy testing doesn't enforce the History rule. -- Policy testing enforces the password policy even if Password Policy Enforcer or the assigned - policy is disabled. Use this to test your configuration before enabling Password Policy - Enforcer, or a new password policy. -- Policy testing occurs on the computer that the management console is running on. If the management - console is connected to a remote domain configuration, then it may not find the dictionary file on - the local computer, or the local dictionary file may be different to the one on the domain - controller. Copy the dictionary file onto the local computer (in the same path) to avoid this - problem. -- If the management console is connected to a domain configuration and the Password Policy Enforcer - configuration was modified recently, then Active Directory may still be propagating the new - configuration to the other domain controllers. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/usersgroups.md b/docs/passwordpolicyenforcer/11.0/admin/manage-policies/usersgroups.md deleted file mode 100644 index 8dc4e47122..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/usersgroups.md +++ /dev/null @@ -1,85 +0,0 @@ ---- -title: "Assign Policies to Users & Groups" -description: "Assign Policies to Users & Groups" -sidebar_position: 20 ---- - -# Assign Policies to Users & Groups - -Password Policy Enforcer uses policy assignments to decide which policy to enforce for each user. -Domain policies can be assigned to users, groups, and containers (Organizational Units). Local -policies can only be assigned to users. See the -[Domain and Local Policies](/docs/passwordpolicyenforcer/11.0/installation/domain_and_local_policies.md) topic for additional information. - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -**Step 2 –** Click a policy name to open the policy configuration page. - -**Step 3 –** Open the **Users & Groups** tab. - -![Assign policies to Users and Groups](/images/passwordpolicyenforcer/11.0/administration/usersandgroups.webp) - -When a domain policy is assigned to a user or group, Password Policy Enforcer stores the user or -group SID in the configuration. The assignment remains valid even if the user or group is renamed. -When a local policy is assigned to a user, Password Policy Enforcer stores the username in the -configuration. The assignment is invalidated if the user is renamed. - -When a policy is assigned to a group, Password Policy Enforcer enforces the policy for all members -of the group as well as any nested groups. For example, if the Helpdesk group is a member of the -Info Tech group, then any policy assigned to the Info Tech group also applies to the members of the -Helpdesk group. If this behavior isn't desired, then you can assign a different policy to the -Helpdesk group. - -When a policy is assigned to a container, Password Policy Enforcer enforces the policy for all users -in the container as well as any child containers. For example, if the Helpdesk and Managers OUs are -children of the Info Tech OU, then any policy assigned to the Info Tech OU also applies to the two -child OUs. If this behavior isn't desired, then you can assign a different policy to a child OU. - -![managing_policies_3](/images/passwordpolicyenforcer/11.0/administration/managing_policies_3.webp) - -:::note -You can use different assignment types for a single policy. For example, you may assign -users to a policy by both OU and group at the same time. -::: - - -As you assign users and groups to the policy, they are displayed on the page. - -![Policy assignments](/images/passwordpolicyenforcer/11.0/administration/usersandgroups2.webp) - -To remove a policy assignment: - -**Step 1 –** Select the user, group, or container. For example, **Administrators** under **Groups**. - -**Step 2 –** Click the trash can icon in the appropriate header. For example, **Groups**. - -## Policy Assignment Conflicts - -A policy assignment conflict occurs when more than one policy is assigned to a user. Password Policy -Enforcer can resolve these conflicts and choose one policy for each user. - -Password Policy Enforcer first tries to resolve a policy assignment conflict by examining the -assignment type. Assignments by user take precedence over assignments by group, which in turn take -precedence over assignments by container. For example, if Policy A is assigned to a user by group, -and Policy B is assigned to the same user by container, then Password Policy Enforcer enforces -Policy A because assignments by group take precedence over assignments by container. - -If all the policies are assigned to the user by container, then Password Policy Enforcer enforces -the policy that is assigned to the nearest parent container. For example, if Policy A is assigned to -the Users OU, and Policy B is assigned to the Users\Students OU, then Password Policy Enforcer -enforces Policy B for all users in the Users\Students and Users\Students\Science OUs because it is -the policy assigned to the nearest parent container. - -If a policy assignment conflict still exists, then Password Policy Enforcer checks the priority of -each remaining policy, and enforces the policy with the highest priority. See the -[Policy Selection Flowchart](manage_policies.md#policy-selection-flowchart) topic for a diagrammatic -representation of this algorithm. - -Click **Test Policy** and expand the **View log** to see which policy Password Policy Enforcer -enforces for a particular user. - -![Expand View log under Test to see which policy is enforced](/images/passwordpolicyenforcer/11.0/administration/testviewlog.webp) diff --git a/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/_category_.json b/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/_category_.json deleted file mode 100644 index 7194f80dac..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Password Policy Client", - "position": 50, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "password_policy_client" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/configuring_the_password_policy_client.md b/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/configuring_the_password_policy_client.md deleted file mode 100644 index 808f06de2d..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/configuring_the_password_policy_client.md +++ /dev/null @@ -1,109 +0,0 @@ ---- -title: "Configuring the Password Policy Client" -description: "Configuring the Password Policy Client" -sidebar_position: 10 ---- - -# Configuring the Password Policy Client - -The Password Policy Client is self-configuring and doesn't require manual configuration in most -cases. See the [Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.0/installation/installationclient.md) topic for -additional details. You may need to manually configure the Password Policy Client if: - -- You want to install it in a disabled state to be enabled later. -- You want to change the display settings for small screens. -- Password Policy Client displays policy messages in the wrong language. -- Default communication settings aren't suitable (for example, if you change the default Password - Policy Server Port). - -Password Policy Enforcer includes an administrative template to help configure the Password Policy -Client. You can use Active Directory GPOs to configure many computers, or the Local Group Policy -Editor to configure one computer. The Password Policy Client configuration is stored in the -HKLM\SOFTWARE\Policies\ANIXIS\Password Policy Client\ registry key. - -**Install the Password Policy Client Administrative Template** - -**Step 1 –** Connect to any Domain Controller where you have Password Policy Enforcer installed and -have the group policy management console available. - -**Step 2 –** Go to Password Policy Enforcer install directory (C:\Program Files or C:\Program Files -(x86)\Password Policy Enforcer) and copy the **PPEClt.adml** and **PPEClt.admx** files (highlighted -in yellow): - -![ppc_configuration](/images/passwordpolicyenforcer/11.0/administration/ppc_configuration.webp) - -**Step 3 –** Go to C:\Windows\Policy Definitions and paste the .admx file in the root of this -folder. - -![ppc_configuration2](/images/passwordpolicyenforcer/11.0/administration/ppc_configuration2.webp) - -**Step 4 –** Go to C:\Windows\Policy Definitions\en-US and paste the .adml file in the root of this -folder. - -![ppc_configuration1](/images/passwordpolicyenforcer/11.0/administration/ppc_configuration1.webp) - -**Step 5 –** Open **Group Policy Management** console and check if you have a GPO created for -Client. If not, see the topic's section for additional information. - -**Step 6 –** In the left pane, navigate to **Forest: ``** > **Domain** > -**``**, right-click **``** and select **Create a GPO** in this domain and Link -it here. - -After the GPO is configured, this view is available: - -![ppc_configuration3](/images/passwordpolicyenforcer/11.0/administration/ppc_configuration3.webp) - -**Step 7 –** Right-click the newly created GPO and select **Edit** from the pop-up menu. - -**Step 8 –** Expand **Computer Configuration** > **Policies** > **Administrative Templates** > -**Netwrix Password Policy Enforcer** - -![ppc_configuration4](/images/passwordpolicyenforcer/11.0/administration/ppc_configuration4.webp) - -**Step 9 –** Click **Netwrix Password Policy Client** to open a list of modification settings. - -![ppc_configuration5](/images/passwordpolicyenforcer/11.0/administration/ppc_configuration5.webp) - -**Step 10 –** Select the one you need, then modify and save it. - -## Changing the Default Display Settings - -The Windows 10 and 11 Change Password screen has less space for the Password Policy message than -earlier Windows versions. Users may need to scroll to see the message if their screen is small, or -if their computer is set to use large fonts. - -The Password Policy Client for Windows 10 and 11 maximizes the available screen space by hiding -non-essential user interface elements on small screens. It can also display the Password Policy -message in a message box to draw attention to the password policy. - -![the_password_policy_client_3](/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client_3.webp) - -You can change the default display settings to control which user interface elements are hidden, and -the point at which they are hidden. The display of the Password Policy message box is also -configurable. - -Follow the following steps to change the default display settings for the Password Policy Client on -Windows 10 and 11. - -**Step 1 –** Use the **Group Policy Management Console** (gpmc.msc) to display the GPOs linked at -the domain level. - -:::note -If you aren't using Active Directory, then open the Local Group Policy Editor -(**gpedit.msc**) and skip step 2. -::: - - -**Step 2 –** Right-click the **Password Policy Client GPO**, then click the **Edit...** button. - -**Step 3 –** Expand the **Computer Configuration**, **Policies** (if visible), **Administrative -Templates**, **Classic Administrative Templates** (**ADM**), **Password Policy Enforcer**, and -**Password Policy Client** items. - -**Step 4 –** Double-click the **Display settings (Windows 10)** setting in the right pane of the -Group Policy Management Editor. - -:::note -Information about each option is shown in the Help box. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/password_policy_client.md b/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/password_policy_client.md deleted file mode 100644 index 15d4abfff4..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/password_policy_client.md +++ /dev/null @@ -1,29 +0,0 @@ ---- -title: "Password Policy Client" -description: "Password Policy Client" -sidebar_position: 50 ---- - -# Password Policy Client - -The Password Policy Client helps users to choose a compliant password. Detailed information is -provided if their new password is rejected. - -The Password Policy Client is optional. If it isn't installed, the -[Similarity Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/similarity_rule.md) can't be enforced. Users only see the default Windows error -message if their password is rejected, not the detailed help they receive from the Password Policy -Client. - -![the_password_policy_client](/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client.webp) - -![the_password_policy_client_1](/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client_1.webp) - -The Password Policy Client displays the password policy during a password change so that users can -see the policy while they choose their password. The Password Policy Client also displays a detailed -rejection message to explain why a password was rejected. Both these messages are customizable. - -:::note -The Password Policy Client doesn't modify any Windows system files. It also doesn't send -passwords or password hashes over the network. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/admin/ppe_tool.md b/docs/passwordpolicyenforcer/11.0/admin/ppe_tool.md deleted file mode 100644 index e717933992..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/ppe_tool.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "PPE Tool" -description: "PPE Tool" -sidebar_position: 80 ---- - -# PPE Tool - -The PPE Tool is designed to configure local and domain instances of Password Policy Enforcer and -produce reports pertaining to the configuration of Password Policy Enforcer. The PPE Tool is -designed to perform the following functions: - -- Export the configuration from the existing instance of Password Policy Enforcer, regardless if the - server is local or domain. -- Import existing PPE configurations on another PPE server instance. -- Generate user-friendly reports that contain configuration values and descriptions. -- Create HTML reports with configuration values and descriptions of the PPE server instance. - -This topic covers how to install the PPE Tool, how to customize and run reports, and how to review configuration options in the PPE Tool. - -## Using the PPE Tool - -The PPE Tool installs with the default installation of Password Policy Enforcer under the -`C:\Program Files (x86)\Password Policy Enforcer\ppetool` folder. After installation, the PPE Tool supports a number of operations related to Password Policy Enforcer functionality, which are described in the following table. - -:::note -All PPE Tool operations can be executed from the Command Prompt, if run with administrator -rights. -::: - - -### PPE Tool Operations - -:::info -PPE Tool operations should only be executed one at a time. For example, you -shouldn't execute the /e (Export) and /i (Import) operations simultaneously; you shouldn't run /e -(Export) and /r (Report) operations simultaneously. -::: - - -**Common PPE Tool Operations** - -| Operation | Operation Name | Operation Description | -| --------- | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| /? | help |
  • Displays Help and exits the application. All other options are ignored.
| -| /m | minimal |
  • Configures the PPE Tool to operate in Minimal mode.
  • This operation strips away all extraneous information (e.g., policy messages, license information, etc.) while importing or exporting to the PPE Tool.
  • By default, the PPE Tool imports and exports all information available (e.g., policy messages, license information, etc.).
| -| /d | domain [in controller] |
  • Configures the PPE Tool to operate in Domain mode.
  • The default controller is localhost.
  • This operation makes PPE Tool work with the LDAP Password Policy Enforcer instance. PPE Tool imports or exports configurations from the local registry.
  • To use this operation , you must run PPE Tool as a domain administrator user. However, this operation can be used on both the domain controller and on any member. If an invalid domain controller is provided as an argument, then the PPE Tool will fail at the import / export stage.
  • This operation is ignored when used to create reports from the file source (present with the /c (Config [in file name]) option). When the PPE Tool starts in a domain environment without the /d (Domain [in controller]) operation, a warning message appears. However, this won't prevent the PPE Tool from operating on a local environment.
| -| /c | config [in file name] |
  • Uses a config file instead of Password Policy Enforcer export when exporting reports (in the case of /i (Import), /h (Human [out file name]), and /r (Report [out file name]).
  • The default file is `config.xml`.
  • This operation defines the input file for the i/ (Import) operation, and thus is necessary for importing files to the PPE Tool. An error message will appear if the /c (Config [in file name]) option is omitted.
  • By default, the /h (Human [out file name]) and /r (Report [out file name]) operations use the Password Policy Enforcer instance as the reporting source. The /c (Config [in file name]) operation should provide the source configuration file as an argument to create reports. If an invalid file name is provided as an argument in this operation, the PPE Tool displays the appropriate error message and exits.
| - - -Operations PPE Tool options are as follows: - -| Task | Task Name | Task Description | -| ---- | ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| /e | export [out file name] |
  • Exports config data (default) from the Password Policy Enforcer instance to the file.
  • This operations is enabled by default.
  • This operation can't be used with /c (Config [in file name]) or i/ (Import) operations, but can be combined with /h (Human [out file name]).
| -| /i | import |
  • Imports the config file.
  • Imports existing configuration using the input configuration file defined by the /d (Domain [in controller]) . If the /c (Config [in file name]) operation is omitted, the PPE Tool displays an error message and exits.
  • When i/ (Import) is used with the /h (Human [out file name]) or /r (Report [out file name]) operations, the latter is ignored.
  • /d (Domain [in controller]) and /m (Minimal) operations may affect the result of the import.
| -| /h | human [out file name] |
  • Converts the config file to a human-readable format and produces a human-readable report based on the current Password Policy Enforcer instance configuration or the configuration provided by the /d (Domain [in controller]).
  • If no custom file name is provided, the default file name is `config_human_readable.xml`.
| -| /r | report [out file name] |
  • Converts the config file to HTML and produces an HTML report file based on the current Password Policy Enforcer instance configuration or the configuration provided by the /d (Domain [in controller]).
  • Generates the HTML report into `C:\Program Files (x86)\Password Policy Enforcer\Report` alongside the .css file.
  • The default files name is `report.html`.
| - - -### PPE Usage Samples - -This section covers some sample operations usable in either the PPE Tool or in the Command console -(with administrator rights). Each operation can be executed after the following commands have been -executed: - -C:\Windows/system32>cd.. - -`C:\`[location of PPE Tool]`>`[operation] - -After this location has been accessed in the Command console, enter one of the following commands in -the [operation] variable above to execute a PPE Tool operation in the Command console. - -| Action | Operation | Message | -| -------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Simple Config export operation |
  • ppetool
| Warning: PPETool started in domain environment without /d option. Using local source. Hope you know what are you doing. Config successfully exported. | -| Simple Config export in domain environment with DC %Full computer name of Domain Controller% |
  • ppetool /d localhost
  • ppetool /d %Full computer name of Domain Controller%
| Config successfully exported. | -| Export local config into local.xml and create it from the HR.xml and report.html reports |
  • ppetool /e local.xml /h HR.xml /r Report.html
| Warning: PPETool started in domain environment without /d option. Using local source. Hope you know what are you doing. Config successfully exported. Human readable config representation successfully exported. HTML config representation exported successfully. | -| Import Config from config.xml |
  • ppetool /c config.xml /i
| Warning: PPETool started in domain environment without /d option. Using local source. Hope you know what are you doing. Config import successful. | - - -### Generating Reports with Custom Descriptions - -The PPE Tool generates user-friendly reports by processing configuration tags (i.e., ``). For -example, the PPE Tool searches for the file tagname.xml (or, ppe.xml in this case). This file has -root elements which name match each file name. Each root tag contains child tags (e.g., ``). -Each tag has the following attributes: - -- name — Contains the original tag name from the input configuration file. If this attribute is - missed, then the original tag and its value are absent in the human-readable report. -- DisplayName — Contains the user-friendly description for the original tag. If this attribute is - missed, then the original tag and its value appear in the report without a description. - -The `` tag can also contain the child `` tag. This tag can have an optional attribute -'mode' and this attribute can have the following values: - -- value (default) — With the default value, the report contains only tag descriptions for the - child `` tag. The 'value' attribute matches the child `` tag with the value of the - original tag. -- combined — With the combined value, the report contains the child `` tags which contain - values that are bitwise or are the result of the original values. - -#### Example of 'value' mode - -**Original configuration** - -```xml -1 -``` - -**Transform configuration** - -```xml - - - - - - - -``` - -**Transformation result** - -```xml - - - - - - - -``` - -#### Example of 'combined' mode - -**Original configuration** - -`25` - -**Transformation configuration** - -```xml - - - - - - - - - - - -``` - -**Result human-readable report** - -```xml - - - - - - - - - - - -``` - -### Customize HTML Report - -The PPE Tool comes with a pre-defined template.css file in the configuration folder, found here: -`C:\Program Files (x86)\Password Policy Enforcer\config`. The template.css defines the visual design -(formatting, colors, fonts etc.) of HTML report. See the -[XSLT - Transformation](https://www.w3schools.com/xml/xsl_transformation.asp) article for additional -information of transforming .xml to .xhtml. diff --git a/docs/passwordpolicyenforcer/11.0/admin/systemaudit.md b/docs/passwordpolicyenforcer/11.0/admin/systemaudit.md deleted file mode 100644 index 1fee8debbb..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/systemaudit.md +++ /dev/null @@ -1,85 +0,0 @@ ---- -title: "System Audit and Support" -description: "System Audit and Support" -sidebar_position: 40 ---- - -# System Audit and Support - -Password Policy Enforcer can run a discovery and testing of your domain controllers for an overview -on PPE health, versions, and logs. - -Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -Click the **System Audit and Support** tile on the Configuration Console dashboard. This feature is -only available when **domain** is selected with the [Connected To](configconsole.md#connected-to) -configuration setting. System Audit and Support opens on the **Version Tracker** tab. - -## Version Tracker - -![System Audit and Support Version Tracker tab](/images/passwordpolicyenforcer/11.0/administration/systemaudit.webp) - -Click **Run test**. The audit reports the discovered domain controllers and versions. - -:::note -If you don't see the **Configuration Timestamp**, contact your network administrator to -set up the firewall to allow Password Policy Enforcer to communicate. -::: - - -![System Audit results](/images/passwordpolicyenforcer/11.0/administration/systemauditversion.webp) - -You can click the export icon to download your results. The file name is -**Audit\_\_**timestamp**\_.xlxs**, it is downloaded into the default **Downloads** folder. For large -domains, you can apply filters or use the Search feature to make it easier to navigate your list. - -:::note -**Debug logging** should only be enabled when you are actively debugging your system. -Leaving it enabled impacts Password Policy Enforcer performance and uses free disk space to create -the logs. -::: - - -## Support Tools - -Use the **Support Tools** tab to save a configuration report, export/import PPE settings, -and open the property editor. - -![System Audit Support Tools tab](/images/passwordpolicyenforcer/11.0/administration/systemaudittools.webp) - -- **Policies Configuration Report** saves the configuration as a text file. Browse to the folder - where you want the report. The default filename is **PPEConfig.txt**. -- **PPE Settings** export your PPE settings for a backup. You can import the settings to replicate - configurations across systems. - - **Export** exports the PPE settings to an xml file. Browse to the folder where you want the - file. The default filename is **PPEExport.xml**. - - Import imports the settings from an exported xml PPE Settings file. Browse to the location of - the **PPEExport.xml** file. Click **Open**. A status message is displayed when complete. -- **Open Property Editor** launches the Property Editor. - - :::note - Properties should only be changed when advised by Netwrix Support. - ::: - - -### Property Editor - -The Property Editor lets you edit the Password Policy Enforcer configuration. It should only -be used instructed by Netwrix Support. It is accessed from the Configuration Console: - -**Help** > **Open Property Editor** - -**or** - -**System Audit and Support** > **Support Tools** > **Open editor** - -![Property Editor](/images/passwordpolicyenforcer/11.0/administration/propertyeditor.webp) - -- **Policy**: select the policy to edit. -- **Property**: select the property to change. -- **Property ID**: enter the ID supplied by Netwrix Support. -- **Value**: enter the new value supplied by Netwrix Support. Click **Set value**. diff --git a/docs/passwordpolicyenforcer/11.0/admin/troubleshooting.md b/docs/passwordpolicyenforcer/11.0/admin/troubleshooting.md deleted file mode 100644 index 1468ec408e..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/troubleshooting.md +++ /dev/null @@ -1,81 +0,0 @@ ---- -title: "Troubleshooting" -description: "Troubleshooting" -sidebar_position: 90 ---- - -# Troubleshooting - -This topic contains troubleshooting information for the most common support questions. Contact -Netwrix support with any questions. - -Password policy assigned to some users is being enforced for all users. Check the Default Policy in -the PPS Properties page. Users must comply with the default policy if no other policy is assigned to -them. Select the first (blank) item in the dropdown list if you don't want a default policy. - -#### Password policy not displayed during password change - -Open the Programs and Features list in Control Panel on the computer you are changing the password -from, and check if the Password Policy Client is in the list of installed programs. If it isn't, -then install the Password Policy Client. See the [Password Policy Client](/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/password_policy_client.md) -topic for additional information. - -If Password Policy Enforcer is enforcing a domain policy, then search the Windows Application Event -Log on every domain controller for events from Password Policy Enforcer. If there are no events from -Password Policy Enforcer since the last restart on any domain controller, then ensure that -Password Policy Enforcer is installed on that domain controller and restart it. Check the Windows -Application Event Log again after the restart to ensure that Password Policy Enforcer started. For -local policies, search the Application Event Log on the local computer. - -If there is a firewall between the client computer and the domain controllers (including Windows -Firewall), then you must create firewall rules to allow the Password Policy Client and Password -Policy Server to communicate. Windows firewall is enabled by default on Windows Server 2008 and -later. - -Use the Test Policies page to test a password for the user. Click the **Log** tab to see if a -password policy is assigned to the user. - -Ensure that the Password Policy Server is enabled. - -Ensure that the Password Policy Client is enabled. See -[Password Policy Client](/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/password_policy_client.md) topic for additional information. - -#### Accepting passwords that don't comply with the policy - -If Password Policy Enforcer is enforcing a domain policy, then search the Windows Application Event -Log on every domain controller for events from Password Policy Enforcer. If there are no events from -Password Policy Enforcer since the last restart on any domain controller, then ensure that -Password Policy Enforcer is installed on that domain controller and restart it. Check the Windows -Application Event Log again after the restart to ensure that Password Policy Enforcer started. For -local policies, search the Application Event Log on the local computer. - -Use the Test Policies page to test a password that Password Policy Enforcer is accepting. Examine -the test results and event log to determine why Password Policy Enforcer accepted the password. If -the Test Policies page rejects the password, you must configure the policy. See the -[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) topic for -additional information. - -If the **Enforce policy when password is reset** checkbox isn't selected in the PPS Properties -page, then Password Policy Enforcer won't enforce the password policy for passwords that are -reset from the Active Directory Users and Computers console, or the Local Users and Groups console. -You should select this option during testing, or test password changes from the Windows Change -Password screen. - -#### Rejecting passwords that comply with the policy - -Use the Test Policies page to test a password that Password Policy Enforcer is rejecting. Examine -the test results and event log to determine why Password Policy Enforcer rejected the password. If -the Test Policies page rejects the password, you must configure the policy. See the -[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) topic for -additional information. - -Set **User must change password at next logon** for the user and repeat the password change test. If -the password is accepted, then either Windows or Password Policy Enforcer is configured to enforce a -minimum password age. Disable the Minimum Age rule in Windows and Password Policy Enforcer to -facilitate testing. If you can't disable the Minimum Age rule, then set User must change password -at next logon before every password change test to bypass the rule. - -#### Passwords that are accepted in the Test Policies page are rejected during a password change - -See the [Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) -topic for additional information. diff --git a/docs/passwordpolicyenforcer/11.0/admin/windowseventviewer.md b/docs/passwordpolicyenforcer/11.0/admin/windowseventviewer.md deleted file mode 100644 index 80bb6dce49..0000000000 --- a/docs/passwordpolicyenforcer/11.0/admin/windowseventviewer.md +++ /dev/null @@ -1,26 +0,0 @@ ---- -title: "View Event Logs in Windows Event Viewer" -description: "View Event Logs in Windows Event Viewer" -sidebar_position: 100 ---- - -# View Event Logs in Windows Event Viewer - -**Step 1 –** Open **Windows Event Viewer**. - -![View Event Logs](/images/passwordpolicyenforcer/11.0/administration/vieweventlogs.webp) - -**Step 2 –** Navigate to **Windows Logs** > **Application**. - -**Step 3 –** In the Application list, select a Netwrix Password Policy Enforcer event under the -Source column. - -The General tab shows details for the selected event. The Details tab shows... - -## View Log Properties - -To view Log Properties, navigate to the Actions menu and select **Properties**. - -![Log Properties Window](/images/passwordpolicyenforcer/11.0/administration/vieweventlogslogproperties.webp) - -The Log Properties window displays. Configure settings for this log from this window. diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/conclusion.md b/docs/passwordpolicyenforcer/11.0/evaluation/conclusion.md deleted file mode 100644 index 6b7321524d..0000000000 --- a/docs/passwordpolicyenforcer/11.0/evaluation/conclusion.md +++ /dev/null @@ -1,17 +0,0 @@ ---- -title: "Conclusion" -description: "Conclusion" -sidebar_position: 80 ---- - -# Conclusion - -You have successfully installed, configured, and tested Netwrix Password Policy -Enforcer. This guide is an introduction to Password Policy Enforcer's capabilities. You can enforce -almost any password policy imaginable with Password Policy Enforcer, customize the Password Policy -Client messages, and even synchronize passwords with other networks and applications. The -[Administration](/docs/passwordpolicyenforcer/11.0/admin/administration_overview.md) topic contains more information to -help you use Password Policy Enforcer effectively. - -The [Password Policy Enforcer Web](/docs/passwordpolicyenforcer/11.0/web-overview/web_overview.md) application lets users securely manage their passwords from a web browser, ensuring passwords comply with the password policy, and -helping users choose compliant passwords. diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/configuring_policy_rules.md b/docs/passwordpolicyenforcer/11.0/evaluation/configuring_policy_rules.md deleted file mode 100644 index ea7aec5f0a..0000000000 --- a/docs/passwordpolicyenforcer/11.0/evaluation/configuring_policy_rules.md +++ /dev/null @@ -1,94 +0,0 @@ ---- -title: "Configure Policy Rules" -description: "Configure Policy Rules" -sidebar_position: 40 ---- - -# Configure Policy Rules - -The policy you just created doesn't enforce any password requirements yet. You can now configure -the policy to enforce these rules: - -- Password must contain at least seven characters. -- Password must contain at least one lowercase alpha character. -- Password must contain at least one uppercase character. -- Password must not be similar to the user's logon name. -- Password must not exist in a dictionary of common passwords. - -When you create a policy, the policy settings are opened. You can open the settings for a policy at -any time by clicking the policy name on the Configuration Console dashboard. - -![New policy open for settings](/images/passwordpolicyenforcer/11.0/evaluation/newpolicysettings.webp) - -Requirement: Password must contain at least seven characters. - -This condition is set with the **Length** rule. - -**Step 1 –** Select **Length**. - -**Step 2 –** Click the **Length** checkbox to enable the rule. - -**Step 3 –** Select **7** for the **At least...** value. Depending on the template, this might be -the default. - -![Set the Length](/images/passwordpolicyenforcer/11.0/evaluation/evallength.webp) - -Requirement: Password must contain at least one lowercase alpha character. - -This condition is set with the **Characters (Complexity)** rule. - -**Step 1 –** Select **Characters (Complexity)**. - -**Step 2 –** Click the **Characters (Complexity)** checkbox to enable the rule. - -**Step 3 –** Select **1** as the **Must contain at least...** value. - -**Step 4 –** Select **Lower Alpha (a-z)**. - -**Step 5 –** Select **Upper Alpha (A-Z)** for the next requirement while you are here. - -![Set upper and lower case requirements](/images/passwordpolicyenforcer/11.0/evaluation/evalchars.webp) - -Password must contain at least one uppercase character. - -This condition is set with the **Characters (Granular)** rule. - -**Step 1 –** Select **Characters (Granular)**. - -**Step 2 –** Click the **Characters (Granular)** checkbox to enable the rule. - -**Step 3 –** Select **1** as the **Must contain at least...** value. - -**Step 4 –** Select **Upper Alpha (A-Z)** **Contain** **1** or more characters. - -**Step 5 –** Select **Lower Alpha (a-z)** **Contain** **1** or more characters. - -![set character granularity](/images/passwordpolicyenforcer/11.0/evaluation/evalcharsgran.webp) - -Requirement: Password must not be similar to the user's logon name. - -This condition is set with the **Similarity** rule. - -**Step 1 –** Select **Similarity**. - -**Step 2 –** Click the **Similarity** checkbox to enable the rule. - -**Step 3 –** Select **User logon name**. - -![Set Similarity rule](/images/passwordpolicyenforcer/11.0/evaluation/evalsimilarity.webp) - -Requirement: Password must not exist in a dictionary of common passwords. - -This condition is set with the **Dictionary** rule. - -**Step 1 –** Select **Dictionary**. - -**Step 2 –** Click the **Dictionary** checkbox to enable the rule. - -**Step 3 –** Click **Browse**. - -**Step 4 –** Navigate to **\Program Files\Password Policy Enforcer** folder and select**Dict.txt**. - -![Enable the sample dictionary](/images/passwordpolicyenforcer/11.0/evaluation/evaldict.webp) - -When you have added all the rules, click **Save** to save your new policy. diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/creating-a-password-policy/creating_a_password_policy.md b/docs/passwordpolicyenforcer/11.0/evaluation/creating-a-password-policy/creating_a_password_policy.md deleted file mode 100644 index d69d0ac0e0..0000000000 --- a/docs/passwordpolicyenforcer/11.0/evaluation/creating-a-password-policy/creating_a_password_policy.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "Create a Password Policy" -description: "Create a Password Policy" -sidebar_position: 30 ---- - -# Create a Password Policy - -Password Policy Enforcer has no password policies defined when first installed. You can now -create your first Password Policy Enforcer password policy. Password Policy Enforcer accepts all -passwords in this state, so users only need to comply with the Windows password policy rules (if -enabled). - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -![Configuration Console Dashboard](/images/passwordpolicyenforcer/11.0/evaluation/ppedashboard.webp) - -The Configuration Console dashboard shows **No password policies have been set up** when you are -getting started with Password Policy Enforcer. - -**Step 2 –** Click **Add policy**. - -**Step 3 –** Enter a unique policy name. Maximum is 32 characters. **Eval Policy** is used for this -example. - -**Step 4 –** Select a Policy template or **None** if you are creating your own. For a list of -policies see [Policy Templates ](/docs/passwordpolicyenforcer/11.0/evaluation/creating-a-password-policy/policy_templates.md). - -**Step 5 –** Click **Create policy**. - -Password Policy Enforcer creates the policy and opens the policy settings, showing the first item on the **Rules** tab. - -![New policy open for settings](/images/passwordpolicyenforcer/11.0/evaluation/newpolicysettings.webp) - -**Step 6 –** Click the context menu (beside the policy name and select **Make default**. - -![Make the policy the default](/images/passwordpolicyenforcer/11.0/evaluation/evaldefault.webp) diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/enforcing_multiple_policies.md b/docs/passwordpolicyenforcer/11.0/evaluation/enforcing_multiple_policies.md deleted file mode 100644 index 4b194d7a0d..0000000000 --- a/docs/passwordpolicyenforcer/11.0/evaluation/enforcing_multiple_policies.md +++ /dev/null @@ -1,78 +0,0 @@ ---- -title: "Enforce Multiple Policies" -description: "Enforce Multiple Policies" -sidebar_position: 70 ---- - -# Enforce Multiple Policies - -Password Policy Enforcer can enforce up to 256 password policies on each domain or computer. You can -assign policies to users directly, or indirectly through Active Directory security groups and -containers (Organizational Units). - -### Create Additional Password Policy - -If you are in the settings for your first policy, click the left arrow beside the policy name to -return to the Configuration Console dashboard. - -![Return to the dashboard](/images/passwordpolicyenforcer/11.0/evaluation/evaldashboard.webp) - -Create an additional password policy. - -**Step 1 –** Click the context menu beside your first policy and select **Make copy**. - -**Step 2 –** Enter **Admins Policy** for the Policy duplication. - -![Enter Admins Policy](/images/passwordpolicyenforcer/11.0/evaluation/evalcopypolicy2.webp) - -**Step 3 –** Click **Make copy**. - -**Step 4 –** Open the **Users & Groups** tab. - -![Open the Users & Groups tab](/images/passwordpolicyenforcer/11.0/evaluation/evalusergroups.webp) - -**Step 5 –** Click the **+** in the **Groups** list and enter **Domain Admins**. Specify a Domain or -local **Location** depending on your evaluation set up. - -**Step 6 –** Click **OK**. Domain Admins are added to the **Groups**. - -![Domain Admins added](/images/passwordpolicyenforcer/11.0/evaluation/evaldomainadmins.webp) - -- Members of the Domain Admins group (or the PPETestAdmin user, if not using a domain controller) - must now comply with the Administrators policy. All other users must comply with the Users policy. - Users won't notice any difference at this point because the two polices are enforcing identical - rules. - -### Differentiate Password Policies - -To differentiate the policies, change the minimum password length for the Admins policy from seven -to nine characters. - -**Step 1 –** Open the **Rules** tab. - -**Step 2 –** Open the **Length** rule. - -**Step 3 –** Select **9** from the **At Least** dropdown list. - -![Set the length to 9](/images/passwordpolicyenforcer/11.0/evaluation/evallength9.webp) - -**Step 4 –** Click **Save**. - -**Step 5 –** Click **Test policy**. - -**Step 6 –** Select the **PPETestAdmin** user. The results pane shows the **Admins Policy** is being -applied, and the password must **contain at least 9 characters**. - -![Admins policy is being tested](/images/passwordpolicyenforcer/11.0/evaluation/evaladmin.webp) - -Use the Password Policy Enforcer configuration console, the Windows Change Password screen, the -Active Directory Users and Computers console, or the Local Users and Groups console to test password -changes and resets for the **PPETestUser** and **PPETestAdmin** accounts. Password Policy Enforcer -should enforce the Eval policy for **PPETestUser**, and the Admins policy for **PPETestAdmin**. - -:::note -The [Set Priorities](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/manage_policies.md#set-priorities) topic contains -more information about policy assignments, and how Password Policy Enforcer resolves policy -assignment conflicts that occur when more than one policy is assigned to a user. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/evaluation_overview.md b/docs/passwordpolicyenforcer/11.0/evaluation/evaluation_overview.md deleted file mode 100644 index 0ccc625df5..0000000000 --- a/docs/passwordpolicyenforcer/11.0/evaluation/evaluation_overview.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -title: "Evaluate Password Policy Enforcer" -description: "Evaluate Password Policy Enforcer" -sidebar_position: 50 ---- - -# Evaluate Password Policy Enforcer - -Netwrix Password Policy Enforcer is an advanced password filter for Windows. Use this guide to -quickly install, configure, and test an evaluation version of Password Policy Enforcer. Netwrix -Password Policy Enforcer helps secure your network by ensuring users set strong passwords. When a -user enters a password that doesn't comply with the password policy, Password Policy Enforcer -immediately rejects the password and details why the password was rejected. - -![introduction_3](/images/passwordpolicyenforcer/11.0/evaluation/introduction_3.webp) - -Unlike password cracking products that check passwords after they are accepted by the operating -system, Password Policy Enforcer checks new passwords immediately to ensure that weak passwords do -not jeopardize system security. - -:::note -You can also use Password Policy Enforcer to ensure that passwords are compatible with -other systems, and to synchronize passwords with other systems and applications. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/installforeval.md b/docs/passwordpolicyenforcer/11.0/evaluation/installforeval.md deleted file mode 100644 index 12a90ca4c9..0000000000 --- a/docs/passwordpolicyenforcer/11.0/evaluation/installforeval.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -title: "Install Password Policy Enforcer for Evaluation" -description: "Install Password Policy Enforcer for Evaluation" -sidebar_position: 20 ---- - -# Install Password Policy Enforcer for Evaluation - -The evaluation installation uses the standard installation packages: - -- Server Installation: install on each server and domain controller in the domain you are - evaluating. You can install manually using the procedure in - [Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.0/installation/installationserver.md) or automatically - with [Install with Group Policy Management](/docs/passwordpolicyenforcer/11.0/installation/installationgpm.md) procedure. Installing - Password Policy Enforcer doesn't extend the Active Directory schema. Be sure and install the - **Configuration Console** feature on at least one server. -- Client Installation: install on each workstation you are evaluating. The Password Policy Client is - an optional Password Policy Enforcer component to help users choose compliant passwords. Follow - the [Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.0/installation/installationclient.md) procedure, or - [Install with Group Policy Management](/docs/passwordpolicyenforcer/11.0/installation/installationgpm.md). - -You may need to create a firewall port exception on the domain controllers if you are evaluating the -Password Policy Client on a domain with client computers. See the -[Password Policy Client](/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/password_policy_client.md) topic for additional -information. diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/preparing_the_computer.md b/docs/passwordpolicyenforcer/11.0/evaluation/preparing_the_computer.md deleted file mode 100644 index caf25b0a58..0000000000 --- a/docs/passwordpolicyenforcer/11.0/evaluation/preparing_the_computer.md +++ /dev/null @@ -1,62 +0,0 @@ ---- -title: "Prepare the Computer" -description: "Prepare the Computer" -sidebar_position: 10 ---- - -# Prepare the Computer - -You only need one computer for the evaluation. A Windows Server 2016, 2019, or 2022 domain -controller in its own domain is recommended. You can also use Windows 10 or 11 if you only need to -enforce policies for local accounts. - -## Disable the Windows Password Policy Rules - -If the Password Policy Enforcer and Windows password policies are both enabled, then users must -comply with both policies. This isn't recommended for the evaluation because the Windows policy may -stop users from reusing recent passwords, or from changing their password more than once a day. -These restrictions can make it difficult to evaluate Password Policy Enforcer. - -This procedure disables the Windows password policy: - -**Step 1 –** Open the appropriate policy management tool: - -- If you are evaluating Password Policy Enforcer on a domain, use the Group Policy Management - Console (**gmpc.msc**) to display the GPOs linked at the domain level. Right-click the **Default - Domain Policy GPO** (or whichever GPO you use to set the password policy), then click the - **Edit...** button. -- If you are evaluating Password Policy Enforcer on a standalone server or workstation, open the - **Local Group Policy Editor** (**gpedit.msc**). - -**Step 2 –** Expand the following items: - -- Computer Configuration -- Policies (if it exists) -- Windows Settings -- Security Settings -- Account Policies -- Password Policy - -**Step 3 –** Double-click **Enforce password history** in the right pane of the GPO Editor. - -**Step 4 –** Enter **0** in the text box, then click **OK**. - -**Step 5 –** Repeat this step for the Maximum Password Age and Minimum Password Length -policies. - -**Step 6 –** Double-click the **Group Policy Management Editor**. - -**Step 7 –** Close the **Group Policy Management Editor**. - -![preparing_the_computer](/images/passwordpolicyenforcer/11.0/evaluation/preparing_the_computer.webp) - -**Step 8 –** Execute the `gpupdate/target:computer` command to refresh the Group Policy. - -## Create Test Accounts - -Create two user accounts for the evaluation: **PPETestUser** and **PPETestAdmin**. - -![preparing_the_computer_1](/images/passwordpolicyenforcer/11.0/evaluation/preparing_the_computer_1.webp) - -Make **PPETestAdmin** a member of the Domain Admins group if you are evaluating Password Policy -Enforcer on a domain controller. diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/testing_the_password_policy.md b/docs/passwordpolicyenforcer/11.0/evaluation/testing_the_password_policy.md deleted file mode 100644 index 5750f175e5..0000000000 --- a/docs/passwordpolicyenforcer/11.0/evaluation/testing_the_password_policy.md +++ /dev/null @@ -1,140 +0,0 @@ ---- -title: "Test the Password Policy" -description: "Test the Password Policy" -sidebar_position: 50 ---- - -# Test the Password Policy - -You can test the policy from the policy settings right where you are in the policy settings. You can -also test it from the Password Policy Enforcer configuration console dashboard, the Windows Change -Password screen, or the Active Directory Users and Computers / Local Users and Groups consoles. - -## Configuration Console - -Test policy is available in the policy settings and on the configuration console dashboard. This -option shows you the most information about the policy. - -**Step 1 –** Click **Test policy**. - -**Step 2 –** Select the **PPETestUser** you created. The details pane displays the policy applied to -the selected user. - -![Enter user name for the test](/images/passwordpolicyenforcer/11.0/evaluation/evaltestuser.webp) - -**Step 3 –** Enter a password to test. - -The Password Policy Enforcer configuration console tests the password by simulating a password -change, but it doesn't change the user's password. A green check mark indicates the password -complies, a red and white x indicates the password fails. Detailed test results appear in the -results pane. - -**mypassword** fails two requirements. You can hover over the requirements to view the associated -rule. - -![mypassword fails](/images/passwordpolicyenforcer/11.0/evaluation/evaltestuserfail.webp) - -Click **View log** to expand Password Policy Enforcer's internal event log. The information in the -event log can help you to understand why Password Policy Enforcer accepted or rejected a password. - -:::note -Policy testing simulates a password change, but it may not always reflect what happens -when a user changes their password. See the -[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) -topic for additional information. -::: - - -## Windows Change Password Screen - -This is how most users change their password. Testing password policies from the Windows Change -Password screen is useful because it shows you exactly what your users see. - -From the Windows Change Password screen: - -**Step 1 –** Press **CTRL + ALT + DEL**. - -**Step 2 –** Click the **Change a password** option. - -**Step 3 –** Enter a user name in the User name text box. - -**Step 4 –** Enter passwords in the Old Password, New Password, and Confirm Password text boxes. - -**Step 5 –** Click the **submit arrow**. - -You may have noticed that the Change Password screen looks different after installing Password -Policy Enforcer. The Password Policy Enforcer password policy is shown during password changes if -the Password Policy Client is installed. This helps users to choose a compliant password. The -Password Policy Client also changes the message that users see when their password is rejected. Both -these messages are customizable. - -![introduction_3](/images/passwordpolicyenforcer/11.0/evaluation/introduction_3.webp) - -The Password Policy Client doesn't modify any Windows system files, and you don't have to install -it to enforce a Password Policy Enforcer password policy. Web browser based versions of the Password -Policy Enforcer Client are also available. - -## Active Directory Users / Computers Console and local Users and Groups Console - -Administrators often change domain passwords from the Active Directory Users and Computers console -and local passwords from the Local Users and Groups console. In fact, these consoles don't change -passwords; they reset them. This is an important distinction because a password reset is: - -- Restricted to privileged users -- Performed without knowing the current password - -Password Policy Enforcer can enforce the password policy for both password changes and password -resets. It does this by default, but you can configure it to only enforce the password policy for -password changes. The Minimum Age rule is never enforced when a password is reset. - -Follow the following steps to test password policies from these consoles. - -**Step 1 –** Open the appropriate console: - -- If Password Policy Enforcer is enforcing a domain policy, open the Active Directory Users and - Computers console -- If Password Policy Enforcer is enforcing a local policy, open the Local Users and Groups console - -**Step 2 –** Right-click a user, then click **Reset Password**. - -**Step 3 –** Enter a password in the **New password** and **Confirm password** text boxes. - -**Step 4 –** Click **OK**. - -:::note -These consoles don't explain why a password was rejected. Use the Password Policy -Enforcer configuration console, or the Change Password screen with the Password Policy Enforcer -Client installed to see this information. -::: - - -Here are some sample passwords and expected test results when the Users policy is enforced. Try to -change the password for the PPETestUser account to confirm that Password Policy Enforcer is -enforcing the password policy correctly. - -| Password | Result | Reason | -| -------- | -------- | -------------------------------------------- | -| AbdF6 | Rejected | Doesn't contain at least 7 characters | -| abd65fgo | Rejected | Doesn't contain an upper alpha character | -| ABD65FGO | Rejected | Doesn't contain a lower alpha character | -| PPETest1 | Rejected | Similar to user logon name | -| Aardvark | Rejected | Similar to common password (dictionary file) | -| tseTEPP | Accepted | N/A | -| kravdraA | Accepted | N/A | -| Aardv@rk | Accepted | N/A | - -Password Policy Enforcer accepts the last three passwords in the table because they comply with the -password policy, but this highlights some weaknesses in this policy: - -- tseTEPP is part of the user logon name with the characters reversed -- kravdraA is Aardvark with the characters reversed -- Aardv@rk is Aardvark with an @ substituting an "a." - -These three passwords are only marginally stronger than the rejected passwords. The next section -shows you how to improve the password policy so Password Policy Enforcer rejects these passwords. - -:::note -Contact [Netwrix support](mailto:support@anixis.com) if Password Policy Enforcer isn't -working as expected. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/gettingstarted.md b/docs/passwordpolicyenforcer/11.0/gettingstarted.md deleted file mode 100644 index 3b42f88ee1..0000000000 --- a/docs/passwordpolicyenforcer/11.0/gettingstarted.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Getting Started" -description: "Getting Started" -sidebar_position: 2 ---- - -# Getting Started - -Review the [Domain and Local Policies](/docs/passwordpolicyenforcer/11.0/installation/domain_and_local_policies.md) topic. - -## Install Products - -Password Policy Enforcer (PPE Server) is installed on every domain controller to enforce the -password policy for domain user accounts, or on individual servers and workstations to enforce the -password policy for local user accounts. See the -[Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.0/installation/installationserver.md) or -[Install with Group Policy Management](/docs/passwordpolicyenforcer/11.0/installation/installationgpm.md) topics for additional -information. - -The Configuration Console can be installed on what ever servers are convenient for you to access. It -is a selectable feature in the server installation **msi** package. See the -[Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.0/installation/installationserver.md) topic for additional -information. - -The Mailer Service is installed on a single server in each domain. See the -[Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.0/installation/installationserver.md) topic for additional -information. - -Password Policy Enforcer client is optional, but recommended. Users receive immediate feedback when -setting up their passwords. This saves your users time and frustration when picking compliant -passwords. See the [Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.0/installation/installationclient.md) or -[Install with Group Policy Management](/docs/passwordpolicyenforcer/11.0/installation/installationgpm.md) topics for additional -information. - -Password Policy Enforcer Web is a separate product enabling users to change their Windows domain -password from a web browser. See the [Password Policy Enforcer Web](/docs/passwordpolicyenforcer/11.0/web-overview/web_overview.md) topic for -additional information. - -Create the **Compromised Passwords Base** before enabling the Compromised Password Check. See the -[HIBP Updater](/docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md) topic for additional information. - -## Exclude PPE Files from AntiVirus Checks - -**Domain Controller** - -**PPE.DLL** if this file doesn't load, the password policy isn't enforced. - -**Clients** - -**PPEClt.dll** and **APRClt.dll** if either of these files are blocked, the client doesn't run. - -## Next Steps - -You can work through the [Evaluate Password Policy Enforcer](/docs/passwordpolicyenforcer/11.0/evaluation/evaluation_overview.md). diff --git a/docs/passwordpolicyenforcer/11.0/index.md b/docs/passwordpolicyenforcer/11.0/index.md deleted file mode 100644 index d092523488..0000000000 --- a/docs/passwordpolicyenforcer/11.0/index.md +++ /dev/null @@ -1,89 +0,0 @@ ---- -title: "Netwrix Password Policy Enforcer v11.0" -description: "Netwrix Password Policy Enforcer v11.0" -sidebar_position: 1 ---- - -# Netwrix Password Policy Enforcer v11.0 - -Netwrix Password Policy Enforcer helps secure your network by ensuring users set strong passwords. -When a user enters a password that doesn't comply with the password policy, Password Policy -Enforcer immediately rejects the password and details why the password was rejected. - -# Requirements - -Netwrix Password Policy Enforcer 11 can be installed for both domain and local user accounts. - -Domain user accounts exist in Active Directory. Information about these accounts is kept on the -domain controllers, and changes to the accounts are replicated amongst the domain controllers. - -Local user accounts exist in the SAM database of workstations and servers. The workstations and -servers may be standalone, or domain members. Information about these accounts is only kept on the -host computer, and doesn't replicate to any other computers. - -A typical Windows network has both domain and local user accounts, but you may not want to enforce -Password Policy Enforcer password policies for both account types. If your users normally log on with -a domain account, then you will most likely only use Password Policy Enforcer to enforce password -policies for the domain accounts. - -Password Policy/Web is installed on a Windows server and accessed via user browsers. - -## Password Policy Enforcer Server - -Here are the requirements for both the full and evaluation Password Policy Enforcer installations. - -- Windows Server Versions (64 bit): - -- 2016 -- 2019 -- 2022 - -- Windows Workstation Versions (64 bit only) - -- 10 -- 11 - -## Password Policy Enforcer Client - -Here are the requirements for both the full and evaluation Password Policy Enforcer installations. - -- Windows Server Versions (64 bit): - -- 2016 -- 2019 -- 2022 - -- Windows Workstation Versions (64 and 32 bit) - -- 10 -- 11 - -## Password Policy Enforcer Configuration Console - -Here are the requirements for both the full and evaluation Password Policy Enforcer installations. - -- Windows Server Versions (64 bit): - -- 2016 -- 2019 -- 2022 - -- Windows Workstation Versions (64 and 32 bit) - -- 10 -- 11 - -- .net framework 4.7.2 or higher - -## Password Policy Enforcer Web - -Here are the requirements for the Password Policy Enforcer Web. Password Policy Enforcer Web can -share server resources with other applications. It can be installed on an existing, well secured web -server. - -- Windows Server Versions: - - - 2016 - - 2019 - - 2022 - - Microsoft IIS diff --git a/docs/passwordpolicyenforcer/11.0/installation/disable_windows_rules.md b/docs/passwordpolicyenforcer/11.0/installation/disable_windows_rules.md deleted file mode 100644 index 260384ef29..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/disable_windows_rules.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "Disable Windows Rules" -description: "Disable Windows Rules" -sidebar_position: 80 ---- - -# Disable Windows Rules - -The Windows password policy rules can place restrictions on password history, age, length, and -complexity. If you enable the Password Policy Enforcer rules and the Windows rules, then users must -comply with both sets of rules. - -Password Policy Enforcer has its own history, minimum age, and maximum age, length, and complexity rules. -See the [Rules](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/rules.md) topic for additional information. You can use the Password Policy Enforcer -and Windows rules together. A password is only accepted if it complies with the Windows and Password -Policy Enforcer password policies. - -These steps disable the Windows password policy rules: - -**Step 1 –** Start the Group Policy Management Console **(gpmc.msc**). - -**Step 2 –** Expand the forest and domain items in the left pane. - -**Step 3 –** Right-click the **Default Domain Policy GPO** (or whichever GPO you use to set your -domain password policy), then click **Edit...** - -**Step 4 –** Expand the **Computer Configuration**, **Policies**, **Windows Settings**, **Security -Settings**, **Account Policies**, and **Password Policy** items. - -**Step 5 –** Double-click **Enforce password history** in the right pane of the GPO Editor. - -**Step 6 –** Enter **0** in the text box, then click **OK**. - -**Step 7 –** Repeat this step for the **Maximum password age**, **Minimum password age**, and -**Minimum password length** policies. - -**Step 8 –** Double-click **Password must meet complexity requirements** in the right pane. - -**Step 9 –** Select the **Disabled** option, and then click **OK**. - -**Step 10 –** Close the Group Policy Management Editor. - -![installing_ppe_3](/images/passwordpolicyenforcer/11.0/evaluation/preparing_the_computer.webp) - -:::note -You don't have to disable all the Windows password policy rules to use Password Policy -Enforcer. You can use a combination of Password Policy Enforcer and Windows rules together if you -like. Just remember that a password is only accepted if it complies with the rules enforced by both -Windows and Password Policy Enforcer. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/installation/domain_and_local_policies.md b/docs/passwordpolicyenforcer/11.0/installation/domain_and_local_policies.md deleted file mode 100644 index 2b91604be5..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/domain_and_local_policies.md +++ /dev/null @@ -1,103 +0,0 @@ ---- -title: "Domain and Local Policies" -description: "Domain and Local Policies" -sidebar_position: 10 ---- - -# Domain and Local Policies - -Netwrix Password Policy Enforcer enforces password policies for both domain and local user accounts. - -Domain user accounts exist in Active Directory. Information about these accounts is kept on the -domain controllers, and changes to the accounts are replicated amongst the domain controllers. - -Local user accounts exist in the SAM database of workstations and servers. The workstations and -servers may be standalone, or domain members. Information about these accounts is only kept on the -host computer, and doesn't replicate to any other computers. - -A typical Windows network has both domain and local user accounts, but you may not want to enforce -Password Policy Enforcer password policies for both account types. If your users normally log on with -a domain account, then you will most likely only use Password Policy Enforcer to enforce password -policies for the domain accounts. - -## Installation Differences - -To enforce password policies for domain user accounts, you should install Password Policy Enforcer -onto all the domain controllers in the domain. If you have read-only domain controllers and aren't -using the [Rules](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/rules.md), [Password Policy Client](/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/password_policy_client.md), or other software -(such as -[Netwrix Password Reset](https://www.netwrix.com/active_directory_password_reset_tool.html)) that -uses the Password Policy Enforcer Client protocol, then you don't need to install Password Policy -Enforcer on the read-only domain controllers. - -To enforce password policies for local user accounts, you should install Password Policy Enforcer -onto the computers containing the user accounts you want to enforce password policies for. These -computers may be workstations or servers, and they may be standalone or domain members. It is -normally not necessary to install Password Policy Enforcer onto all the workstations and servers in -a domain because most users in a domain logon with a domain account. If this is the case, then you -will most likely only need to install Password Policy Enforcer on the domain controllers. - -## Operational Differences - -Most of Password Policy Enforcer's rules and features can be used with both domain and local -policies, but there are some differences. When enforcing the password policy for domain accounts, -Password Policy Enforcer queries Active Directory to get information about the accounts. - -While it is theoretically possible to get most of this information from the SAM database for local -accounts, there is a technical limitation which stops password filters from querying the SAM. There -is also some information, such as the user's OU, which doesn't exist in the SAM. Because of these -limitations, the following rules and features can't be used with local password policies: - -- The Minimum Age and Maximum Age rules (you can use the Windows version of these rules with - Password Policy Enforcer). See the [Rules](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/rules.md) topic for additional information. -- Policy assignments by groups and containers. See the - [Assign Policies to Users & Groups](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/usersgroups.md) topic for additional information. - -Password Policy Enforcer's configuration is stored in Active Directory for domain password policies, -and in the Windows registry for local password policies. The Connect To page in the Password Policy -Enforcer management console. Use it to choose a configuration source. See the -[Connected To](/docs/passwordpolicyenforcer/11.0/admin/configconsole.md#connected-to) topic for additional information. Changes you make to -Password Policy Enforcer's domain configuration are replicated to all domain controllers in the -domain. Changes to a local configuration are applied only to the local computer. If you want to use -the same local configuration for many computers, export the HKLM\SOFTWARE\ANIXIS\Password Policy -Enforcer 10.0\ registry key from the configured computer, and import it into the other computers. - -You can also use Group Policy to distribute Password Policy Enforcer's local configuration to many -computers in a domain. This is only necessary for local password policies. Domain password policies -automatically replicate to the domain controllers because they are stored in Active Directory. - -Follow the following steps to distribute Password Policy Enforcer's local configuration with Group -Policy. - -**Step 1 –** Start the Group Policy Management Console (gpmc.msc). - -**Step 2 –** Expand the forest and domain items in the left pane. - -**Step 3 –** Right-click the **Group Policy** object that you would like to use to distribute the -configuration, and then click the **Edit...** button. - -**Step 4 –** Expand the Computer Configuration, Preferences, and Windows Settings items in the left -pane. - -**Step 5 –** Right-click the **Registry** item, and then select **New** > **Registry Wizard**. - -![domain_and_local_policies](/images/passwordpolicyenforcer/11.0/administration/domain_and_local_policies.webp) - -**Step 6 –** Select the computer that contains the Password Policy Enforcer local configuration that -you want to distribute, and then click **Next**. - -**Step 7 –** Expand the **HKEY_LOCAL_MACHINE**, **SOFTWARE**, and **ANIXIS** items. - -**Step 8 –** Click the **Password Policy Enforcer _version_** item, and then select the check boxes -beside each item in the bottom pane of the window. - -![domain_and_local_policies_1](/images/passwordpolicyenforcer/11.0/administration/domain_and_local_policies_1.webp) - -**Step 9 –** Click **Finish**. - -**Step 10 –** Close the Group Policy Management Editor. - -Password Policy Enforcer's local configuration is applied to the target computers in the domain. -This doesn't happen immediately, as Windows takes some time to apply the changes to Group Policy. -You can force an immediate refresh of Group Policy on the local computer with this command: -`gpupdate /target:computer` diff --git a/docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md b/docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md deleted file mode 100644 index 9002b163af..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "HIBP Updater" -description: "HIBP Updater" -sidebar_position: 90 ---- - -# HIBP Updater - -Password Policy Enforcer can be configured to use the Have I Been Pwnd (HIBP) database. A copy of -this database is hosted on the Netwrix website. The HIBP database contains a list of the hashes of -known compromised passwords. During password change operations, the application can be configured to -reject passwords with a hash that matches a hash in the HIBP database. See the Password Policy -Enforcer [Compromised Password Check](/docs/passwordpolicyenforcer/11.0/admin/compromisedpasswordcheck.md) topic for HIBP database -information and configuration options. - -The HIBP database must be initially deployed to a server or workstation with an internet connection -that can retrieve and format the file. After the database is formatted, you can distribute the HIBP -database to your domain controllers so the Password Policy Enforcer server can check passwords -against the HIBP database. - -## Considerations When Deploying the HIBP Database - -Before deploying the HIBP database, consider the pros and cons when choosing its deployment -location. - -- The HIBP database takes up additional space on the machine where it is copied (approximately 13 - GB, but subject to change) -- A network connection to the application server isn't required to check passwords against the HIBP - database - -## Installation and Configuration - -The HIBP Updater is installed when you install the Password Policy Enforcer Configuration Console. - -:::info -Only run this from one server. -::: - - -**Step 1 –** To access the HIBP Updater, navigate to the installation location: - -**...\Program Files\Password Policy Enforcer\HIBP\** - -![hibpfolder](/images/passwordpolicyenforcer/11.0/administration/hibpfolder.webp) - -**Step 2 –** Click HIBPWINUpdater. - -### Passwords Hash Database - -Password Policy Enforcer uses the Passwords Hash database to check if users’ new and pending -password (i.e. during a password reset) matches the hash of a compromised password from a data -breach. - -:::note -First-time configuration of this window requires downloading the HIBP database from the -Netwrix website. -::: - - -![HIBP Updater](/images/passwordpolicyenforcer/11.0/administration/hibpupdater.webp) - -:::warning -Ensure the initial update of the database occurs during non-office hours. Due to the -size of the hash file, this download takes up a significant amount of CPU and download time. -::: - - -- Passwords Hash Database Folder – Central location of the Pwned database on the application server. - The default path is: - -**…\HIBP\DB** - -- Update Type: - - - Full Download – Download all data from the HIBP database hosted on the Netwrix website - - Incremental Update – Download updates from the HIBP database hosted on the Netwrix website - instead of downloading the full HIBP database. This option is enabled after a full download of - the HIBP database has completed. - - :::note - Only the full HIBP database file obtained from the Netwrix website has version - information. That full HIBP database file can be obtained using the Website option. - Alternately, the HIBP database can be obtained outside of the application by downloading it - directly from the Netwrix website using an FTP connection: - ::: - - - - [https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip](https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip) - - [https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip.sha256.txt](https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip.sha256.txt) - - Then use the File option to enable incremental updates. - -- Location: - - - File – If the application server doesn't have internet access, you can manually download the - HIBP database and select the **File** radio button to browse to your local copy of the - database - - Web Site – This option points to the Netwrix website that hosts a copy of the latest HIBP - database. This is the default option and the preferred method if the application server has - internet access. - -- Apply: - - - If Website is selected, then clicking **Apply** downloads the HIBP database from the Netwrix - website and then processes the database for use by the application - - If File is selected, then clicking **Apply** processes the local copy of the (manually obtained) database for use by the application - -### Hash File Replication - -Password Policy Enforcer doesn't distribute hash file updates to other computers, but you can use -the Windows Distributed File System to ensure that all domain controllers have the latest hash -files. Copy the hash files into the Sysvol share on one domain controller, and the Distributed File -System will copy the files into the Sysvol share of all other domain controllers. Configure the -Compromised rule to read the files from: - -**\\127.0.0.1\sysvol\your.domain\filename.db** - -See the [Compromised Rule](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/compromised_rule.md) topic for additional information. - -This path only works if the computer has a Sysvol share. This won't be the case if you are -using a workstation for policy testing, or if you are using Password Policy Enforcer to enforce -local policies. If you are using Password Policy Enforcer for local policies and want all computers -to receive hash file updates, then use the Sysvol share for file replication and a script or -scheduled task to copy the file to a local folder. - -:::warning -%SystemRoot%. hash files should only be read from a local disk. Using shared hash files -degrades performance, and could jeopardize security. -::: - - -## Scheduler - -Password Policy Enforcer administrators can use the Scheduler portion of the HIBP Updater to -automate the tool to retrieve and/or prepare the HIBP dataset. The Scheduler uses Microsoft Task -Scheduler technology to execute the process. - -### How to Schedule a Task - -**Step 1 –** Click **Scheduler** in the HIBP Updater. - -**Step 2 –** Click **Add Schedule**. An Edit Schedule window appears that looks similar to the HIBP -Updater window. - -![editschedule](/images/passwordpolicyenforcer/11.0/administration/editschedule.webp) - -**Step 3 –** Enter the Name and Description of the schedule. - -**Step 4 –** Select **Add Trigger** to add the interval that you want to have the schedule run. - -- You can add as many triggers as you want to a schedule. - -**Step 5 –** Select the Update Type and Location to get the update. - -**Step 6 –** After you have set up your schedule, click **OK** to save the schedule. - -The HIBP database is updated according to the schedule. - -### Schedule List - -The Schedule List window shows the names, run times, next run times, and whether the schedule is -enabled or not. - -![schedulelist](/images/passwordpolicyenforcer/11.0/administration/schedulelist.webp) - -Use this window to Add, Edit, or Delete schedules for the HIBP Updater. diff --git a/docs/passwordpolicyenforcer/11.0/installation/installationclient.md b/docs/passwordpolicyenforcer/11.0/installation/installationclient.md deleted file mode 100644 index 4d438aa8c3..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/installationclient.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Install Password Policy Enforcer Client" -description: "Install Password Policy Enforcer Client" -sidebar_position: 30 ---- - -# Install Password Policy Enforcer Client - -This procedure is used to install the client on your current workstation. See the -[Install with Group Policy Management](/docs/passwordpolicyenforcer/11.0/installation/installationgpm.md) top for details on installing the client -across your network. You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.0/admin/command_line_interface.md#silent-installation). - -**Step 1 –** Navigate to the folder where you extracted the installers downloaded from Netwrix. - -**Step 2 –** Click the **Netwrix_PPE_Client**version**x64.msi** (64 bit OS) or -**Netwrix_PPE_Client**version**x86.msi** (32 bit OS) installation package. The installer is -launched. - -![Client Setup](/images/passwordpolicyenforcer/11.0/install/clientsetup1.webp) - -**Step 3 –** Click **Next**. - -![Client Setup](/images/passwordpolicyenforcer/11.0/install/clientsetup2.webp) - -**Step 4 –** Review the End-User License Agreement. Click **I accept the terms in the License -Agreement**. - -**Step 5 –** Click **Next**. - -![Client Setup](/images/passwordpolicyenforcer/11.0/install/clientsetup3.webp) - -**Step 6 –** Click **Install**. - -![Client Setup](/images/passwordpolicyenforcer/11.0/install/clientsetup4.webp) - -**Step 7 –** Click **Finish** when installation is complete. - -The client is installed. There is no associated desktop icon or menu item. - -Restart each computer to complete the installation. Windows installs the Password Policy Client -during startup. - -## Testing the Password Policy Client - -Test the Password Policy Client by logging on to a computer and pressing the CTRL + ALT + DEL keys -and clicking the **Change a password** item. If you don't see the password policy, it could be -because a Password Policy Enforcer policy hasn't been assigned to you, or because the firewall -rules haven't been created. - -:::note -The Password Policy Client doesn't store or send passwords or password hashes over the -network. An attacker can't determine user passwords by sniffing the communication protocol. The -protocol is also encrypted by default for additional protection. -::: - - -## Creating Firewall Rules for the Password Policy Client - -You may need to create firewall rules for the Password Policy Client if your domain controllers are -running a software (host) firewall, or if the Password Policy Client and Password Policy Server -communicate through a firewall. Firewall rules aren't necessary for local policies because the -Password Policy Client and Password Policy Server are on the same computer. - -### Windows Firewall - -If Windows Firewall is enabled on your domain controllers, then you must create a port exception to -allow connections to the Password Policy Server. Windows Firewall is enabled by default on Windows -Server 2008 and later. - -Follow the following steps to create the port exception on all domain controllers. - -**Step 1 –** Use the **Group Policy Management Console** (gpmc.msc) to display the GPOs linked to -the Domain Controllers OU. - -**Step 2 –** Right-click the **Password Policy Enforcer GPO**, and then click **Edit...**. - -:::note -You need to create the GPO if you chose the Express Setup option. -::: - - -**Step 3 –** Expand the **Computer Configuration**, **Policies**, **Administrative Templates**, -**Network**, **Network Connections**, and **Windows Firewall** items. - -**Step 4 –** Click **Domain Profile** in the left pane then double-click **Windows Firewall: Define -inbound port exceptions** in the right pane. - -![the_password_policy_client_3](/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_3.webp) - -**Step 5 –** Select the **Enabled** option, and then click **Show...**. - -![the_password_policy_client_4](/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_4.webp) - -**Step 6 –** Select the **Enabled** option, and then click **Show...**. - -![the_password_policy_client_5](/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_5.webp) - -**Step 7 –** Click **OK** until you return to the Group Policy Management Editor. - -**Step 8 –** Close the **Group Policy Management Editor**. - -### Other Firewalls - -Use the information on this page to create appropriate rules for your firewall that allow the -Password Policy Client and Password Policy Server to communicate through the firewall. - -The Password Policy Client initiates a request by sending a datagram with the following attributes -to the Password Policy Server: - -| Attribute | Result | -| ------------------- | ---------------------------- | -| Protocol | UDP | -| Source Address | Client Computer IP address | -| Source Port | Any | -| Destination address | Domain controller IP address | -| Destination port | 1333 | - -The Password Policy Server responds by sending a datagram with the following attributes back to the -Password Policy Client: - -| Attribute | Result | -| ------------------- | ---------------------------- | -| Protocol | UDP | -| Source Address | Domain controller IP address | -| Source Port | Any | -| Destination address | Client Computer IP address | -| Destination port | Any | - -:::note -If your firewall performs Stateful Packet Inspection, then only create a rule for the -request datagram as the firewall automatically recognizes and allows the response datagram. - -::: diff --git a/docs/passwordpolicyenforcer/11.0/installation/installationconfigconsole.md b/docs/passwordpolicyenforcer/11.0/installation/installationconfigconsole.md deleted file mode 100644 index 8db57075b6..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/installationconfigconsole.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -title: "Install the Configuration Console" -description: "Install the Configuration Console" -sidebar_position: 50 ---- - -# Install the Configuration Console - -The Configuration Console configures and manages Netwrix Password Policy Enforcer on your domain. - -Install the Password Policy Enforcer Configuration Console on any server or workstation where you need it. - -The Configuration Console is a feature package included in the server installation **.msi** file: - -- PPE Server – enforces password policies. It can be installed on Domain Controllers for domain - password policy, or on servers and workstations for local account password policy. -- Configuration Console – manages policy configuration. Install wherever needed. -- Mailer Service – sends email reminders. Install on any server. - -Follow the procedure in [Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.0/installation/installationserver.md), -selecting the **Configuration Console** feature. You can select the other features if appropriate -for the server. - -You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.0/admin/command_line_interface.md#silent-installation). diff --git a/docs/passwordpolicyenforcer/11.0/installation/installationgpm.md b/docs/passwordpolicyenforcer/11.0/installation/installationgpm.md deleted file mode 100644 index c88ed35efc..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/installationgpm.md +++ /dev/null @@ -1,86 +0,0 @@ ---- -title: "Install with Group Policy Management" -description: "Install with Group Policy Management" -sidebar_position: 40 ---- - -# Install with Group Policy Management - -An automated installation uses Group Policy to distribute Password Policy Enforcer. This type of -installation is recommended when you need to install Password Policy Enforcer on many computers. -This section shows you how to install Password Policy Enforcer on domain controllers to enforce -domain policies, but you can also use Group Policy to target member servers and workstations if you -need to enforce local policies. See the -[Domain and Local Policies](/docs/passwordpolicyenforcer/11.0/installation/domain_and_local_policies.md) topic for additional -information. - -## Create a Distribution Point - -A distribution point can either be a UNC path to a server share, or a DFS (Distributed File System) -path. To create a Password Policy Enforcer distribution point: - -**Step 1 –** Log on to a server as an administrator. - -**Step 2 –** Create a shared network folder to distribute the files from. - -**Step 3 –** Give the **Domain Controllers** security group read access to the share, and limit -write access to authorized personnel only. - -**Step 4 –** Download the Netwrix Password Policy Enforcer installation package from Netwrix. - -**Step 5 –** Extract the installers from the compressed file. - -**Step 6 –** Copy the **.msi** files to the distribution folder. - -## Create a Group Policy Object - -**Step 1 –** Start the Group Policy Management Console (**gpmc.msc**). - -**Step 2 –** Expand the forest and domain items in the left pane. - -**Step 3 –** Right-click the **Domain Controllers OU** in the left pane, and then click **Create a -GPO in this domain, and Link it here...** - -![GPM installation](/images/passwordpolicyenforcer/11.0/install/gpm1.webp) - -**Step 4 –** Enter **Password Policy Enforcer** in the provided field, and then press **Enter**. - -![GPM Install](/images/passwordpolicyenforcer/11.0/install/gpm2.webp) - -## Edit the Group Policy Object - -**Step 1 –** Right-click the **Password Policy Enforcer GPO**, and then click the **Edit...** -button. - -**Step 2 –** Expand the **Computer Configuration**, **Policies**, and **Software Settings** items. - -**Step 3 –** Right-click the **Software installation** item, and then select **New** > -**Package...** - -**Step 4 –** Enter the full **UNC path** to your **msi** files. - -:::note -You must enter a UNC path so that other computers can access this file over the network. -For example: \\file server\distribution point share\Netwrix*PPE\_\_version*.msi -::: - - -**Step 5 –** Click **Open**. - -![installing_ppe_2](/images/passwordpolicyenforcer/11.0/install/installing_ppe_2.webp) - -**Step 6 –** Select **Assigned** as the deployment method. - -**Step 7 –** Click **OK**. - -**Step 8 –** Close the Group Policy Management Editor. - -## Complete the Installation - -Restart each domain controller to complete the installation. Windows installs Password Policy -Enforcer during startup, and then immediately restarts the computer a second time to complete the -installation. - -Password Policy Enforcer doesn't enforce a password policy until the policies are defined. Users -can still change their password, and must comply only with the Windows password policy rules -(if enabled). diff --git a/docs/passwordpolicyenforcer/11.0/installation/installationmailer.md b/docs/passwordpolicyenforcer/11.0/installation/installationmailer.md deleted file mode 100644 index 9f47ba61ac..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/installationmailer.md +++ /dev/null @@ -1,33 +0,0 @@ ---- -title: "Install Mailer Service" -description: "Install Mailer Service" -sidebar_position: 60 ---- - -# Install Mailer Service - -Netwrix Password Policy Enforcer sends email reminders to domain users before their passwords -expire. This is especially useful for users who log on infrequently, and for remote users who access -the network without logging on to the domain. You must install the Password Policy Enforcer Mailer -and configure the email delivery and email message options to send email reminders to users. See the -[Notifications](/docs/passwordpolicyenforcer/11.0/admin/configconsole.md#notifications) topic for additional information. - -Add your email address to a service account, and the Password Policy Enforcer Mailer reminds you to -change the service account password before it expires. - -The Password Policy Enforcer Mailer isn't installed by default. Only install it on one server in -each domain. The Password Policy Enforcer Mailer can be installed on any server. - -The mailer is a feature package included in the server installation **.msi** file: - -- PPE Server – enforces password policies. It can be installed on Domain Controllers for domain - password policy, or on servers and workstations for local account password policy. -- Configuration Console – manages policy configuration. Install wherever needed. -- Mailer Service – sends email reminders. Install on any server. - -Follow the procedure in [Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.0/installation/installationserver.md), -selecting the **Mailer Service** feature. You can select the other features if appropriate for the -server. - -You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.0/admin/command_line_interface.md#silent-installation). diff --git a/docs/passwordpolicyenforcer/11.0/installation/installationserver.md b/docs/passwordpolicyenforcer/11.0/installation/installationserver.md deleted file mode 100644 index d3ea315ceb..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/installationserver.md +++ /dev/null @@ -1,80 +0,0 @@ ---- -title: "Install Password Policy Enforcer on a Server" -description: "Install Password Policy Enforcer on a Server" -sidebar_position: 20 ---- - -# Install Password Policy Enforcer on a Server - -Password Policy Enforcer server should be installed on every domain controller to enforce the -password policy for domain user accounts, or on individual servers and workstations to enforce the -password policy for local user accounts. - -If your domain contains some read-only domain controllers, then installation of Password Policy -Enforcer on these servers is only necessary if you are using the following features: - -- [Rules](/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/rules.md) -- [Password Policy Client](/docs/passwordpolicyenforcer/11.0/admin/password-policy-client/password_policy_client.md) -- [Netwrix Password Reset](https://helpcenter.netwrix.com/category/passwordreset) -- [Password Policy Enforcer Web](/docs/passwordpolicyenforcer/11.0/web-overview/web_overview.md) - -The Server installation package includes multiple features selected during installation: - -- PPE Server – enforces password policies. It can be installed on Domain Controllers for domain - password policy, or on servers and workstations for local account password policy. -- Configuration Console – manages policy configuration. Install wherever needed. -- Mailer Service – sends email reminders. Install on any server. - -**Step 1 –** Download the installation package from Netwrix. - -**Step 2 –** Extract the installers from the compressed file. If you are going to use Group Policy -Manager to install Netwrix Password Policy Enforcer, copy the **msi** files to a distribution -folder. See the [Install with Group Policy Management](/docs/passwordpolicyenforcer/11.0/installation/installationgpm.md) topic for additional -details. You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.0/admin/command_line_interface.md#silent-installation). - -:::note -Continue with these steps to install one or more features on your current server or domain -controller. You must repeat these steps for each server where the features are installed. -::: - - -**Step 3 –** Click the **Netwrix_PPE_Server**version**x64.msi** installation package. The -installer is launched. - -![Server Setup](/images/passwordpolicyenforcer/11.0/install/serversetup1.webp) - -**Step 4 –** Click **Next**. - -![Server Setup](/images/passwordpolicyenforcer/11.0/install/serversetup2.webp) - -**Step 5 –** Review the End-User License Agreement. Click **I accept the terms in the License -Agreement**. - -**Step 6 –** Click **Next**. - -![Server Setup](/images/passwordpolicyenforcer/11.0/install/serversetup3.webp) - -**Step 7 –** Select the features to install. The required storage is shown for each selection. - -- PPE Server – enforces password policies. It can be installed on Domain Controllers for domain - password policy, or on servers and workstations for local account password policy. It isn't - selected by default. -- Configuration Console – manages policy configuration. Install wherever needed. Selected by - default. -- Mailer Service – sends email reminders. Should be installed on a Domain Controller. It isn't - selected by default. - -**Step 8 –** The default location is shown. Click **Browse** and select a new location if needed. - -**Step 9 –** Click **Next**. - -![Server Setup](/images/passwordpolicyenforcer/11.0/install/serversetup4.webp) - -**Step 10 –** Review your selections. Click **Back** to make any changes. When ready, click -**Install**. - -![Server Setup](/images/passwordpolicyenforcer/11.0/install/serversetup5.webp) - -**Step 11 –** Click **Finish** when installation is complete. You are prompted to restart your -system for the changes to take effect. diff --git a/docs/passwordpolicyenforcer/11.0/installation/installationweb.md b/docs/passwordpolicyenforcer/11.0/installation/installationweb.md deleted file mode 100644 index 0af8f9277f..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/installationweb.md +++ /dev/null @@ -1,80 +0,0 @@ ---- -title: "Install Password Policy Enforcer Web" -description: "Install Password Policy Enforcer Web" -sidebar_position: 70 ---- - -# Install Password Policy Enforcer Web - -Password Policy Enforcer Web V7.11 is a web server enabling users to change their Windows domain -password from a web browser. - -Click the following link to download Password Policy Enforcer Web: - -[Password_Policy_Enforcer_WEB_7.11.zip](https://www.netwrix.com/download/commercial/Password_Policy_Enforcer_WEB_7.11.zip) - -## The PPE Web Setup Wizard - -The Setup Wizard copies the required files onto the server and configures IIS to run the Password -Policy Enforcer Web application. - -Follow the following steps to install PPE Web. - -**Step 1 –** Start the Password Policy Enforcer Web Setup Wizard (PPEWeb711.exe). - -**Step 2 –** If another version of Password Policy Enforcer Web is detected, the Setup Wizard may -required older files to be backed up. Back up these files if the original files have been modified. -Click **Next**. - -**Step 3 –** Click **Next**. - -**Step 4 –** Read the License Agreement. Click **I accept the terms of the license agreement**, then -click **Next** if you accept all the terms. - -**Step 5 –** Click **Browse...** if you want to choose a different folder for the Password Policy -Enforcer Web documentation and tools, then click **Next**. - -**Step 6 –** Select an **IIS Web Site** from the dropdown. Change the default Virtual Directory, if -needed. - -:::note -Password Policy Enforcer Web should be installed in its own virtual directory. -::: - - -**Step 7 –** Click **Next** twice. - -**Step 8 –** Wait for Password Policy Enforcer Web to install, then click **Finish**. - -#### Upgrading from PPE Web V7.x - -Some planning is needed to ensure a smooth upgrade from PPE Web V7.x. A trial run on a lab network -is recommended. - -#### Before You Begin - -The HTML templates and associated images are overwritten during an upgrade. You must back up and -customized HTML templates and images before upgrading. The HTML templates and images are installed -in the `\Inetpub\wwwroot\ppeweb\` folder by default. - -:::note -A full backup of the PPE Web server is recommended. Use it to roll back to the -previous version if the upgrade can't be completed. You may need to restart Windows after -upgrading. -::: - - -:::warning -PPE Web V7.11 is only compatible with Password Policy Enforcer V7.0 and later. Upgrade -Password Policy Enforcer to a compatible version if you have enabled Password Policy Enforcer -integration. -::: - - -#### Upgrading to V7.11 - -**Step 1 –** Start the PPE Web Setup Wizard and follow the prompts. The Setup Wizard uninstalls the -previous version. There is no need to manually uninstall previous versions. - -**Step 2 –** Restore any customized HTML templates and images after upgrading. Don't restore -PPEWeb.dll from the backup as it belongs to the previous version. diff --git a/docs/passwordpolicyenforcer/11.0/installation/uninstall.md b/docs/passwordpolicyenforcer/11.0/installation/uninstall.md deleted file mode 100644 index 1694cc0308..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/uninstall.md +++ /dev/null @@ -1,29 +0,0 @@ ---- -title: "Uninstall Netwrix Password Policy Enforcer" -description: "Uninstall Netwrix Password Policy Enforcer" -sidebar_position: 120 ---- - -# Uninstall Netwrix Password Policy Enforcer - -You can uninstall Password Policy Enforcer on every domain server and computer, or use Group Policy -Management to remove the PPE Server and PPE Client on all machines. - -You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.0/admin/command_line_interface.md#silent-installation). - -**Step 1 –** Open **Start** > **Control Panel** > **Programs and Features** on each system where a -PPE component is installed. - -**Step 2 –** Click **Uninstall a program**. - -**Step 3 –** Select Netwrix Password Policy Enforcer to uninstall the PPE Server, PPE Configuration -Console and Mailer. - -**Step 4 –** Click **Uninstall**. - -**Step 5 –** Select Netwrix Password Policy Client to uninstall the client. - -**Step 6 –** Click **Uninstall**. - -**Step 7 –** Reboot the Domain Controller. diff --git a/docs/passwordpolicyenforcer/11.0/installation/upgrading.md b/docs/passwordpolicyenforcer/11.0/installation/upgrading.md deleted file mode 100644 index 624f5f7862..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/upgrading.md +++ /dev/null @@ -1,56 +0,0 @@ ---- -title: "Upgrading Password Policy Enforcer" -description: "Upgrading Password Policy Enforcer" -sidebar_position: 110 ---- - -# Upgrading Password Policy Enforcer - -Upgrades are supported for versions 9.0 and above. Contact Customer Support at -[https://www.netwrix.com/support.html](https://www.netwrix.com/support.html) if you need assistance -upgrading older versions - -You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.0/admin/command_line_interface.md#silent-installation). - -**Upgrading the Password Policy Server** - -The Password Policy Enforcer installer detects existing installations and upgrades them to 11. See -the [Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.0/installation/installationserver.md) topic for additional -information. If you are performing an automated installation with Group Policy, then add the new -**.msi** installer files to the same Group Policy Object used to install the older version. See the -[Install with Group Policy Management](/docs/passwordpolicyenforcer/11.0/installation/installationgpm.md) topic for additional information. - -:::note -Upgrade all your servers and domain controllers. Configuration changes performed with the -new version don't affect servers running an older version. If you have multiple versions, you must -make configuration changes in both configuration consoles until all domain controllers are upgraded -to 11. Failure to do so may lead to inconsistent enforcement of the password policy. -::: - - -Open the [License](/docs/passwordpolicyenforcer/11.0/admin/configconsole.md#license) settings on the Configuration Console -after an upgrade to check your license details. Password Policy Enforcer reverts to a 30-day -evaluation license if it can't import the license key. - -**Upgrading the Password Policy Client** - -The Password Policy Client installer detects existing installations and upgrades them to 11. See the -[Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.0/installation/installationclient.md)[Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.0/installation/installationclient.md) -topic for additional information. If you are distributing the Password Policy Client with Group -Policy, then add the new client **.msi** file to the same Group Policy Object used to install the -older version. Upgrade and reboot the Password Policy Servers before upgrading the clients. - -The Password Policy Enforcer 11 Password Policy Server is backwards compatible with the V10.x and -V9.x Password Policy Client. You aren't required to update the Password Policy Clients, but it is -recommended. - -**Upgrading the Mailer** - -The Password Policy Enforcer installer detects existing installations of the Password Policy -Enforcer Mailer and upgrades them to 11. See the [Install Mailer Service](/docs/passwordpolicyenforcer/11.0/installation/installationmailer.md) -topic for additional information. - -**Upgrade Notes** - -- Versions 9.x and above don't support perpetual license keys. diff --git a/docs/passwordpolicyenforcer/11.0/installation/writeback.md b/docs/passwordpolicyenforcer/11.0/installation/writeback.md deleted file mode 100644 index 78e5beb5e8..0000000000 --- a/docs/passwordpolicyenforcer/11.0/installation/writeback.md +++ /dev/null @@ -1,19 +0,0 @@ ---- -title: "Enforce Password Reset with Azure Password Writeback" -description: "Enforce Password Reset with Azure Password Writeback" -sidebar_position: 100 ---- - -# Enforce Password Reset with Azure Password Writeback - -You can use Password Policy Enforcer to enforce password policies for passwords reset from Microsoft -Entra ID and O365 by enabling password writeback in Microsoft Entra ID. See the -[How does self-service password reset writeback work in Microsoft Entra ID?](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-writeback) -Microsoft knowledge base article for additional information on password writeback in Microsoft Entra -ID. Password writeback sends all new passwords from Microsoft Entra ID to an available, on-premises -domain controller to check with Password Policy Enforcer. This happens while the user is resetting -their password. See the -[Tutorial: Enable Microsoft Entra self-service password reset writeback to an on-premises environment](https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr-writeback) -and -[How it works: Microsoft Entra self-service password reset](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks#how-it-works-microsoft-entra-self-service-password-reset) Microsoft -knowledge base articles for additional information on password writeback for Microsoft Entra ID. diff --git a/docs/passwordpolicyenforcer/11.0/web-overview/configuration.md b/docs/passwordpolicyenforcer/11.0/web-overview/configuration.md deleted file mode 100644 index cde43df8a2..0000000000 --- a/docs/passwordpolicyenforcer/11.0/web-overview/configuration.md +++ /dev/null @@ -1,85 +0,0 @@ ---- -title: "Configuration" -description: "Configuration" -sidebar_position: 40 ---- - -# Configuration - -Click **Start** >**[All] Programs** > **PPE Web Configuration Console** to open the Password Policy -Enforcer Web Configuration Console. - -## General Tab - -Use the General tab to maintain the list of managed domains, and to configure Password Policy -Enforcer integration. See the Password Policy Enforcer topic for additional information. - -![configuring_ppe_web](/images/passwordpolicyenforcer/11.0/web/configuring_ppe_web.webp) - -### Domain List - -When Password Policy Enforcer Web is first installed, the Domain List is empty and users must type -their domain name. You can configure Password Policy Enforcer Web to display a list of domains -instead of an empty text box. - -**Add Domain** - -Follow the following steps to add a domain to the list. - -**Step 1 –** Click the **Add...** button. - -**Step 2 –** Enter a NetBIOS (NT Compatible) or DNS domain name. - -**Step 3 –** Click **OK**, the click **Apply**. - -:::note -Put the most frequently used domain first in the list — it is the default. You -can rearrange the domains by dragging them to another position. You can also click **Sort** to sort -them alphabetically. -::: - - -**Remove Domain** - -Follow the following steps to remove a domain from the list. - -**Step 1 –** Select the domain name from the Domain List. - -**Step 2 –** Click **Remove**, then click **Yes** when asked to confirm. - -**Step 3 –** Click **Apply**. - -### Password Policy Enforcer - -Password Policy Enforcer is a configurable password filter that enforces granular password policies -with many advanced features. Password Policy Enforcer Web can integrate with Password Policy -Enforcer to help users choose a compliant password. - -![configuring_ppe_web_1](/images/passwordpolicyenforcer/11.0/web/configuring_ppe_web_1.webp) - -Password Policy Enforcer Web displays the Password Policy Enforcer password policy message when a -user is prompted for their new password, and the Password Policy Enforcer rejection message if the -new password doesn't comply with the password policy. Select the **Password Policy Enforcer -integration** checkbox if you have installed and configured Password Policy Enforcer on your domain -controllers. - -You can also set the Port, Timeout, and number of Retries for the Password Policy Protocol if the -defaults aren't suitable. - -:::note -A Password Policy Enforcer Web license doesn't include a Password Policy Enforcer -license. See [Netwrix Password Policy Enforcer](https://www.netwrix.com/password_policy_enforcer.html) for licensing information. -::: - - -## About Tab - -The **About** tab contains version and license key information. - -To install a new license key. - -**Step 1 –** Copy the entire license e-mail to the clipboard. - -**Step 2 –** Click **Get license from clipboard**. - -**Step 3 –** Click **Apply**. diff --git a/docs/passwordpolicyenforcer/11.0/web-overview/editing_html_templates.md b/docs/passwordpolicyenforcer/11.0/web-overview/editing_html_templates.md deleted file mode 100644 index 9735740a6b..0000000000 --- a/docs/passwordpolicyenforcer/11.0/web-overview/editing_html_templates.md +++ /dev/null @@ -1,212 +0,0 @@ ---- -title: "Edit HTML Templates" -description: "Edit HTML Templates" -sidebar_position: 60 ---- - -# Edit HTML Templates - -Password Policy Enforcer Web's user interface is built with customizable templates. Modify the user interface by editing the templates. - -### User Interface Files - -Password Policy Enforcer Web installs four .htm files for every language. Each filename starts with -a language code. The files for the US English language are: - -| Filename | Content | -| --------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -| en_default.htm | Static HTML for the Welcome page. See the [Launch Password Policy Enforcer Web](/docs/passwordpolicyenforcer/11.0/web-overview/using_web.md) topic for additional information. | -| en_ppeweb.htm | Template for the Password Change page. See the [Change Password](using_web.md#change-password) topic for additional information. | -| en_finished.htm | Template for the Finished page. | -| en_error.htm | Template for the Password Critical Error page. See the [Error Messages](using_web.md#error-messages) topic for additional information. | - -The other user interface files are language independent. Most of the formatting is in ppeweb.css, -and some additional CSS for Internet Explorer is in ppeweb_ie.css. The image files are in the images -folder. These files are installed into the `\Inetpub\wwwroot\ppeweb\` folder by default. - -:::note -Always backup the user interface files before and after editing them. Your changes may be -overwritten when Password Policy Enforcer Web is upgraded, and some changes could stop Password -Policy Enforcer Web from working correctly. Web browsers display pages differently, so test your -changes with several versions of the most popular browsers to ensure compatibility. -::: - - -The en_default.htm contains static HTML, but the other .htm files contain special comment tags that -are used to prepare the pages. Some of these comments define ranges. A range looks like this: - -`Some text or HTML` - -Password Policy Enforcer Web deletes ranges (and the text inside them) when they aren't needed. -Some ranges span only one word, while others span several lines. The other type of comment tag is -called a field. - -`` - -Fields are replaced by some other information. For example, this field is replaced with a -username. - -#### Resource Strings - -Templates end with a resource string section. - -`` - -Resource strings are mostly validation error messages, but they can contain any text Password Policy -Enforcer Web may need to build the page. See the [Error Messages](using_web.md#error-messages) topic -for additional information. Don't modify the identifiers on the left, only edit the text on the -right. Resource strings are always inside a range called RESOURCE_STRINGS. Password Policy Enforcer -Web deletes this range before sending the page to the user's web browser. - -:::warning -You may rebrand the Password Policy Enforcer Web user interface, but it is a violation -of the License Agreement to modify, remove, or obscure any copyright notice. -::: - - -## Examples - -This topic contains examples of common customizations. Use these examples to gain a better -understanding of Password Policy Enforcer Web's templates. You don't need to be an expert in HTML to -follow these examples, but a basic understanding of HTML will help. Work through them carefully, and -backup files before you edit them. The examples in this section are from the US English files, but -the format is the same for all languages. - -### Replacing the Netwrix Logo - -The Netwrix logo is shown in the top left corner of the Welcome page. The logo is installed into the -`\Inetpub\wwwroot\ppeweb\images\` folder by default, and it is called logo.gif. You can replace this -file with one containing your organization's logo. - -Your logo may appear distorted if it isn't the same size as the Netwrix logo. You can fix this by -opening en_default.htm in a text editor such as Notepad. Search for the following line, and replace the width (116) and height (69) with the dimensions of your logo in pixels. - -`` - -### Edit Page Instructions - -Instructions appear at the top of the Password Change page in the white section above the input -fields. You can edit these instructions by opening `en_ppeweb.htm` and searching for the text you -want to modify. - -Instructions are inside ranges called SECTION_A and SECTION_B. Each section contains the -instructions for a page in the template. Ensure you edit the instructions in the correct section, -or they may be displayed on the wrong page. - -`` - -`

Enter your username and domain, and then click Next to continue…` - -`` - -`` - -`

Enter your old and new passwords in the text boxes below.

` - -`` - -### Edit Validation Error Messages - -Validation error messages are shown in a yellow box below the page instructions. Validation errors -are normally caused by invalid user input. - -![using_ppe_web_1](/images/passwordpolicyenforcer/11.0/web/using_ppe_web_1.webp) - -Validation error messages are defined in en_ppeweb.htm. The error messages are in the resource -strings section near the end of the file. See the Resource Strings topic for additional information. - -| String | Error Message | -| ----------------------------- | ---------------------------------------- | -| @RES_EMPTY_FIELD_USERNAME | Enter your username in the Username box. | -| @RES_EMPTY_FIELD_DOMAIN | Enter your domain name in the Domain bo… | -| @RES_BAD_USERNAME_OR_PASSWORD | The username, domain, or old password i… | - -### Edit Critical Error Messages - -All the critical error messages are defined in `en_error.htm`. The error messages are in the -resource strings section near the end of the file. See the Resource Strings topic for additional -information. - -![using_ppe_web_2](/images/passwordpolicyenforcer/11.0/web/using_ppe_web_2.webp) - -You may see placeholders like %1 and %2 in some error messages. These are replaced with more -information about the error. You should keep these as they provide important information about the -error, but you can delete them if you don't want them. - -| String | Error Message | -| ----------------------- | ---------------------------------------------- | -| @RES_ACCESS_DENIED | You don't have permission to change your pas… | -| @RES_ACCOUNT_LOCKED_OUT | Your account is locked out. Try aga… | -| @RES_LICENSE_MISSING | License reminder. Your password wasn't chang… | - -If you want to display some text for all error messages, then insert your text above or below the -`

{/*ERROR*/}

` line. For example: - -```html -` -

{/*ERROR*/}

-` ` -

The help desk phone number is 555-555-5555.

-` -``` - -### Edit Finished Message - -The finished message is shown after users successfully change their password. This message is -defined in en_finished.htm. - -![editing_the_html_templates_1](/images/passwordpolicyenforcer/11.0/web/editing_the_html_templates_1.webp) - -`

Finished

` - -`

Your password has been changed. You can now logon with your new pass…` - -### Change Font Sizes and Colors - -`ppeweb.css` contains most of the user interface formatting information. Change font sizes and colors by editing this file. To reposition and resize items, you need some understanding of CSS. For example, this is the CSS for the validation error box: - -``` -.error { - -background-color: #ffffd6; - -border: 3px solid #ff8080; - -color: #333333; - -font: bold 1.3em/1.2em Arial, sans-serif; - -margin: 3px 0 0 4px; - -padding: 6px 22px 6px 8px; - -width: 499px; - -} -``` - -Edit these properties to change the appearance of the error box. You may need to clear your web -browser's cache to see the changes. - -:::note -Web browsers display pages differently, so test your changes with several versions of the -most popular browsers to ensure compatibility. -::: - - -### Replace URLs to the Welcome Page - -Password Policy Enforcer Web shows the Welcome page when users click OK or Cancel on the Password -Change, Error, and Finished pages. - -To display a different page when users click OK or Cancel, search for `en_default.htm` in -`en_ppeweb.htm`, `en_finished.htm`, and `en_error.htm` and replace `en_default.htm` with an -alternative URL. For example: - -`https://myserver/accounts/login.htm` diff --git a/docs/passwordpolicyenforcer/11.0/web-overview/using_web.md b/docs/passwordpolicyenforcer/11.0/web-overview/using_web.md deleted file mode 100644 index d4dc8c38d4..0000000000 --- a/docs/passwordpolicyenforcer/11.0/web-overview/using_web.md +++ /dev/null @@ -1,78 +0,0 @@ ---- -title: "Launch Password Policy Enforcer Web" -description: "Launch Password Policy Enforcer Web" -sidebar_position: 30 ---- - -# Launch Password Policy Enforcer Web - -The default URL for Password Policy Enforcer Web is: `http://[server]/ppeweb/` - -Where [server] is the name or IP address of the server hosting Password Policy Enforcer Web. - -![Web Welcome page](/images/passwordpolicyenforcer/11.0/web/webwelcome.webp) - -The default page is called the Welcome page. You can customize the information on this page by -editing **en_default.htm**, or you can bypass this page and send users directly to the Password -Change page: - -`http://[server]/ppeweb/ppeweb.dll` - -You can also include the username and/or domain in the URL: - -`http://[server]/ppeweb/ppeweb.dll?username=maryjones&domain=ANIXIS` - -:::info -Install the SSL Certificate the web server and use the HTTPS protocol if Password -Policy Enforcer Web is used on an unencrypted network. See the -[Install an SSL Certificate](/docs/passwordpolicyenforcer/11.0/web-overview/securing_web.md) topic for additional -information. -::: - - -:::note -A license reminder message is shown occasionally when Password Policy Enforcer Web is used -without a license key. Contact Netwrix support if you would like to evaluate Password Policy -Enforcer Web without the reminder message. -::: - - -## Change Password - -To change a password with Password Policy Enforcer Web: - -**Step 1 –** Click **Change Password** on the Welcome page. - -![using_ppe_web](/images/passwordpolicyenforcer/11.0/web/using_ppe_web.webp) - -**Step 2 –** Enter a **Username** and **Domain**, then click **Next**. - -![introduction_4](/images/passwordpolicyenforcer/11.0/web/introduction_4.webp) - -**Step 3 –** Enter the **Old Password**, **New Password**, and **Confirm Password**, then click -**Next**. - -:::note -Windows increments the bad password count in Active Directory every time a user enters -their old password incorrectly. This may trigger a lockout if the Windows account lockout policy is -enabled. -::: - - -## Error Messages - -Validation errors are shown in a yellow box below the page instructions. Validation errors are -normally caused by invalid user input. They can often be overcome by changing the value of one or -more input fields and resubmitting the form. - -![using_ppe_web_1](/images/passwordpolicyenforcer/11.0/web/using_ppe_web_1.webp) - -Critical errors are shown on their own page. These errors are mostly a result of configuration or -system errors. Users can sometimes overcome a critical error by following the instructions in the -error message, but most critical errors are beyond the user's control. - -![using_ppe_web_2](/images/passwordpolicyenforcer/11.0/web/using_ppe_web_2.webp) - -Validation and critical error messages are stored in the HTML templates. You can modify the default -messages by editing the templates. See the [Edit HTML Templates](/docs/passwordpolicyenforcer/11.0/web-overview/editing_html_templates.md) topic -for additional information. diff --git a/docs/passwordpolicyenforcer/11.0/web-overview/web_overview.md b/docs/passwordpolicyenforcer/11.0/web-overview/web_overview.md deleted file mode 100644 index 2670f9e31e..0000000000 --- a/docs/passwordpolicyenforcer/11.0/web-overview/web_overview.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -title: "Password Policy Enforcer Web" -description: "Password Policy Enforcer Web" -sidebar_position: 60 ---- - -# Password Policy Enforcer Web - -Password Policy Enforcer Web lets users change their Windows domain password from a web browser. It can optionally integrate with Password Policy Enforcer to enforce customizable password -policies and help users set compliant passwords. - -Download Password Policy Enforcer Web: - -[Password_Policy_Enforcer_WEB_7.11.zip](https://www.netwrix.com/download/commercial/Password_Policy_Enforcer_WEB_7.11.zip) - -![introduction_4](/images/passwordpolicyenforcer/11.0/web/introduction_4.webp) - -Password Policy Enforcer Web communicates directly with the domain controllers, so it works best -when both the web server and domain controllers are on the same network. If you need to put the web -server in a DMZ for extra security, then consider using Netwrix Password Reset instead of Password -Policy Enforcer Web. - -Password Reset also lets users change their password from a web browser, but it has many other -features including the ability to work in a DMZ without any domain controllers. Use Password Reset -if you need to: - -- Users can reset a forgotten password or unlock their account by answering questions about - themselves, such as their date of birth, first pet's name, etc. Users can access APR from the web - browser, or from the Windows Logon and Unlock screens if the APR Client is installed. -- Send e-mail alerts to users whenever their account is used in the password management system. -- Keep a detailed, searchable audit log of all user activity. -- Separate the web server from he internal network for extra security. - -See the [Netwrix Help Center](https://helpcenter.netwrix.com/) page for documentation on the -Password Reset product. diff --git a/docs/passwordpolicyenforcer/11.1/admin/_category_.json b/docs/passwordpolicyenforcer/11.1/admin/_category_.json deleted file mode 100644 index 5874d2dc57..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Administration", - "position": 40, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "administration_overview" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.1/admin/administration_overview.md b/docs/passwordpolicyenforcer/11.1/admin/administration_overview.md deleted file mode 100644 index 39c495ce52..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/administration_overview.md +++ /dev/null @@ -1,28 +0,0 @@ ---- -title: "Administration" -description: "Administration" -sidebar_position: 40 ---- - -# Administration - -Netwrix Password Policy Enforcer helps secure your network by ensuring users set strong passwords. -When a user enters a password that doesn't comply with the password policy, Password Policy -Enforcer immediately rejects the password and details why the password was rejected. - -![introduction_2](/images/passwordpolicyenforcer/11.1/evaluation/introduction_3.webp) - -Unlike password cracking products that check passwords after they are accepted by the operating -system, Password Policy Enforcer checks new passwords immediately to ensure that weak passwords do -not jeopardize network security. - -You can also use Password Policy Enforcer to ensure that passwords are compatible with other -systems, and to synchronize passwords with other networks and applications. - -:::note -The [Evaluate Password Policy Enforcer](/docs/passwordpolicyenforcer/11.1/evaluation/evaluation_overview.md) contains -step-by-step instructions to help you quickly install, configure, and evaluate Password Policy -Enforcer. Consider using the Evaluation Guide if you are using Password Policy Enforcer for the -first time, before installing and deploying on your domains. - -::: diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/_category_.json b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/_category_.json deleted file mode 100644 index 56191c74b1..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "PPE cmdlets", - "position": 60, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "cmdlets" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdconnectppe.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdconnectppe.md deleted file mode 100644 index 47d9859094..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdconnectppe.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -title: "Connect-PPE" -description: "Connect-PPE" -sidebar_position: 10 ---- - -# Connect-PPE - -The **Connect-PPE** cmdlet establishes a connection to the PPE Server. - -**SYNTAX** - -**Connect-PPE** [[__-Local__] `<_SwitchParameter_>`] [[__-Domain__] `<_string_>`] -[`<_CommonParameters_>`] - -**PARAMETERS** - -**-Domain** `<_string_>` - -Name of the domain controller to connect. Can also use **-D** or **-d**. - -**-Local** `<_SwitchParameter_>` - -Connect to PPE Server installed locally. Can also use **-L** or **-l**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5) -[about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Connect-PPE -d "DCNAME1.COMPANY.COM" - -Connection to PPE was established. Connection to Domain "DCNAME1.COMPANY.COM" diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdcopyppepolicy.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdcopyppepolicy.md deleted file mode 100644 index 23f1ad5d9c..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdcopyppepolicy.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Copy-PPEPolicy" -description: "Copy-PPEPolicy" -sidebar_position: 20 ---- - -# Copy-PPEPolicy - -The **CopyPPEPolicy** cmdlet makes a copy of a PPE policy. - -**SYNTAX** - -**Copy-PPEPolicy -DestPolicyName** `<_string_>` **-SrcPolicyName** `<_string_>` -[`<_CommonParameters_>`] - -**PARAMETERS** - -**-SrcPolicyName** `<_string_>` - -Source PPE Policy Name. Can also use **-S** or **-s**. - -**-DestPolicyName** `<_string_>` - -Destination PPE Policy Name. Can also use **-D** or **-d**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Copy-PPEPolicy -s "Eval Policy" -d "User Policy" - -The "User Policy" policy was created based on the "Eval Policy". diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdexportppeconfig.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdexportppeconfig.md deleted file mode 100644 index 8c7c2996b1..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdexportppeconfig.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: "Export-PPEConfig" -description: "Export-PPEConfig" -sidebar_position: 30 ---- - -# Export-PPEConfig - -The **Export-PPEConfig** cmdlet exports the Password Policy Enforcer configuration to a file. - -**SYNTAX** - -**Export-PPEConfig** [__-File__ `<_string_>`] [`<_CommonParameters_>`] - -**PARAMETERS** - -**-File** `<_string_>` - -Name of the file to create. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Export-PPEConfig -file c:\ppe\ppe_config - -Configuration export has been successfully completed. The file "c:\ppe\ppe_config" has been created. diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdexportppepolicy.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdexportppepolicy.md deleted file mode 100644 index 0b747fc05a..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdexportppepolicy.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "Export-PPEPolicy" -description: "Export-PPEPolicy" -sidebar_position: 40 ---- - -# Export-PPEPolicy - -The **Export-PPEPolicy** exports a Password Policy Enforcer policy to a file. - -:::note -This cmdlet calls the **PPE Tool**. You must be an administrator to run this cmdlet. Start -PowerShell with the **Run as Administrator** option. -::: - - -**SYNTAX** - -**Export-PPEPolicy** -PolicyName `<_string_>` [__-File__ `<_string_>`] [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PolicyName** `<_string_>` - -Name of the to export. - -**-File** `<_string_>` - -Name of the file to create. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Export-PPEPolicy -PolicyName "Eval Policy" -File C:\ppe\EvalPolicy - -Configuration export has been successfully completed. The file "C:\ppe\EvalPolicy" has been created. diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppebulkpasswordtest.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppebulkpasswordtest.md deleted file mode 100644 index fb102534ab..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppebulkpasswordtest.md +++ /dev/null @@ -1,47 +0,0 @@ ---- -title: "Get-PPEBulkPasswordTest" -description: "Get-PPEBulkPasswordTest" -sidebar_position: 50 ---- - -# Get-PPEBulkPasswordTest - -The **Get-PPEBulkPasswordTest** cmdlet runs the Password Policy Enforcer bulk password test of the -specified policy. - -**SYNTAX** - -**Get-PPEBulkPasswordTest** **-PasswordFile** `<_string_>` **-Policy** `<_string_>` -**-ResultFolder** `<_string_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PasswordFile** `<_string_>` - -Path and name of the text file containing the passwords to test. Passwords in your test file are 1 -per line. - -**-Policy** `<_string_>` - -The name of the policy to enforce for the test. - -**-ResultFolder** `<_string_>` - -The folder for the created html report. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEBulkPasswordTest -PasswordFile C:\PPE\password.txt -Policy "Eval Policy" --resultFolder C:\PPE - -Bulk test is running... - -The report is created: "C:\PPE\password.txt_Result_2209222024122350.html". - -![Results of the Get-PPEBulkPasswordTest cmdlet](/images/passwordpolicyenforcer/11.1/administration/cmdletgetppebulkpasswordtest.webp) diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeconfigreport.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeconfigreport.md deleted file mode 100644 index ca71b0cb98..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeconfigreport.md +++ /dev/null @@ -1,39 +0,0 @@ ---- -title: "Get-PPEConfigReport" -description: "Get-PPEConfigReport" -sidebar_position: 60 ---- - -# Get-PPEConfigReport - -The **Get-PPEConfigReport** cmdlet saves a Password Policy Enforcer configuration report. - -:::note -This cmdlet calls the PPE Tool. You must be an administrator to run this cmdlet. Start -PowerShell with the **Run as Administrator** option. -::: - - -**SYNTAX** - -**Get-PPEConfigReport** **-Folder** `<_string_>` - -**PARAMETERS** - -**-Folder** `<_string_>` - -Name of the folder to save the report. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEConfigReport -Folder C:\PPE - -The report is created: "C:\PPE\report.html". - -![Creates the PPE Configuration report](/images/passwordpolicyenforcer/11.1/administration/cmdletgetppeconfigreport.webp) diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppedefaultpolicy.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppedefaultpolicy.md deleted file mode 100644 index 4ca6cd8998..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppedefaultpolicy.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: "Get-PPEDefaultPolicy" -description: "Get-PPEDefaultPolicy" -sidebar_position: 70 ---- - -# Get-PPEDefaultPolicy - -The **Get-PPEDefaultPolicy** cmdlet reports the name of the Password Policy Enforcer default Policy. - -**SYNTAX** - -**Get-PPEDefaultPolicy** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEDefaultPolicy - -**Default policy : Eval Policy** diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeenabled.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeenabled.md deleted file mode 100644 index 42a8cc2dbc..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeenabled.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: "Get-PPEEnabled" -description: "Get-PPEEnabled" -sidebar_position: 80 ---- - -# Get-PPEEnabled - -The **Get-PPEEnabled** cmdlet returns the enabled/disabled status of the PPE Server. - -**SYNTAX** - -**Get-PPEEnabled** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEEnabled - -**Status PPE : Enabled** diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppehelp.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppehelp.md deleted file mode 100644 index 1fde1f675f..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppehelp.md +++ /dev/null @@ -1,60 +0,0 @@ ---- -title: "Get-PPEHelp" -description: "Get-PPEHelp" -sidebar_position: 90 ---- - -# Get-PPEHelp - -The **Get-PPEHelp** cmdlet lists the available Password Policy Enforcer cmdlets. If a cmdlet is -specified, returns help for the cmdlet. - -**SYNTAX** - -**Get-PPEHelp** [[__-Cmdlet__] `<_string_>`] - -**PARAMETERS** - -**-Cmdlet** `<_string_>` - -Name of the cmdlet for help. Can also use **-C** or **-c**. - -`` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> get-ppehelp get-ppehelp - -**NAME** - -Get-PPEHelp - -**SYNOPSIS** - -Get a list of the PPE Cmdlet - -**SYNTAX** - -Get-PPEHelp [[-Cmdlet] ``] `[]` - -**DESCRIPTION** - -Get a list of the PPE Cmdlet - -**RELATED LINKS** - -https://www.netwrix.com/password_policy_enforcer.html - -**REMARKS** - -To see the examples, type: "get-help Get-PPEHelp -examples". - -For detailed information, type: "get-help Get-PPEHelp -detailed". - -For technical information, type: "get-help Get-PPEHelp -full". - -**For online help, type: "get-help Get-PPEHelp -online"** diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppelicenseinfo.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppelicenseinfo.md deleted file mode 100644 index 180bc324d0..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppelicenseinfo.md +++ /dev/null @@ -1,63 +0,0 @@ ---- -title: "Get-PPELicenseInfo" -description: "Get-PPELicenseInfo" -sidebar_position: 100 ---- - -# Get-PPELicenseInfo - -The **Get-PPELicenseInfo** cmdlet returns the Password Policy Enforcer license information. - -**SYNTAX** - -**Get-PPELicenseInfo** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -``` -PS C:\> Get-PPELicenseInfo - -**ANIXIS Software License Certificate** - -Product: Password Policy Enforcer - -**License type: Perpetual** - -Licensed to: test - -**Version: 11** - -Users: 100 - -**JrPQdyhsxWrLj7RsuX322Ni8vwIRr6ozC+sY3M16aJba** - -XuRXG6VjOjWUMT1XwqO4c3VA0eIB8+z4KyUNEzLjmSZKvtLsHb0kFYi1zRiL - -**6EBVflEmzxYIsCvAlsg1fNfK1JgjFefOc1gENy2CBikDTbe+HnHf3aVBq6p2** - -Va1eXmMXToi3NDNJCNFzQHy7ZGC5AhQ8GIjQfgK8z9s1sHzpdj2Gn+9BEyQQ - -**nv833QdoFhjKoAXN/xCecZclkCkP9f1GLuq4kN0Emsh5qqXl686JBJlisA3o** - -XWQrEQ0Me9P3TkSUpb742JCngQaGcjKHvQoufBJ+GIrcwWG2DZJ1i9xrOJMT - -**g8D5eFDz/OiqXuZyBHFTInbq77V59x/xtIlUffBW7sCUmY8B+ZhLR2XpLdxr** - -S+4E37Lhf46bScltZxfHZbDQKZuT4hdMKnnzgNHEzkMh8Q3T/40sMvQbAV4O - -**tDF633YsQMH3Ttbyc+vAvIvbAHJOVhBpNd9TCybfas+j6uQL5fa4qo8dFrx+** - -+UrPakOmSL/eDR7xB5/zmB37shDXIPfzfG/Vu7I1/EQuH01rZDyafHnzTmmm - -**1hCMqyi+oVzxZtN8I3sIpAH3FLu+1N37CuHJFrXD97Iu6RjKi+11nG9BmZ2Q** - -0SX5EYc= -``` diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepasswordtest.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepasswordtest.md deleted file mode 100644 index 621da3b866..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepasswordtest.md +++ /dev/null @@ -1,72 +0,0 @@ ---- -title: "Get-PPEPasswordTest" -description: "Get-PPEPasswordTest" -sidebar_position: 110 ---- - -# Get-PPEPasswordTest - -The **Get-PPEPasswordTest** cmdlet runs the Password Policy Enforcer password test for a user. - -**SYNTAX** - -**Get-PPEPasswordTest** **-Password** `<_string_>` **-Username** `<_string_>` [__-OldPassword__ -`<_string_>`] [`<_CommonParameters_>`] - -**PARAMETERS** - -**-Password** `<_string_>` - -The password to test. - -**-User** `<_string_>` - -The username to test. Can also use **-U** or **-u**. - -**-OldPassword** `<_string_>` - -The old password to test. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEPasswordTest -Password qwerty -User PPETestUser - -**Assigning default policy "Eval Policy"** - -Log - -- Info : Reading configuration from NT-DC03.nwxtech.com. - -- Info : DN is "CN=PPE Test User,CN=Users,DC=NWXTECH,DC=COM" - -- Info : Current password is 5 days old. - -- Info : Extended Maximum Age group not found. - -- Info : Dictionary rule found "QWERTY". - -- Info : Password rejected. - -Password must: - -- Accepted : contain a lower alpha character - -- Rejected : contain an upper alpha character - -- Accepted : contain at least 1 of these character types: - -- upper alpha - -- lower alpha - -- Rejected : not be similar to a common password - -- Rejected : contain at least 7 characters - -- Accepted : not be similar to your logon name diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepolicies.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepolicies.md deleted file mode 100644 index b900e6a131..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepolicies.md +++ /dev/null @@ -1,33 +0,0 @@ ---- -title: "Get-PPEPolicies" -description: "Get-PPEPolicies" -sidebar_position: 120 ---- - -# Get-PPEPolicies - -The **Get-PPEPolicies** cmdlet returns the Password Policy Enforcer policies. - -**SYNTAX** - -**Get-PPEPolicies** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEPolicies - -**Admins Policy** - -Eval Policy - -**Test** - -User Policy diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepolicyenabled.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepolicyenabled.md deleted file mode 100644 index a90cb7246f..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepolicyenabled.md +++ /dev/null @@ -1,32 +0,0 @@ ---- -title: "Get-PPEPolicyEnabled" -description: "Get-PPEPolicyEnabled" -sidebar_position: 130 ---- - -# Get-PPEPolicyEnabled - -The **Get-PPEPolicyEnabled** cmdlet returns the enabled/disabled status of a Password Policy -Enforcer policy. - -**SYNTAX** - -**Get-PPEPolicyEnabled** **-PolicyName** `<_string_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PolicyName** `<_string_>` - -Name of the policy. Can also use **-P** or **-p**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEPolicyEnabled -PolicyName "Eval Policy" - -**Policy "Eval Policy" is Enabled** diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdimportppeconfig.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdimportppeconfig.md deleted file mode 100644 index e502ee0fe9..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdimportppeconfig.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -title: "Import-PPEConfig" -description: "Import-PPEConfig" -sidebar_position: 160 ---- - -# Import-PPEConfig - -The **Import-PPEConfig** cmdlet imports a Password Policy Enforcer configuration file. - -:::note -This cmdlet calls the **PPE Tool**. You must be an administrator to run this cmdlet. Start -PowerShell with the **Run as Administrator** option. -::: - - -**SYNTAX** - -**Import-PPEConfig** **-File**] `<_string_>` `<_CommonParameters_>`] - -**PARAMETERS** - -**-File** `<_string_>` - -Name of the configuration file. Can also use **-F** or **-f**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See -[about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Import-PPEConfig -File C:\PPE\ppe_config - -Config import successful. diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdimportppepolicy.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdimportppepolicy.md deleted file mode 100644 index cc1b8b5b5f..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdimportppepolicy.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -title: "Import-PPEPolicy" -description: "Import-PPEPolicy" -sidebar_position: 170 ---- - -# Import-PPEPolicy - -The **Import-PPEPolicy** cmdlet imports a Password Policy Enforcer policy from a file. - -:::note -This cmdlet calls the **PPE Tool**. You must be an administrator to run this cmdlet. Start -PowerShell with the **Run as Administrator** option. -::: - - -**SYNTAX** - -**Import-PPEPolicy** **-File**] `<_string_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-File** `<_string_>` - -Name of the policy file. Can also use **-F** or **-f**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Import-PPEPolicy -File "C:\PPE\EvalPolicy" - -Config import successful. diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdlets.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdlets.md deleted file mode 100644 index 56edf0134b..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdlets.md +++ /dev/null @@ -1,56 +0,0 @@ ---- -title: "PPE cmdlets" -description: "PPE cmdlets" -sidebar_position: 60 ---- - -# PPE cmdlets - -Cmdlets are available to manage Password Policy Enforcer from a Windows PowerShell. The -cmdlets aren't case-sensitive. - -Starting with version **11.1**, the PowerShell cmdlets use .NET 8.0 and require PowerShell version 7.4 or later to function. -**Installation link**: [https://learn.microsoft.com/en-us/powershell/scripting/install/installing-powershell-on-windows?view=powershell-7.5](https://learn.microsoft.com/en-us/powershell/scripting/install/installing-powershell-on-windows?view=powershell-7.5) - -To establish the connection: - -**Step 1 –** Open a Windows PowerShell. Some cmdlets require administrative permissions. You can use -the **Run as Administrator** option. - -**Step 2 –** Import the PPE cmdlets module: -**Import-Module "$env:ProgramFiles\Netwrix\Password Policy Enforcer\PS\PPEConf.PowerShell.dll"** - -**Step 3 –** Connect to your domain: -**Connect-PPE -d "_domain_"** where _domain_ is the full name of your domain controller. -**NT-DC03.NWXTECH.COM** in this example. - -**Get-PPEHelp** with no parameters, displays a list of available cmdlets. Use the PowerShell -**get-help** _Cmdlet_ for information about the cmdlet. - -![PPE cmdlets Connect](/images/passwordpolicyenforcer/11.1/administration/cmdletconnect.webp) - -Click a PPE cmdlet name for details. - -- [Connect-PPE](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdconnectppe.md) -- [Copy-PPEPolicy](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdcopyppepolicy.md) -- [Export-PPEConfig](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdexportppeconfig.md) -- [Export-PPEPolicy](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdexportppepolicy.md) -- [Get-PPEBulkPasswordTest](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppebulkpasswordtest.md) -- [Get-PPEConfigReport](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeconfigreport.md) -- [Get-PPEDefaultPolicy](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppedefaultpolicy.md) -- [Get-PPEEnabled](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeenabled.md) -- [Get-PPEHelp](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppehelp.md) -- [Get-PPELicenseInfo](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppelicenseinfo.md) -- [Get-PPEPasswordTest](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepasswordtest.md) -- [Get-PPEPolicies](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepolicies.md) -- [Get-PPEPolicyEnabled](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppepolicyenabled.md) -- [Get-PPEServerVersion](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeserverversion.md) -- [Get-PPEVersion](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeversion.md) -- [Import-PPEConfig](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdimportppeconfig.md) -- [Import-PPEPolicy](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdimportppepolicy.md) -- [Remove-PPEPolicy](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdremoveppepolicy.md) -- [Set-PPEDefaultPolicy](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppedefaultpolicy.md) -- [Set-PPEEnabled](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppeenabled.md) -- [Set-PPEPolicyEnabled](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppepolicyenabled.md) -- [Start-PPECompromisedPasswordChecker](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md) -- [Start-PPEHibpUpdater](/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdstartppehibpupdater.md) diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdremoveppepolicy.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdremoveppepolicy.md deleted file mode 100644 index a3cceb3344..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdremoveppepolicy.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: "Remove-PPEPolicy" -description: "Remove-PPEPolicy" -sidebar_position: 180 ---- - -# Remove-PPEPolicy - -The **Remove-PPEPolicy** cmdlet removes a Password Policy Enforcer policy. - -**SYNTAX** - -**Remove-PPEPolicy** **-PolicyName**] `<_string_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PolicyName** `<_string_>` - -Name of the policy. Can also use **-P** or **-p**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Remove-PPEPolicy -PolicyName Test - -**PS C:\>** diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppedefaultpolicy.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppedefaultpolicy.md deleted file mode 100644 index e3c39399cf..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppedefaultpolicy.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: "Set-PPEDefaultPolicy" -description: "Set-PPEDefaultPolicy" -sidebar_position: 190 ---- - -# Set-PPEDefaultPolicy - -The **Set-PPEDefaultPolicy** cmdlet sets the Password Policy Enforcer policy as the default. - -**SYNTAX** - -**Set-PPEDefaultPolicy** **-PolicyName**] `<_string_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PolicyName** `<_string_>` - -Name of the policy. Can also use **-P** or **-p**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Set-PPEDefaultPolicy -PolicyName "Eval Policy" - -**Default policy : Eval Policy** diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppeenabled.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppeenabled.md deleted file mode 100644 index 515242af8b..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppeenabled.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Set-PPEEnabled" -description: "Set-PPEEnabled" -sidebar_position: 200 ---- - -# Set-PPEEnabled - -The **Set-PPEEnabled** cmdlet sets the enabled/disabled status for the PPE Server. - -**SYNTAX** - -**Set-PPEEnabled** **-Enable**] `<_int_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-Enable** `<_int_>` - -Specify **1** to enable the PPE Server, specify **0** to disable the PPE Server. Can also use **-E** -or **-e**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLES** - -PS C:\> Set-PPEEnabled -Enable 0 - -**Status PPE : Disabled** - -PS C:\> Set-PPEEnabled -Enable 1 - -**Status PPE : Enabled** diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppepolicyenabled.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppepolicyenabled.md deleted file mode 100644 index 72605efcf3..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdsetppepolicyenabled.md +++ /dev/null @@ -1,42 +0,0 @@ ---- -title: "Set-PPEPolicyEnabled" -description: "Set-PPEPolicyEnabled" -sidebar_position: 210 ---- - -# Set-PPEPolicyEnabled - -The **Set-PPEPolicyEnabled** cmdlet sets the enabled/disabled status for a Password Policy Enforcer -policy. - -**SYNTAX** - -**Set-PPEPolicyEnabled\_\_**-PolicyName** `<_string_>` **-Enable\__] -`<\_int_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PolicyName** `<_string_>` - -The policy name. - -**-Enable** `<_int_>` - -Specify **1** to enable the policy, specify **0** to dis -Poliable the policy. Can also use **-E** -or **-e**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLES** - -PS C:\> Set-PPEPolicyEnabled -PolicyName "Eval Policy" -Enable 0 - -**Policy "Eval Policy" is Disabled** - -PS C:\> Set-PPEPolicyEnabled -PolicyName "Eval Policy" -Enable 1 - -**Policy "Eval Policy" is Enabled** diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md b/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md deleted file mode 100644 index 7cf47bdc8f..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md +++ /dev/null @@ -1,28 +0,0 @@ ---- -title: "Start-PPECompromisedPasswordChecker" -description: "Start-PPECompromisedPasswordChecker" -sidebar_position: 220 ---- - -# Start-PPECompromisedPasswordChecker - -The **Start-PPECompromisedPasswordChecker** cmdlet runs the Password Policy Enforcer Compromised -Password Checker. - -**SYNTAX** - -**Start-PPECompromisedPasswordChecker** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Start-PPECompromisedPasswordChecker - -**PS C:\>** diff --git a/docs/passwordpolicyenforcer/11.1/admin/command_line_interface.md b/docs/passwordpolicyenforcer/11.1/admin/command_line_interface.md deleted file mode 100644 index 685f1f1c87..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/command_line_interface.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "Command Line Interface" -description: "Command Line Interface" -sidebar_position: 70 ---- - -# Command Line Interface - -## Silent Installation - -Replace _version_ with the complete version and build number of the **msi** file. For example, -11.1.0.74. - -Install only PPE Server: msiexec /i Netwrix_PPE_Server_**version**_x64.msi ADDLOCAL=FeatureServerPPE -/q - -Install only Console: msiexec /i Netwrix_PPE_Server_**version**_x64.msi ADDLOCAL=FeatureConsole /q - -Install only Mailer Server: msiexec /i Netwrix_PPE_Server_**version**_x64.msi -ADDLOCAL=FeaturePPEMailerServer /q - -Install all 3 components: - -msiexec /i Netwrix_PPE_Server_**version**_x64.msi -ADDLOCAL=FeaturePPEMailerServer,FeatureConsole,FeatureServerPPE /q - -By default Console only installed: msiexec /i Netwrix_PPE_Server_**version**_x64.msi /q - -Uninstall all: msiexec /uninstall Netwrix_PPE_Server_**version**_x64.msi /q - -Uninstall only particular feature: msiexec /i _path_to_your_msi_file.msi_ REMOVE=_FeatureName_ /qn - -If a reboot wasn't done, add **/forcerestart** at the end - -## Mailer - -You can run the Password Policy Enforcer Mailer from the command line to deliver email immediately, -or to troubleshoot problems. PPEMail.exe is copied into the \Program Files\Netwrix\Password Policy -Enforcer\ folder when the Password Policy Enforcer Mailer is installed. - -PPEMail.exe starts a simulation when run without any parameters. It finds users whose password will -expire soon, but no email is sent or saved to the pickup folder. Use the simulation mode to find -common configuration errors that may stop the Password Policy Enforcer Mailer from delivering email. - -Running PPEMail.exe with the /send parameter disables simulation mode. Any emails that are due to be -sent today are sent immediately. PPEMail.exe can identify a wider range of configuration errors when -run in this mode. Use the /send parameter judiciously to avoid sending duplicate emails to users. - -To test email delivery options without sending any emails to users, run PPEMail.exe with the /test -parameter followed by your email address. For example, PPEMail.exe /test johnsmith@netwrix.com. This -sends one test email to your mail server or pickup folder. diff --git a/docs/passwordpolicyenforcer/11.1/admin/compromisedpasswordcheck.md b/docs/passwordpolicyenforcer/11.1/admin/compromisedpasswordcheck.md deleted file mode 100644 index 78711443af..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/compromisedpasswordcheck.md +++ /dev/null @@ -1,98 +0,0 @@ ---- -title: "Compromised Password Check" -description: "Compromised Password Check" -sidebar_position: 30 ---- - -# Compromised Password Check - -The Compromised Password Checker identifies weak or unsafe passwords, including compromised, reused, -or empty ones. Users can be notified via email and advised or forced to change their password. -The check can be scheduled to run at any time to verify existing passwords against security rules. - -:::note -Create the **Compromised Passwords Base** file before enabling the Compromised Password -Check. See the [HIBP Updater](/docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md) topic for instructions. -::: - - -The Compromised Password Checker is launched from the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -Click the **Compromised Passwords** tile on the Configuration Console dashboard. This feature is -only available when **domain** is selected with the [Connected To](configconsole.md#connected-to) -configuration setting. The Compromised Password Check is disabled by default, and the schedule is -set to **None**. - -Click the **Compromised Password Check** toggle to enable/disable the feature. - -![Compromised Password Check](/images/passwordpolicyenforcer/11.1/administration/compromisedpasswords.webp) - -- **Compromised Passwords Base** specify the database to use when checking for compromised - passwords. Netwrix recommends using the [HIBP Updater](/docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md) to create this database. - Click **Browse** to navigate to the folder. Default is **C:\HIBP\DB** -- **Domain Controller (FQDN)** specify the fully qualified domain controller name where you want to - run the password check. Click **Browse** and select from the list. -- **Log events in Windows Application Event Viewer** select this option if you want to log events. -- **Force users to change password** select this option to force users to change compromised - passwords. -- **Report password reuse by another account** select this option to generate password reuse report. -- **Force users to change password** select this option to force users to change reused - passwords. -- **Recipient of the full report on the found compromised passwords** specify the email address of - the administrator who should receive the full report. -- **From** specify the email sender. -- **Notify users whose passwords are compromised by email** select this option to send email - notification to users their password appears in the compromised list. -- **Set up email** click to set up the email message for users. Enter the **From** address and edit - the subject and body template as needed. Click **Apply** to save changes. - - ![Email user notification of compromised password](/images/passwordpolicyenforcer/11.1/administration/emailusernotification.webp) - -Click **Save** to save your settings before running the check or setting up a schedule. - -Click **Run now** to run the check. Depending on your network, the check can take quite a while to -complete. You can schedule it for off hours instead of running it now. - -Here is an example of the compromised passwords report: - ---- -**List of compromised passwords** -|User | Account | Sid | Email | Description | -| --- | --- | --- | --- | --- | -| admin | Administrator | S-1-5-21-1006207104-1546379664-2458629591-500 | | Sending emails isn't possible due to the lack of an email address in the account. | -| user2 | user2 | S-1-5-21-1006207104-1546379664-2458629591-1118 | user2@company.com | Email has been sent | - - -**List of reused passwords** -|User | Account | Sid | Email | Description | -| --- | --- | --- | --- | --- | -| admin | Administrator | S-1-5-21-1006207104-1546379664-2458629591-500 | | Sending emails isn't possible due to the lack of an email address in the account. | -| user2 | user2 | S-1-5-21-1006207104-1546379664-2458629591-1118 | user2@company.com | Email has been sent | - -**Users with empty password:** -Guest (S-1-5-21-1006207104-1546379664-2458629591-501) - ---- - -#### Schedule the Compromised Password Check - -Click **Schedule** to set up a schedule to run the Compromised Password Check. - -![Schedule the Compromised Password Policy Check](/images/passwordpolicyenforcer/11.1/administration/compromisedpasswordsschedule.webp) - -Select the **Frequency**: - -- None: no scheduled runs. -- Run now: run the check now. No scheduled runs. -- Once: set the **Start date** and **Start time** to run the check a single time. -- Daily: set the **Start date** and **Start time** to run the check daily. -- Weekly: set the **Start date**, **Start time** and select the day of the week to run the check - weekly. -- Monthly: set the **Start date**, **Start time** and select the day of the month to run the check - monthly. - -Click **Apply**. diff --git a/docs/passwordpolicyenforcer/11.1/admin/configconsole.md b/docs/passwordpolicyenforcer/11.1/admin/configconsole.md deleted file mode 100644 index 3ec47fa2da..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/configconsole.md +++ /dev/null @@ -1,290 +0,0 @@ ---- -title: "Configuration Console" -description: "Configuration Console" -sidebar_position: 10 ---- - -# Configuration Console - -The PPE Configuration Console manages Password Policy Enforcer across your domain. It can be -installed on multiple servers/workstations as convenient. - -Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -![Configuration Console Dashboard](/images/passwordpolicyenforcer/11.1/evaluation/ppedashboard.webp) - -## Dashboard Controls - -The Configuration Console dashboard has all the tools you need to set up and manage Password Policy -Enforcer. - -- Enable/Disable Password Policy Enforcer -- Connected To -- Help -- Settings - General, Notifications, License - -In addition, there are tiles to access Password Policy Enforcer major features: - -- [Manage Policies](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/manage_policies.md) -- [Compromised Password Check](/docs/passwordpolicyenforcer/11.1/admin/compromisedpasswordcheck.md) -- [System Audit and Support](/docs/passwordpolicyenforcer/11.1/admin/systemaudit.md) - Version Tracker, Support Tools, Property Editor - -See the specific topics for details. - -### Enable/Disable Password Policy Enforcer - -The toggle enables/disables Password Policy Enforcer on all domain controllers. It is enabled by -default. - -![Enable/Disable PPE](/images/passwordpolicyenforcer/11.1/administration/enabledisableppeconsole.webp) - -Click the toggle to disable PPE: - -![Disable PPE](/images/passwordpolicyenforcer/11.1/administration/disable.webp) - -If PPE  is disabled, click the toggle to enable: - -![Enable PPE](/images/passwordpolicyenforcer/11.1/administration/disabled.webp) - -### Connected To - -Sets the configuration for **Domain** (default) or **Local**. Password Policy Enforcer's -configuration settings are stored in Active Directory or the registry. An Active Directory -configuration is called a domain configuration, and it defines the password policies for domain user -accounts. A registry configuration is called a local configuration, and it defines the password -policies for local user accounts. - -Domain configurations are stored in the **CN=Password Policy Enforcer** _version\*\*_,CN=System -object\*\*. - -Local configurations are stored in the **HKLM\SOFTWARE**ANIXIS**\Password Policy Enforcer** -_version\*\*_\ registry key\*\*. - -:::note -Users with write permission to these objects can configure Password Policy Enforcer. -::: - - -**Domain** - -- Defines policies for domain user accounts. -- Select a Domain Controller from the list of domain controllers where PPE is installed. -- Configuration is replicated to all the domain controllers in the domain. - -![Connect To Domain Configuration](/images/passwordpolicyenforcer/11.1/administration/connecttodomain.webp) - -**Local** - -- Defines policies for local user accounts. -- Only affects the computer where it is set. -- You can copy a local configuration to another computer by exporting the configuration from the - registry, and then importing it into the registry of the other computer. You can also use Group - Policy to distribute a local configuration to many computers. See the - [Domain and Local Policies](/docs/passwordpolicyenforcer/11.1/installation/domain_and_local_policies.md) topic for additional information. - -![Connected To Local Configuration](/images/passwordpolicyenforcer/11.1/administration/connecttolocal.webp) - -### Help - -Links to documentation and support tools. - -- **Netwrix Help Center** launches the Password Policy Enforcer help. -- **About** displays the Configuration Console version. -- **Export Configuration Report** opens an export dialog. You can export the configuration as an - html or txt file. Browse to the folder where you want the report. -- **Open Property Editor** launches the Property Editor. - - :::note - Properties should only be changed when advised by Netwrix Support. - ::: - - -### Settings - -There are four tabs: - -- General -- Notifications -- Mail Service -- License - -#### General - -Open the **Settings** > **General** tab to set up policy and log settings. The general settings -apply to either the domain or to a local computer, depending on your Connected To configuration -setting. - -If you make changes, click **Save** to keep your changes or **Discard** to cancel. - -Here are the default settings. - -![General Settings PPE](/images/passwordpolicyenforcer/11.1/administration/settingsgeneral.webp) - -- **Default policy** sets the policy to be enforced on the domain or local computer unless users - have a different policy assigned to them. -- **Enforce policy when password is reset** requires users, administrators, and helpdesk operators to - comply with the password policy when resetting a password or creating a new user account. Default - is checked. - - - Minimum Age rule is never enforced during a reset. - - History rule is enforced if this option is selected and the **Enforce this rule when a - password is reset** option is selected on the [History Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/history_rule.md) Properties. - -- **Accept encrypted client request only** specifies requests from Password Policy Client, Netwrix - Password Reset and Password Policy/Web must be encrypted. Client requests don't contain passwords - or password hashes. See the [Password Policy Client](/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/password_policy_client.md) topic for - additional information. Default is checked. -- **Log event when password not checked by service** adds an entry to the Windows Application Event - Log whenever it accepts a password without checking it. Default is checked. This can occur if: - - - Password Policy Enforcer is disabled. - - The policy assigned to a user is disabled. - - No policy is assigned to a user or an error occurs when determining the assigned policy, and a - Default Policy isn't specified. - - A password is reset, and the **Enforce policy when password is reset** isn't selected. - -- **Log event when password rejected by service** adds an entry to the Windows Application Event Log - whenever a password is rejected. Default isn't checked. The logged event includes: - - - Username - - Source (client or server) - - Rules the password doesn't meet. - - :::note - Passwords or password hashes aren't sent over the network. - ::: - - - Most rules are enforced by both the Password Policy Client and Password Policy Server. If the - Password Policy Enforcer Client is installed, a non-compliant password can be rejected before - Windows sends it to the domain controller. The following limitations apply when a password is - rejected by the Password Policy Client: - - - An event is only logged if the Password Policy Enforcer Client version is 9.0 or later. If a - password is rejected by the Password Policy Server, then the event is logged. - - Client logged events only show the local rules the password violated. For example, the - Compromised rule is only enforced by the Password Policy Server. See the [Rules](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/rules.md) - topic for additional information. - - Client rejections can be lost or duplicated if there are communication issues between the - Password Policy Client and Password Policy Server. - -- **Log event when password accepted by service** adds an entry to the Windows Application Event Log - whenever a password is accepted. The logged event includes the username. Default isn't checked. - -- **Use old icons in Live Policy Feedback** allows switching between displaying old-style and new-style icons in the Password Policy Enforcer Client on the change password screen. - -#### Notifications - -Open the **Settings** > **Notifications** tab to set up notifications. Notifications are only -available when **domain** is selected with the Connected To configuration setting. - -If you make changes, click **Save** to keep your changes or **Discard** to cancel. - -![Notifications Settings](/images/passwordpolicyenforcer/11.1/administration/settingsnotifications.webp) - -- **Send email reminders**: check this option to send reminders. Default isn't checked. -- **Save email to a pickup folder**: check this option to have the Mailer save emails to a folder for later delivery by a mail server. The mail server must monitor this folder for new email. - - **Path**: Click **Browse** and select the path to the pickup folder. - -:::note -Saving email to a pickup folder is the fastest and most reliable delivery method. Use this -option if your mail server supports pickup folders. -::: - -The Password Policy Enforcer Mailer sends emails at 2:00 AM every day (local time on your server). -Check the Windows Application Event Log to monitor its progress. You can also run the Password -Policy Enforcer Mailer from the command line to send email immediately, or to troubleshoot problems. - -:::note -You can change the time the mailer runs. Set the **PPE Mailer** service startup to -**Disabled** or **Manual**, then stop the service. Create a task to run "**PPEMail /send**" at the -desired time. -::: - -##### Configuring Email Settings - -There are three possible ways to configure email settings: - - **SMTP Server** - - **Google OAuth2** - - **O365 OAuth2** - -###### SMTP Server - -![Notifications Settings](/images/passwordpolicyenforcer/11.1/administration/settingsnotifications2.webp) - -- **SMTP Server**: enter IP address. -- **Port**: enter port number. -- **Username**: enter your username. -- **Password**: enter your password. -- **Use TLS**: check this option to enable TLS email encryption. - -###### Google OAuth2 - -![Notifications Settings](/images/passwordpolicyenforcer/11.1/administration/settingsnotifications3.webp) - -- **User Account**: authenticated Google Workspace account. -- **Client ID**: value configured in the Google Workspace Admin Console. -- **Client Secret**: value configured in the Google Workspace Admin Console. -- **Clear Credentials**: removes stored values and tokens. -- **Update Credentials**: initiates token generation in a browser window. - -:::note -The Google OAuth2 timeout can be configured in **PPEConfiguration.json**. -By default, it is set to **1 minute**: -``` -"Configuration": { - "GoogleOAuthTimeout": 60 -} -``` -::: - -###### O365 OAuth2 - -![Notifications Settings](/images/passwordpolicyenforcer/11.1/administration/settingsnotifications4.webp) - -- **User Account**: Office 365 account. -- **Client ID**: value configured in the Office 365 Admin Console. -- **Client Secret**: value configured in the Office 365 Admin Console. -- **Tenant ID**: Office 365 tenant identifier. -- **Clear Credentials**: removes values. - -#### Mail Service - -Open the **Settings** > **Mail Service** tab to set up mail service for notifications. - -If you make changes, click **Save** to keep your changes or **Discard** to cancel. - -![Mail Server Tab](/images/passwordpolicyenforcer/11.1/administration/settingsmailserver.webp) - -- **Service**: specify the address of the machine where the mail service is installed. -- **Port**: specify the port number. - -:::note -If you need to use a port other than 12345, open the **PPEMailService.json** file on the machine where -the mail service is installed, update the port value, and restart the mail service to apply the changes. -``` -"MailService": { - "HostName": "localhost", - "Port": 6000 -} -``` -::: - -#### License - -Open the **Settings** > **License** tab to view your current license. The license settings apply to -either the domain or to a local computer, depending on your Connected To configuration setting. - -To add or update your license, copy it from the email or file, then click **Paste license from -clipboard**. - -![License Settings Tab](/images/passwordpolicyenforcer/11.1/administration/settingslicense.webp) - -- **License type** and **Licensed to** are set based on your sales agreement. -- **Users** is the total number of available licenses. -- **AD Users** is the total number of Active Directory user accounts. -- **In use pertains** to active AD user accounts, disregarding disabled accounts. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/_category_.json b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/_category_.json deleted file mode 100644 index eed0fd644e..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Policies", - "position": 20, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "manage_policies" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/manage_policies.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/manage_policies.md deleted file mode 100644 index d3ca896259..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/manage_policies.md +++ /dev/null @@ -1,205 +0,0 @@ ---- -title: "Manage Policies" -description: "Manage Policies" -sidebar_position: 20 ---- - -# Manage Policies - -Netwrix Password Policy Enforcer can enforce up to 256 different password policies. You can assign -policies to users directly, or indirectly through Active Directory security groups and containers -(Organizational Units). See the [Assign Policies to Users & Groups](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/usersgroups.md) topic for -additional information. - -Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -![Configuration Console Dashboard](/images/passwordpolicyenforcer/11.1/evaluation/ppedashboard.webp) - -The Configuration Console dashboard shows **No password policies have been set up** when you are -getting started with Password Policy Enforcer. After you **Add a policy**, the dashboard shows the -defined policies and tool links. In this example, the Default Password Policy and CIS Password -Policy Guide have been added. - -![Dashboard with Policies](/images/passwordpolicyenforcer/11.1/administration/ppedashboardpolicies.webp) - -The policy management links are all on the Password Policies tile: - -- [Add a Policy.](#add-a-policy) -- [Set Up a Policy](#set-up-a-policy) (click existing policy name). -- [Test Policy.](#test-policy) -- [Set Priorities.](#set-priorities) -- [Export.](#export) -- Context menu (3 stacked dots) beside each defined policy [Make Copy](#make-copy), [Make Default/Remove Default](#make-defaultremove-default), [Rename](#rename), and [Delete](#delete). - -## Add a Policy - -**Step 1 –** Click **Add policy** from the Configuration Console. - -**Step 2 –** Enter a unique policy name. Maximum is 32 characters. - -**Step 3 –** Select a Policy template or **None** if you are creating your own. - -**Step 4 –** Click **Create policy**. - -Alternatively, you can select an existing policy and use the Context menu Make Copy option to start -with the selected policy. - -### Policy Templates - -Password Policy Enforcer contains Built-in Policy Templates based on the requirements of the -most popular regulatory frameworks. - -- Center for Internet Security (CIS) Password Policy Guide – See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- Center for Internet Security (CIS) Password Policy Guide MFA – See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- Cybersecurity Information Sharing Act (CISA) -- Criminal Justice Information Services (CJIS) Security Policy -- Cybersecurity Maturity Model Certification (CMMC) -- Defense Federal Acquisition Regulation Supplement (DFARS) -- Gramm-Leach-Bliley Act (FedRAMP) -- Federal Information Security Management Act (FISMA) -- Health Insurance Portability and Accountability Act (HIPPA) – HIPAA Security Rule requires that - organizations must implement procedures for creating, changing, and safeguarding passwords. - - - It also recommends training the workforce on ways to safeguard password information and - establish guidelines to create and change passwords in a periodic cycle. - - HIPAA doesn’t offer any specific password complexity guidelines. To comply with HIPAA, - organizations are better off following NIST password guidelines. - - Most of healthcare institutions use the NIST framework. - -- International Organization for Standardization (ISO/IEC) 27002 – See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. -- North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) – - See the - [CIP-007-6 — Cyber Security – Systems Security Management](https://www.nerc.com/_layouts/15/PrintStandard.aspx?standardnumber=CIP-007-6&title=Cyber%20Security%20-%20System%20Security%20Management&Jurisdiction=United%20States) article - for additional information. -- National Institute of Standards and Technology (NIST) Special Publication 800-171 -- National Institute of Standards and Technology (NIST) Special Publication 800-53 -- National Institute of Standards and Technology (NIST) Special Publication 800-63b – See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. -- Payment Card Industry Data Security Standard (PCI DSS) – See the - [PCI Document Library](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss) web - site for additional information. -- Payment Card Industry Data Security Standard (PCI DSS) (version 4) - -## Set Up a Policy - -After you add a policy, it needs to be set up or reviewed if you used a template. Click the policy -name to edit the policy. For each policy: - -- Set up [Rules](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/rules.md). -- [Assign Policies to Users & Groups](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/usersgroups.md). -- Enable the use of an optional [Passphrase](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/passphrases.md). -- Set up [Policy Properties](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/policy_properties.md). -- Set up [Messages](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/messages.md) for your users. - -## Test Policy - -Launches the Test policy tool in a separate window. You can test **By user** and by **Password bulk -test**. See the [Test Policy](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/testpolicy.md) topic for additional information. - -## Set Priorities - -Set priorities determines which policy to enforce if users have more than one policy. Click **Apply -priorities** to save the new order. - -![Set priorities](/images/passwordpolicyenforcer/11.1/administration/policypriority.webp) - -### Policy Selection Flowchart - -This flowchart shows how Password Policy Enforcer determines a policy for each user. Use the -[Test Policy](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/testpolicy.md) tool to quickly determine which policy Password Policy Enforcer is -enforced for a particular user. - -![managing_policies](/images/passwordpolicyenforcer/11.1/administration/managing_policies.webp) - -## Export - -Exports your policy configuration to **C:\Program Files\Netwrix\Password -Policy Enforcer\Report\report.html** - -## Make Copy - -Duplicates a policy. This context menu item is also available when you are editing a policy. - -**Step 1 –** Click the context menu next to the policy to copy. - -**Step 2 –** Select **Make copy** from the context menu. - -**Step 3 –** Enter a unique name for the policy. - -**Step 4 –** Click **Make copy**. - -## Make Default/Remove Default - -Assigns the selected policy as the default, or removes the selected policy as the default. These -context menu items are also available when you are editing a policy. - -**Step 1 –** Click the context menu next to the policy to set as the default. - -**Step 2 –** Select **Make default** from the context menu. The policy is assigned to all domain -users who don't have a specific policy assigned. **Default** is indicated in the policy list. The -context menu changes to **Remove Default**. - -:::note -If you assign a different policy as the default you are prompted that an existing default -is set. -::: - - -## Rename - -Renames a policy. - -**Step 1 –** Click the context menu next to the policy to rename. - -**Step 2 –** Select **Rename** from the context menu. - -**Step 3 –** Enter a unique name for the policy. - -**Step 4 –** Click **Rename**. - -## Delete - -Deletes a policy. This context menu item is also available when you are editing a policy. - -**Step 1 –** Click the context menu next to the policy to delete. - -**Step 2 –** Select **Delete** from the context menu. - -**Step 3 –** Click **Delete**. A warning confirmation is displayed if you delete the default policy. - -## Exempt Users from a Password Policy - -You can exempt users from having to comply with the password policy when a default policy is -specified. - -**Step 1 –** Create a new policy for these users. - -**Step 2 –** Leave all the rules disabled for this policy. - -**Step 3 –** Assign this policy to the users who don't have to comply with any Password Policy -Enforcer rules. - -:::warning -If Password Policy Enforcer has only one policy and that policy is also the default -policy, then Password Policy Enforcer enforces the policy for all users. -::: - - -The Password Policy Client and Password Policy Server communicate over UDP port 1333 by default. If -you need to change the default port, then enter the new port number in the **Password Policy Server -Port** text box. Setting the port number to zero stops Password Policy Enforcer from accepting -client requests. If you change the port number, then you must also: - -- Restart all the Password Policy Server computers. -- Configure the Password Policy Client to use the new port. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/messages.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/messages.md deleted file mode 100644 index 79daf21b35..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/messages.md +++ /dev/null @@ -1,66 +0,0 @@ ---- -title: "Messages" -description: "Messages" -sidebar_position: 50 ---- - -# Messages - -Each Password Policy Enforcer password policy has multiple message templates, one for each of the -Password Policy Client messages. - -- Password Policy – Displays the password policy guidelines on clients that have the Netwrix - Password Policy Enforcer Client installed. -- [POLICY] – Customize the text for the active rules. -- [LIVE_POLICY] – Password Policy Client (10.2 and above) messages can be configured to display live - feedback for the active rules to users as they enter their passwords. This feature enables users - to see if their passwords meet the requirements of the policy set by the organization. Here is an - example of a live policy message. - - ![Messages](/images/passwordpolicyenforcer/11.1/administration/mesages2.webp) - - :::note - Start each custom message with two spaces, a hypen, and a space before your message so - the X and checks can appear for the rule. For example: " **- Include an upper case alpha - character.**" The quotes are only there to illustrate the message. - ::: - - -- Rejection Reason – Displays why an intended password was rejected on clients that have the Netwrix - Password Policy Enforcer Client installed -- Generic Rejection – Displays if Password Policy Enforcer doesn't have a specific reason for the - rejection, generally because the password doesn't comply with the Windows password policy - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -**Step 2 –** Click a policy name to open the policy configuration page. - -**Step 3 –** Open the **Messages** tab. - -![Set up messages](/images/passwordpolicyenforcer/11.1/administration/messages.webp) - -**Step 4 –** Select the message language from the dropdown list. You can set messages for multiple -languages. You don't have to create a Password Policy Enforcer policy for each language. To set -multiple languages, pick one, edit the message templates. Select another language, and edit the -message templates. Repeat for each language you want to implement. The correct message is displayed -to users based on their selected language. - -**Step 5 –** Edit the message templates in the Password policy, [POLICY], [LIVE_POLICY], Rejection -Reason, and Generic rejection messages for any of the components you want to use. - -**Step 6 –** Insert the macros into your message. Click **Macro** and pick one to insert it. - -![Use macros for your message](/images/passwordpolicyenforcer/11.1/administration/messagesmacros.webp) - -**Step 7 –** Click **Save** and review your changes in the Preview area. Click **Save** f you edit -the message. - -:::note -If you don't see the **Preview**, contact your network administrator to set up the -firewall to allow Password Policy Enforcer to communicate. - -::: diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/passphrases.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/passphrases.md deleted file mode 100644 index ac9d1a44f5..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/passphrases.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Passphrase" -description: "Passphrase" -sidebar_position: 30 ---- - -# Passphrase - -Passphrases have gained popularity in recent years as they can be more difficult to crack and easier -to remember than passwords. The difference between passwords and passphrases is their length. -Passwords are rarely longer than 15 characters, but passphrases commonly contain 20 or more -characters. - -Complexity and dictionary rules are less important for passphrases as passphrases rely primarily on -length for security. You may want to relax some password policy requirements for passphrases. - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -**Step 2 –** Click a policy name to open the policy configuration page. - -**Step 3 –** Open the **Passphrase** tab. - -![Enable Passphrases](/images/passwordpolicyenforcer/11.1/administration/passphrase.webp) - -**Step 4 –** Select the number of characters the password must contain before the selected rules are -disabled. - -**Step 5 –** Select the rules to be disabled. - -Disabled rules aren't counted when calculating the compliance level, but Password Policy Enforcer -accepts passphrases that comply with all enabled rules, irrespective of the compliance level. This -ensures that passphrases can be used, even if they don't meet the compliance level when Password -Policy Enforcer is configured to disable one or more rules for passphrases. - -:::note -Opinions differ on how long a passphrase needs to be. Even a 30 character passphrase can -be weaker than a well-chosen password. Don't disable too many rules under the assumption that -length alone makes up for the reduced complexity. - -::: diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/policy_properties.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/policy_properties.md deleted file mode 100644 index 4e4d085bff..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/policy_properties.md +++ /dev/null @@ -1,87 +0,0 @@ ---- -title: "Policy Properties" -description: "Policy Properties" -sidebar_position: 40 ---- - -# Policy Properties - -Sets the properties for the selected policy. - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -**Step 2 –** Click a policy name to open the policy configuration page. - -**Step 3 –** Open the **Properties** tab. - -![Set the Policy Properties](/images/passwordpolicyenforcer/11.1/administration/properties.webp) - -Each policy must have a unique name. To change the name of a policy, enter the new name in the text -box. - -Enter any **Notes** about the policy - -Select the **Default characters set**. The default value (Netwrix Password Policy Enforcer) requires -users to comply with rules that use the Password Policy Enforcer character set. Choose the alternate -option (Windows) to have users comply with rules that use the Windows character set. - -:::note -Only Password Policy Enforcer 10.0 and higher contain the Windows character set. Password -Policy Enforcer 9, Netwrix Password Reset and Password Policy Enforcer/Web 7 (and older for all -products) always use the Password Policy Enforcer character set. -::: - - -- Some languages such as Japanese don't distinguish between uppercase and lowercase. These - characters are in the Windows Alpha set, but not in the Upper or Lower sets. -- Characters classified as a space, punctuation, control, or blank by Windows are included in the - Special character set. If these characters are also included in some other set by Windows (for - example, a superscript one is both a decimal digit and punctuation), then Password Policy Enforcer - only includes them in the Special character set when the Windows character set is selected. -- When using the Password Policy Enforcer character set, all characters above ANSI 126 are included - in the High set. When using the Windows character set, a character is only included in the High - set if it is above ANSI 126 and not included in any other set by Windows. - -Select the number of rules for **Passwords must comply with** from the dropdown list to specifiy -the required compliance level for this policy. The default value **(all the rules**) requires users -to comply with all enabled rules. Choose an alternative option if Password Policy Enforcer should -enforce a more lenient password policy. The Minimum Age and Maximum Age rules are excluded from -compliance level calculations. See the [Rules](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/rules.md) topic for additional information. - -When setting the compliance level, consider that some rules may be disabled when a user enters a -passphrase. See the [Passphrase](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/passphrases.md) topic for additional information. Password Policy -Enforcer accepts passphrases that comply with all enabled rules, irrespective of the compliance -level. This ensures that passphrases can be used, even if they don't meet the compliance level when -Password Policy Enforcer is configured to disable one or more rules for passphrases. - -Password Policy Enforcer can start a password synchronization application or script whenever a user -successfully changes their password. Enter the full path to the executable in the **Execute the -program when password is changed** text box. The path can contain environment variables like -`%SystemRoot%`. Every computer running Password Policy Enforcer should have a local copy of the -program, and only authorized users should have access to it, or any of its components. - -The user logon name and new password are sent to the program as command-line parameters. For -example, if you add the following commands to a batch file, Password Policy Enforcer records each user's -logon name and new password in a text file named **passwords.txt**: - -**echo Username: %1 >> c:\passwords.txt** - -echo Password: %2 >> c:\passwords.txt - -:::warning -This script is shown as an example only. You shouldn't store user passwords. -::: - - -The command can now include the [USERNAME] and [PASSWORD] macros. If neither is specified, then the -command is executed with both parameters to maintain compatibility with existing programs/scripts. - -:::info -Use the [USERNAME] parameter if the password isn't needed by the program/script -so that the password isn't unnecessarily sent to the change notification command/script. - -::: diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/_category_.json b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/_category_.json deleted file mode 100644 index 278fe80f06..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Rules", - "position": 10, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "rules" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/character_rules.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/character_rules.md deleted file mode 100644 index afc949691f..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/character_rules.md +++ /dev/null @@ -1,102 +0,0 @@ ---- -title: "Character (Granular) Rules" -description: "Character (Granular) Rules" -sidebar_position: 40 ---- - -# Character (Granular) Rules - -Password Policy Enforcer has seven Character rules that reject passwords if they contain, or don't -contain certain characters. These rules can increase password strength or ensure password -compatibility with other systems. - -![Character (Granular) Rule](/images/passwordpolicyenforcer/11.1/administration/chargranular.webp) - -All the Character rules work identically, but each has their own default character set. A character -set is the collection of characters that each rule searches for when checking a password. You can -use the Character rules with their default character sets, or define your own. By default, the -Password Policy Enforcer selects the Password Policy Enforcer character on the -[Set Priorities](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/manage_policies.md#set-priorities) page. - -:::note -Only Password Policy Enforcer 11 and later contain the Windows character set. -Password Policy Enforcer 9, Netwrix Password Reset3 and Password Policy Enforcer Web 7 (and older -for all products) use the Password Policy Enforcer character set. -::: - - -Select the **Characters (Granular)** checkbox to enable the Characters rule. - -For each selected character set, select whether they **Contain** or **Not contain** the specified -number of characters. - -Select the **contain** option if this rule should ensure that new passwords contain certain -characters. Only one character is required by default, but you can specify a different value by -choosing the required number of characters from the dropdown list beside the **contain** option. - -Select the **not contain any...** option if this rule should ensure that new passwords don't -contain certain characters. - -You can further restrict the rule by defining positions or embedding characters. - -Click the + sign by the character set. - -Select **In position**. - -![Restricting Characters](/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict.webp) - -If you want to restrict this rule to certain character positions, choose the starting position from -the first entry box and the ending position from the second entry box. For example, you may want to -enforce a rule that requires a numeric character in the second character position to maintain -compatibility with some other system. - -![Require a number in position 2](/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict2.webp) - -Click the + sign by the character set. - -Select **Embedded**. - -Select the **Embedded** checkbox if users are required to embed these characters within their -passwords. For example, the passwords "12hello", "1hello", and "hello$987" don't contain any -embedded numeric characters, but these passwords do contain embedded numeric characters (shown in -bold type): "he**7**llo", "4he**3**llo", "23hello**7**$45". Embedded numeric and special characters -can help to protect passwords from cracking attacks. - -:::note -The First Character, Last Character, and Complexity rules are easier to configure, and -easier for users to understand. Use these rules instead of the Character rules if they can enforce -your desired policy. -::: - - -You can customize character sets with the Characters option for a selected set. - -**Step 1 –** Click **Characters** beside a selected Character set. - -**Step 2 –** Enter a **Name**. This example uses **vowels**. - -![Set up custom character set](/images/passwordpolicyenforcer/11.1/administration/chargranularvowel.webp) - -**Step 3 –** Enter the **Characters**. This example uses **AaEeIiOoUu**. - -**Step 4 –** Click **Apply**. - -If you save and test the policy, you see **vowels** is listed as a requirement. - -To remove a custom set, click **Characters** and delete the information. Click **Apply**. - -### Enforcing Complex Character Requirements - -Character rules can be combined to enforce complex password requirements. For example, you may need -to enforce a policy such as "passwords must contain a numeric character, but not in the first two -positions" to ensure compatibility with some other system. - -This is done by using two of the Character rules: - -Set **Characters (Complexity)** to require 1 Numeric character. - -![Require a numeric value](/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict3.webp) - -Set **Characters (Granular)** to not contain numeric values in the first two positions. - -![Don't allow numeric values in first two positions](/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict4.webp) diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/complexity_rule.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/complexity_rule.md deleted file mode 100644 index 32d250398b..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/complexity_rule.md +++ /dev/null @@ -1,44 +0,0 @@ ---- -title: "Characters (Complexity) Rule" -description: "Characters (Complexity) Rule" -sidebar_position: 30 ---- - -# Characters (Complexity) Rule - -The Complexity rule rejects passwords that don't contain characters from a variety of character -sets. Using several character types can make passwords more difficult to crack. - -![Character Complexity Rule](/images/passwordpolicyenforcer/11.1/administration/charcomplexity.webp) - -Select the **Characters (Complexity)** checkbox to enable the Character Complexity rule. - -Select the number of required character sets. Passwords are rejected if they don't contain -characters from at least the specified number of character sets. - -Select the available character sets. The number of available character sets must be equal to or -greater than the number of required character sets. - -Select the **Passwords must always comply with this rule** checkbox to make the Complexity rule -mandatory. Password Policy Enforcer rules are mandatory by default, but can be made optional by -changing the Reject passwords that don't comply with value in the Policy Properties page. A -mandatory rule can still be disabled when a passphrase is used. See the [Passphrase](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/passphrases.md) -topic for additional information. - -:::note -The Complexity rule uses custom character set definitions from the Character rules, even -if the Character rules are disabled. -::: - - -This default character set contains the following: - -| Rule | Default character set | -| ----------- | ------------------------------------------------------------------------ | -| Alpha Lower | Lowercase alphabetic (a-z) | -| Alpha Upper | Uppercase alphabetic (A-Z) | -| Alpha | Uppercase and lowercase alphabetic (a-z & A-Z) | -| Numeric | Numerals (0-9) | -| Special | All characters not included above | -| High | All characters above ANSI 126 | -| Custom | No default characters | diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/compromised_rule.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/compromised_rule.md deleted file mode 100644 index 81505583b7..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/compromised_rule.md +++ /dev/null @@ -1,26 +0,0 @@ ---- -title: "Compromised Rule" -description: "Compromised Rule" -sidebar_position: 50 ---- - -# Compromised Rule - -The Compromised rule rejects passwords from prior breaches. These passwords shouldn't be used as -they are vulnerable to credential stuffing attacks. - -![Compromised password rule](/images/passwordpolicyenforcer/11.1/administration/compromised.webp) - -Select the **Compromised** checkbox to enable the Compromised rule. - -You can browse to your compromised passwords base files or enter a path into the text box. The path -can contain environment variables like - -:::warning -%SystemRoot%. hash files should only be read from a local disk. Using shared hash files -degrades performance, and could jeopardize security. -::: - - -See the [HIBP Updater](/docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md) topic for the information about the Have I Been Pwnd (HIBP) -database usage. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/dictionary_rule.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/dictionary_rule.md deleted file mode 100644 index c4ccff0aff..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/dictionary_rule.md +++ /dev/null @@ -1,156 +0,0 @@ ---- -title: "Dictionary Rule" -description: "Dictionary Rule" -sidebar_position: 60 ---- - -# Dictionary Rule - -The Dictionary rule rejects passwords that are vulnerable to guessing, hybrid, and precomputed -attacks. These attacks can crack weak passwords in seconds, and they can be very effective if -passwords are based on common words. - -![Dicitonary Rule](/images/passwordpolicyenforcer/11.1/administration/dictionary.webp) - -There are two Dictionary rules in each password policy. You can use the second rule with a different -dictionary file, or to enforce a more tolerant policy for passphrases by disabling the primary rule -for long passwords. - -Select the **Dictionary** checkbox to enable the Dictionary rule. - -Browse to a dictionary file. Password Policy Enforcer installs a sample file **Dict.txt** in the **\Program Files\Netwrix\Password Policy Enforcer\\** folder. This file is sorted and ready to use. It contains -approximately 257,000 words, names, and acronyms. - -Select the **Detect inclusion of non-alpha characters** checkbox if Password Policy Enforcer should -remove all non-alphabetic characters during analysis. This allows Password Policy Enforcer to reject -passwords such as "myp8asswor8d." - -Select the **Detect character substitution** checkbox if Password Policy Enforcer should reject -passwords that rely on character substitution to comply with this rule. - -Select the **Detect words typed backwards** checkbox if Password Policy Enforcer should -additionally test passwords with their characters reversed. Enabling bi-directional analysis stops -users from circumventing this rule by reversing the order of characters in their password. For -example, a user may enter "drowssapym" instead of "mypassword". - -Select the **Wildcard analysis** checkbox if Password Policy Enforcer should search for wildcard -templates in the dictionary file. Wildcard templates are specially formatted dictionary words that -Password Policy Enforcer uses to reject a range of passwords. The Dictionary rule supports two -wildcard template formats: - - - - - - - - - - - - - - - - - - - - - -
FormatExampleDescription
Prefix - - - - - - - - - -
!!BAN*!!
!!2*!!
-
- - - - - - - - - -
Rejects passwords that start with BAN. For example: band, banish, ban, bank, etc.
Rejects passwords that start with the numeric character 2. For example: 2ABC, 2123, etc.
-
- Suffix - - !!*ING!! - - Rejects passwords that end with ING. For example: pushing, howling, trying, etc. -
- - -Password Policy Enforcer performs partial matching even if Wildcard analysis is disabled. For example, the dictionary -word "password" rejects the passwords "My**Password**$", "**Password**100", and -"12**password**34" even if Wildcard analysis is disabled. - -Wildcard analysis should only be used to limit matching to the characters at the start or end of a -password. - -Enabling Wildcard analysis slightly increases search times, so only enable this option if the -dictionary file contains wildcard templates. The sample dictionary file included with Password -Policy Enforcer doesn't contain any wildcard templates. - -Choose a value from the Tolerance dropdown list to specify the maximum number of consecutive matching characters that Password Policy Enforcer tolerates before rejecting a password. For example, the dictionary word "**sword**" and the password "4my**sword**%" contain five consecutive matching characters (shown in bold). Password Policy Enforcer rejects this password if the tolerance is four or lower, and accepts it if the tolerance is five or higher. - -Click the **Browse** button to select a dictionary file, or enter a path into the text box. The path -can contain environment variables like %SystemRoot%. Password Policy Enforcer installs a sample dictionary in the -\Program Files (x86)\Password Policy Enforcer\ folder. Read the dictionary file from a -local disk. Using a shared dictionary degrades performance, and could jeopardize security. - -:::note -The `\Program Files (x86)\` folder doesn't exist on 32-bit Windows, so move the -dictionary into the `\Program Files\Netwrix\Password Policy Enforcer\` folder if you have 32-bit and 64-bit -computers sharing a common Password Policy Enforcer configuration. -::: - - -Click the **Sort** button if the dictionary file is being used with Password Policy Enforcer for the -first time, or if words have been added to the file since it was last sorted. The Password Policy -Enforcer Configuration Console will sort and reformat the file so that Password Policy Enforcer can use -it. Sorting also removes duplicate words, so the sorted file may be smaller than the original. - -Click the **Messages** tab to customize the Password Policy Client rule inserts. If both Dictionary -rules have identical inserts, then only one of the inserts is shown in the corresponding Password -Policy Client message if the password is rejected by both rules. - -## Creating a Custom Dictionary - -You can add words to the sample dictionary file, or download larger dictionary files from the -Internet. Always sort a dictionary file before using it with Password Policy Enforcer, and ensure -that all computers have a local copy of the updated and sorted file. - -The custom dictionary should meet the following requirements: - -1. The dictionary should begin and end with a blank line. -2. Capitalize all words. -3. Press the Sort button after pointing to a file in the dictionary rule. - -:::note -If you are using a custom dictionary, use a different filename. The default -dictionary file (dict.txt) may be replaced during an upgrade. -::: - - -## Dictionary File Replication - -Password Policy Enforcer doesn't distribute dictionary file updates to other computers, but you can -use the Windows Distributed File System to ensure that all domain controllers have the latest -dictionary file. Copy the dictionary file into the Sysvol share on one domain controller, and the -Distributed File System will copy the file into the Sysvol share of all other domain controllers. -Configure the Dictionary rule to read the file from \\127.0.0.1\sysvol\your.domain\filename.txt - -The path above only works if the computer has a Sysvol share. This won't be the case if you are -using a workstation for policy testing, or if you are using Password Policy Enforcer to enforce -local polices. If you are using Password Policy Enforcer for local policies and want all computers -to receive dictionary file updates, then use the Sysvol share for file replication and a script or -scheduled task to copy the file to a local folder. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/history_rule.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/history_rule.md deleted file mode 100644 index ff5097e83e..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/history_rule.md +++ /dev/null @@ -1,158 +0,0 @@ ---- -title: "History Rule" -description: "History Rule" -sidebar_position: 70 ---- - -# History Rule - -The History rule rejects passwords that are identical to recently used passwords. Password reuse -should be avoided because it defeats the purpose of regular password changes. Password Policy -Enforcer can stop users from reusing passwords for a specified number of password changes or a -number of days. - -![History rule](/images/passwordpolicyenforcer/11.1/administration/history.webp) - -Select the **History** checkbox to enable the History rule. - -Select one of the options: - -**One of the last** option to stop passwords from being reused for a specified number of password -changes. Choose the number of password changes from the dropdown list. - -**A password used in the last** option to stop passwords from being reused for a specified number of -days. Enter the number of days in the text box. - -Choose an item from the **Hash function** dropdown list. Argon2 is recommended for best security. -The Argon2 option uses 100,000 times more computing power to create a hash, so an attacker needs -100,000 more computing power to crack Argon2 hashes. Argon2 increases password change times by 400%, -so a domain controller that can handle 1,000 password changes a minute with SHA-256 can be expected -to handle 250 password changes a minute with Argon2. All numbers are approximate. Use Argon2 if your -domain controllers can handle the load. - -:::note -Changing the **Hash function** doesn't modify existing history records. It sets the -function to be used for new password history records. If a user has Argon2 and SHA-256 hashes in -their password history, then Password Policy Enforcer calculates both the Argon2 and SHA-256 hashes -during a password change to ensure the new password isn't in the password history. -::: - - -The History rule is normally not enforced when a password is reset. Select the **Enforce this rule -when a password is reset** checkbox to override the default behavior. You must also select the -**Enforce policy when password is reset** option in the PPS Properties page to enforce this rule -when a password is reset. - -Click the **Messages** tab to customize the Password Policy Client rule inserts. - -:::note -The History rule isn't enforced when testing passwords from the Test Policies page. -::: - - -Password Policy Enforcer updates a user's password history whenever their password changes. The -password history is updated even if Password Policy Enforcer or the assigned policy is disabled. A -user's password history is deleted if the user doesn't have an assigned policy, or if the History -rule is disabled at the time of the password change. - -Password Policy Enforcer's password history is stored in Active Directory for domain user accounts, -and in the registry for local user accounts. You can create a new Active Directory attribute for the -password history, or configure Password Policy Enforcer to use an existing attribute. - -Disable Password Policy Enforcer's History rule if you don't want Password Policy Enforcer to store -the password history. - -:::note -Password Policy Enforcer doesn't store passwords in the password history, it only stores -the Argon2 or SHA-256 hashes. A salt protects the hashes from precomputed attacks, including rainbow -tables. If you don't want Password Policy Enforcer to store a password history, then leave the -History rule disabled. You can use the Windows History rule together with Password Policy Enforcer's -other rules to enforce your password policy. -::: - - -Password Policy Enforcer can store up to 100 password hashes for each user, but it only stores the -minimum needed to enforce the current password policy. For example, if Password Policy Enforcer is -configured to reject the last 24 passwords, then only the last 24 password hashes are stored. -Reconfiguring Password Policy Enforcer to reject the last 30 passwords won't have an immediate effect because only 24 password hashes are stored. The full effect of the new configuration is realized after users change their passwords six more times, at which point Password Policy Enforcer has 30 stored password hashes for each user. - -Leave both the Windows and Password Policy Enforcer History rules enabled when transitioning from -one to the other. This allows the old rule to enforce the policy until the new rule has built up its -password history. The old rule can be disabled after users have completed the required number of -password changes to enforce the new rule. - -As Password Policy Enforcer is limited to storing the last 100 password hashes, it is possible for -the History rule to run out of storage space before the specified number of days. Use the Minimum -Age rule to avoid this problem. For example, if the History rule is configured to not allow password -reuse for 365 days, then set the minimum password age to four or more days. Even if a user changes -their password every four days, they can only perform 91 password changes in 365 days. - -## Creating a New Attribute for the Password History - -Windows stores a domain user's password history in two Active Directory attributes, but these -attributes can't be used by other applications. Password Policy Enforcer can store the password -history in a new or existing attribute. A new attribute is recommended, but you can use an existing -attribute if you don't want to extend the AD schema. An AD attribute is only needed for domain user -accounts because the password history for local user accounts is stored in the registry. - -:::warning -Password Policy Enforcer's password history attribute is confidential to stop -authenticated users from accessing the password history of other users. See the Microsoft Article -[Mark an attribute as confidential in Windows Server 2003 Service Pack 1](http://support.microsoft.com/kb/922836) -Microsoft article for additional information. Confidential attributes have additional protection in -Active Directory, but they aren't as well protected as the Windows password history attributes. -There is a higher risk of unauthorized access to the password history if it is stored outside the -Windows password history attributes. -::: - - -Follow the following steps to create a new Active Directory attribute for the password history. - -**Step 1 –** Log on to the server holding the Schema Operations Master role with an account that is -a member of the Schema Admins group. - -**Step 2 –** Open a Command Prompt window to the Password Policy Enforcer installation folder. - -**(\Program Files (x86)\Password Policy Enforcer\)** - -**Step 3 –** Enter the following command: - -**: ldifde -i -f History.ldf -c "DC=X" "DC=yourdomain,DC=yourdomain"** - -Replacing the last parameter with your domain's DN. - -**Step 4 –** Press **ENTER** and check the output for errors. - -![ppe_rules_8](/images/passwordpolicyenforcer/11.1/administration/ppe_rules_8.webp) - -## Using an Existing Attribute for the Password History - -Password Policy Enforcer can store the password history in an existing attribute. The desktopProfile -attribute is well suited because it isn't used by Windows. Other attributes are also suitable if -they aren't being used. Contact [Netwrix Support](https://www.netwrix.com/support.html) if you -would like to use an existing attribute for the password history. - -## Password Histories for Local User Accounts - -The password histories of local user accounts are stored in the HKLM\SECURITY\PPE Password History\ -registry key. Users aren't granted access the HKLM\SECURITY\ registry key by default, so a user -can't read the password history of any user (including themselves). This is also true for members -of the Administrators group, but administrators can change the default permissions. If an -administrator accesses the password history they might be able to extract the hashes for cracking, -but they can't extract the passwords directly because the password history doesn't contain any -passwords. - -:::warning -The password history of a local user account isn't automatically deleted when the user -account is deleted. If a local user account is deleted, then another local user account is created -on the same computer with the same username, the new user will inherit the deleted user's password -history. The default registry permissions stop users from accessing their own password history, so -it is difficult for the new user to use this information. They could try to guess the deleted user's -password during a password change to see if it is rejected by the History rule, but they would only -have a few attempts to guess correctly before the old hashes are overwritten with new hashes. The -user's current password is validated, and the Windows Minimum Age rule is enforced before the -password history is checked, so every compliant and incorrect password guessed will overwrite one -hash in the password history. This information applies only to local user accounts. The password -history for domain user accounts is deleted when users are deleted. - -::: diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/length_rule.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/length_rule.md deleted file mode 100644 index b92407557e..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/length_rule.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: "Length Rule" -description: "Length Rule" -sidebar_position: 80 ---- - -# Length Rule - -The Length rule rejects passwords that contain too few or too many characters. Longer passwords are -generally stronger, so only specify a maximum password length if password compatibility must be -maintained with a system that can't accept long passwords. - -![Length rule](/images/passwordpolicyenforcer/11.1/administration/length.webp) - -Select the **Length** checkbox to enable the Length rule. - -Select one of the options: - -**At least** specifies the minimum number of characters that passwords must contain. Choose the -minimum number of characters from the dropdown list. - -**No more than** specifies the maximum number of characters that passwords can contain. Choose the -maximum number of characters from the dropdown list. - -**Between** specifies the minimum and maximum number of characters that passwords can contain. -Choose the minimum number of characters from the first dropdown list, and the maximum from the -second drop- down list. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/maximum_age_rule.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/maximum_age_rule.md deleted file mode 100644 index fd74c3553d..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/maximum_age_rule.md +++ /dev/null @@ -1,117 +0,0 @@ ---- -title: "Age (Max) Rule" -description: "Age (Max) Rule" -sidebar_position: 10 ---- - -# Age (Max) Rule - -The Maximum Age rule forces users to change their passwords regularly. This decreases the likelihood -of an attacker discovering a password before it changes. This rule can only be enforced by domain -policies. - -![Maximum Age rule](/images/passwordpolicyenforcer/11.1/administration/agemax.webp) - -Select the **Age (Max)** checkbox to enable the Maximum Age rule. - -Choose a value from the first days dropdown list to specify how many days must elapse before -passwords expire. - -You can encourage users to choose longer passwords by extending the lifetime of their password if it -exceeds a certain length. To enable this feature, choose a higher value from the second days -dropdown list and a minimum length from the contains dropdown list. Passwords that contain the -required number of characters don't expire until the second (higher) days value. If both days -values are identical, then passwords will expire after the specified number of days, irrespective of -length. - -:::note -When the Maximum Age rule is configured to delay the expiry of longer passwords, it -creates an Active Directory security group called "PPE Extended Maximum Age Users". Password Policy -Enforcer uses this group to identify which users are eligible for a delayed password expiry. Users -are added and removed from the group automatically. You can move and rename this group, but don't -change the pre-Windows 2000 name. Contact Netwrix support if you must change the pre-Windows 2000 -name. Change a Password Policy Enforcer configuration setting (any setting) after moving or renaming -the group to trigger a cache update in Password Policy Enforcer. Password Policy Enforcer recreates -this group if you delete it. To stop creating a group, make the two days values equal in all -policies. -::: - - -Choose a value from the Mode dropdown list to specify how Password Policy Enforcer handles expired -passwords. The Standard mode forces all users with expired passwords to change their password during -logon. The Transitional modes force a percentage of users with expired passwords to change their -password during logon. The Warning mode warns users that their password has expired without forcing -them to change it. - -Use the Warning and Transitional modes to gradually introduce a new password policy. These modes -reduce the number of forced password changes, allowing the help desk to deal with any extra calls -relating to the new policy. Switch to the Standard mode after most users have had a chance to change -their password. - -It takes approximately 50 days for all users with expired passwords to be forced to change them in -the 2% Transitional mode (2% every day). The 5% Transitional mode reduces this to 20 days, and the -10% Transitional mode further reduces it to 10 days. The selection algorithm is randomized, so these -are estimates only. You must switch to the Standard mode to ensure that all old passwords will -expire. - -Users with expired passwords are always prompted to change their password, even in the Transitional -and Warning modes. Users can ignore the prompt to change their password unless they are being forced -to change it. - -:::note -The password expiry prompt is a Windows client feature, and is displayed even if the -Password Policy Client isn't installed. Windows clients display the prompt 5 days before passwords -expire by default. You can alter this behavior in the Windows Group Policy security settings. See -the -[Interactive logon: Prompt user to change password before expiration](https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/interactive-logon-prompt-user-to-change-password-before-expiration) -Microsoft article for additional information. -::: - - -Password Policy Enforcer expires passwords at 1:00 AM every day on the domain controller holding the -PDC emulator operations master role. It sets "User must change password at next logon" for users -whose password has expired, or is due to expire on that day. Password Policy Enforcer doesn't -expire passwords if the Maximum Age rule is in Warning mode, or for users with "Password never -expires" set in Active Directory. Some passwords won't expire immediately when the Maximum Age -rule is in a Transitional mode. - -### Set up Email - -Click the **Set up email** to configure the e-mail message options. - -Enter the name and email address you want to appear in the email's From field in the **From** text -box. The correct format is "Display Name" `` - -Enter the text for the email's Subject field in the **Subject** text box. - -Enter the body of the email in the large text box. The email is sent as plain text unless the body -includes the `` tag. If sending email as HTML, you must include the complete HTML document -starting with `` and ending with ``. If the body is too long to fit in the text box, -enter a path to a file like this: - -`file:C:\path\filename.ext` - -The path can contain environment variables like %SystemRoot%. Don't use quotes for long filenames -and don't include any other text. The Password Policy Enforcer Mailer will read the email body from -the specified file. - -The email's subject and body can contain various macros. Use these macros to personalize the email. - -| Macro | Replaced with | -| ------------------- | ------------------------------------- | -| [LOGON_NAME] | User's logon name | -| [FIRST_NAME] | User's first name | -| [LAST_NAME] | User's last name | -| [DAYS_TO_EXPIRY] | Days until password expires | -| [EXPIRY_DATE] | Expiry date in short format | -| [EXPIRY_DATE_LONG] | Expiry date in long format | -| [EXPIRY_DAY] | Expiry day (1 to 31) | -| [EXPIRY_DAY_NAME] | Expiry day (Monday, Tuesday, ...) | -| [EXPIRY_MONTH] | Expiry month (1 to 12) | -| [EXPIRY_MONTH_NAME] | Expiry month (January, February, ...) | -| [EXPIRY_YEAR] | Expiry year (2021, 2022, ...) | - -### Set up SMTP - -Opens the Notification settings. See the [Configuration Console](/docs/passwordpolicyenforcer/11.1/admin/configconsole.md) topic for -additional details. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/minimum_age_rule.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/minimum_age_rule.md deleted file mode 100644 index 2304ef85ad..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/minimum_age_rule.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: "Age (Min) Rule" -description: "Age (Min) Rule" -sidebar_position: 20 ---- - -# Age (Min) Rule - -The Minimum Age rule stops users from quickly cycling through a series of passwords to -evade the History and Similarity rules. This rule can only be enforced by domain policies. - -![Minimum age rule](/images/passwordpolicyenforcer/11.1/administration/agemin.webp) - -Select the **Age (Min)** checkbox to enable the Minimum Age rule. - -Select the number of days before a user can change their password. - -:::note -The Minimum Age rule is unique because users can't comply with it by choosing a different -password; they must wait until the required number of days has elapsed. The Password Policy Client -consequently handles rejections by this rule differently to other rules. Rather than displaying the -usual message components, the Password Policy Client only displays the Minimum Age rule's Reason -insert. See [Password Policy Client](/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/password_policy_client.md) topic for additional information. -The Rejection Reason template, macros, and inserts from other rules aren't displayed when a -password change is denied by the Minimum Age rule. -::: - - -The Minimum Age rule isn't enforced during policy testing, but the test log does show the user's -password age. A log entry is also added if the Minimum Age rule would have rejected the password -change. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/patterns.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/patterns.md deleted file mode 100644 index cec885b805..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/patterns.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "Patterns Rule" -description: "Patterns Rule" -sidebar_position: 90 ---- - -# Patterns Rule - -The Patterns rule rejects passwords that contain character patterns such as "abcde". Character -patterns weaken the password. - -![Patterns rule](/images/passwordpolicyenforcer/11.1/administration/patterns.webp) - -Select the **Patterns** checkbox to enable the Patterns rule. - -Select **Reject character patterns like "abcde"** to check for character patterns. - -Select **Character patterns** to set the patterns to apply. Default is both **English alphabet -(a-z)** and **Numbers (0-9)**. - -Select **Detect character substitution** if Password Policy Enforcer should reject passwords that -rely on character substitution to comply with this rule. - -Select **Detect words typed backwards** if Password Policy Enforcer should additionally test -passwords with their characters reversed. Enabling this analysis stops users from circumventing this -rule by reversing the order of characters in their password. For example, a user may enter "edcba" -instead of "abcde". - -Choose a value from the **Tolerance** dropdown list to specify the longest pattern that Password -Policy Enforcer allows before rejecting a password. For example, the password "password**wxyz**" -contains a four-character pattern (shown in bold type). Password Policy Enforcer rejects this -password if the tolerance is set to three (or lower), and accept it if the tolerance is set to four -(or higher). Choose the **Auto** value if passwords should be rejected if they only contain a -single, continuous, character pattern. For example, "abcde" would be rejected, but "abcdz" and -"abc123" wouldn't. - -Select **Reject keyboard patterns like "qwerty"** to check for keyboard patterns. - -Select **Keyboard layouts** to set the keyboard type. Default is **United States**. - -Select the type of keyboard pattern: **Horizontal**, **Vertical**, or **Horizontal and Vertical**. - -Select **Detect direction change** for entries that change direction. For example, **qweewq**. - -Select **Detect key repeat** for repeated keys, based on the **Tolerance** value. If Tolerance is 4, -**aaaa** is accepted and **aaaaa** is rejected. - -Select **Detect key skip** for skipped keys, such as **qetuo**. - -Set **Tolerance** for the number of characters in a keyboard pattern is allowed before the password -is rejected. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/repetition.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/repetition.md deleted file mode 100644 index 59dd8f8f8f..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/repetition.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -title: "Repetition Rule" -description: "Repetition Rule" -sidebar_position: 100 ---- - -# Repetition Rule - -The Repetition rule rejects passwords that contain excessive character or pattern repetition. -Reducing repetition increase resistance to both brute-force and dictionary cracking algorithms. The -Repetition rule isn't case sensitive, so "mypaSssSword" contains four consecutive repeating -characters (SssS). - -![Repetition Rule](/images/passwordpolicyenforcer/11.1/administration/repetition.webp) - -Select the **Repetition** checkbox to enable the repetition rule. - -Select the **Reject repetition** option and set the maximum number of consecutive repeating -characters that passwords can contain. - -Select the **Reject repetition like "wordword" or "p@$s_p@$s"** option to enable pattern repetition. - -Select **Detect character substitution** if Password Policy Enforcer should reject passwords that -rely on character substitution to comply with this rule. - -Select **Detect words typed backwards** if Password Policy Enforcer should additionally test -passwords with their characters reversed. Enabling this analysis stops users from circumventing this -rule by reversing the order of characters in their password. For example, a user may enter "edcba" -instead of "abcde". - -Choose a value from the **Tolerance** dropdown list to specify the longest pattern that Password -Policy Enforcer allows before rejecting a password. For example, the password "password**wxyz**" -contains a four-character pattern (shown in bold type). Password Policy Enforcer rejects this -password if the tolerance is set to three (or lower), and accept it if the tolerance is set to four -(or higher). Choose the **Auto** value if passwords should be rejected if they only contain a -single, continuous, character pattern. For example, "abcde" would be rejected, but "abcdz" and -"abc123" wouldn't. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/rules.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/rules.md deleted file mode 100644 index 18343ceda6..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/rules.md +++ /dev/null @@ -1,258 +0,0 @@ ---- -title: "Rules" -description: "Rules" -sidebar_position: 10 ---- - -# Rules - -Netwrix Password Policy Enforcer uses rules to decide if it should accept or reject a password. Each -policy has rules that are configured independently of the rules in other policies. To display the -rules for a policy: - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -**Step 2 –** Click a policy name to open the policy configuration page. - -The **Rules** tab opens by default. A check mark beside a rule indicates that the rule is enabled -(being enforced). Click a rule to set the rule's properties. - -![Enabled rules are checked](/images/passwordpolicyenforcer/11.1/administration/enabledrules.webp) - -Review the sections on **Detecting Character Substitution** and **Tolerance** before setting up -the rules for your policy. - -You can **Save** each rule and use **Test Policy** as you are setting your rules. Turn on **Verbose -logging** on the **Test Policy** window to see which rules you have tested. - -Rules: - -- [Age (Max) Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/maximum_age_rule.md) -- [Age (Min) Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/minimum_age_rule.md) -- [Characters (Complexity) Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/complexity_rule.md) -- [Character (Granular) Rules](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/character_rules.md) -- [Compromised Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/compromised_rule.md) -- [Dictionary Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/dictionary_rule.md) -- [History Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/history_rule.md) -- [Length Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/length_rule.md) -- [Patterns Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/patterns.md) -- [Repetition Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/repetition.md) -- [Similarity Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/similarity_rule.md) -- [Unique Characters Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/unique_characters.md) - -## Detecting Character Substitution - -Character substitution is a technique used by some users to improve password quality. They replace -some alphabetic characters with non-alphabetic characters that have a similar appearance. For -example, "sold" becomes "$old". Many of these substitutions are well known and do little to improve -password strength. - -Some Password Policy Enforcer rules have a Detect Character Substitution checkbox. When this check -box is selected, Password Policy Enforcer tests passwords with, and without character substitution. -This stops users from circumventing the rule by substituting some characters. Password Policy -Enforcer detects these common character substitutions: - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Original - - Substituted -
- A - - a - - ^ @ -
- B - - b - - 8 -
- C - - c - - - - - - - - - -
- ( or { - <[
-
- D - - d - - - - - - - - - -
- ) or } - >]
-
- E - - e - - 3 -
- G - - g - - 6 or 9 -
- I - - i - - - - - - - - -
- ! or | -   1
-
- O - - o - - 0 or (zero) -
- S - - s - -

$ or 5

-
- T - - t - - + or 7 -
- Z - - z - - 2 -
- - -## Tolerance - -Some Password Policy Enforcer rules have a Tolerance dropdown list. Use it to control how strictly the rule is enforced. Tolerance is normally expressed as the maximum allowable number of -consecutive matching characters in the password and some other parameter. Password Policy Enforcer -rejects a password if the specified tolerance is exceeded. For example, the logon name -"mary**jones**", and the password "**Jones**town" contain five consecutive matching characters -(shown in bold type). Password Policy Enforcer rejects this password if the tolerance for the -User Logon Name rule is four or lower, and accepts it if the tolerance is five or higher. - -The User Logon Name, User Display Name, Similarity, and Character Patter rules have an Auto -tolerance option. Setting the tolerance to Auto instructs Password Policy Enforcer to only reject -passwords that contain the entire parameter being compared. This is very useful when the length of -the comparison parameter is unknown. For example, if you want Password Policy Enforcer to reject -passwords that contain the user's entire logon name, then you can't specify a fixed tolerance -unless all logon names have the same length. Setting the tolerance to Auto allows Password Policy -Enforcer to calculate an appropriate tolerance during every password change. - -Password Policy Enforcer sets the tolerance to the length of the comparison parameter minus one. The -following table shows some parameter values and the calculated tolerance. Password Policy Enforcer -rejects a password if it contains all the text in the Value column (or a derivative of it if -character substitution detection or bi-directional analysis is enabled). - -| Rule | Parameter | Value | Tolerance | -| ----------------- | ----------------- | ---------- | --------- | -| User Logon Name | Logon name | maryjones | 8 | -| User Display Name | Display name | Mary Jones | 9 | -| Similarity | Current password | oldpass | 6 | -| Character Pattern | Character pattern | abcdefgh | 7 | - -Password Policy Enforcer's Auto tolerance calculation has a minimum limit to stop passwords from -being rejected when the comparison parameter is very short. The limit is set to two characters by -default, so Password Policy Enforcer accepts passwords that contain the parameter value if the -comparison parameter only contains one or two characters. Contact Netwrix support if you need to -change the minimum limit. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/similarity_rule.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/similarity_rule.md deleted file mode 100644 index 2ebce879c3..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/similarity_rule.md +++ /dev/null @@ -1,39 +0,0 @@ ---- -title: "Similarity Rule" -description: "Similarity Rule" -sidebar_position: 110 ---- - -# Similarity Rule - -The Similarity rule rejects passwords that are similar to a user's current password. Password -similarity may indicate that a user is serializing their passwords. For example, "password1", -"password2", "password3". Password serialization allows an attacker to guess the new password. - -![Similarity Rule](/images/passwordpolicyenforcer/11.1/administration/similarity.webp) - -Select the **Similarity** checkbox to enable the Similarity rule. - -Select **Current password** to apply the similarity rules the user's existing password. The Password -Policy Enforcer client must be installed on the user's machine to enforce this rule. - -Select **User display name** to reject passwords that are similar to a user's Active Directory -display name (full name for local accounts). - -Select **User logon name** to reject passwords that are similar to a user's logon name (user name). - -For each option enabled, set the rules: - -Set **Character substitution** to **Yes** to reject passwords that rely on character substitution to -comply with this rule. - -Set **Words typed backward** to **Yes** to additionally test passwords with their characters -reversed. Enabling bi-directional analysis stops users from circumventing this rule by reversing the -order of characters in their password. For example, a user may enter "drowssapdloym" instead of -"myoldpassword". - -Set a **Tolerance** value to specify the maximum number of matching characters that Password Policy -Enforcer allows before rejecting a password. For example, the two passwords "old**passwd**" and -"new**passwd**" contain six consecutive matching characters (shown in bold type). Password Policy -Enforcer rejects the new password if the tolerance is five (or lower), and accepts it if the -tolerance is six (or higher). diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/unique_characters.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/unique_characters.md deleted file mode 100644 index f974db48ab..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/unique_characters.md +++ /dev/null @@ -1,20 +0,0 @@ ---- -title: "Unique Characters Rule" -description: "Unique Characters Rule" -sidebar_position: 120 ---- - -# Unique Characters Rule - -The Unique Characters rule rejects passwords that don't contain a minimum number of unique -characters. For example, the password "aaaaaaaa" only contains one unique character (a), whereas -"mypassword" contains nine unique characters (mypasword). Increasing the number of unique characters -in a password increases password strength by avoiding repetitive sequences. -The Unique Characters rule is case sensitive, so "LoOpHole" contains seven unique characters -(LoOpHle). - -![Unique characters rule](/images/passwordpolicyenforcer/11.1/administration/unique.webp) - -Select the **Unique characters** checkbox to enable the Unique Characters rule. - -Select the minimum number of unique characters that passwords must contain from the dropdown list. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/usersgroups.md b/docs/passwordpolicyenforcer/11.1/admin/manage-policies/usersgroups.md deleted file mode 100644 index 075e4de89d..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/usersgroups.md +++ /dev/null @@ -1,85 +0,0 @@ ---- -title: "Assign Policies to Users & Groups" -description: "Assign Policies to Users & Groups" -sidebar_position: 20 ---- - -# Assign Policies to Users & Groups - -Password Policy Enforcer uses policy assignments to decide which policy to enforce for each user. -Domain policies can be assigned to users, groups, and containers (Organizational Units). Local -policies can only be assigned to users. See the -[Domain and Local Policies](/docs/passwordpolicyenforcer/11.1/installation/domain_and_local_policies.md) topic for additional information. - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -**Step 2 –** Click a policy name to open the policy configuration page. - -**Step 3 –** Open the **Users & Groups** tab. - -![Assign policies to Users and Groups](/images/passwordpolicyenforcer/11.1/administration/usersandgroups.webp) - -When a domain policy is assigned to a user or group, Password Policy Enforcer stores the user or -group SID in the configuration. The assignment remains valid even if the user or group is renamed. -When a local policy is assigned to a user, Password Policy Enforcer stores the username in the -configuration. The assignment is invalidated if the user is renamed. - -When a policy is assigned to a group, Password Policy Enforcer enforces the policy for all members -of the group as well as any nested groups. For example, if the Helpdesk group is a member of the -Info Tech group, then any policy assigned to the Info Tech group also applies to the members of the -Helpdesk group. If this behavior isn't desired, then you can assign a different policy to the -Helpdesk group. - -When a policy is assigned to a container, Password Policy Enforcer enforces the policy for all users -in the container as well as any child containers. For example, if the Helpdesk and Managers OUs are -children of the Info Tech OU, then any policy assigned to the Info Tech OU also applies to the two -child OUs. If this behavior isn't desired, then you can assign a different policy to a child OU. - -![managing_policies_3](/images/passwordpolicyenforcer/11.1/administration/managing_policies_3.webp) - -:::note -You can use different assignment types for a single policy. For example, you may assign -users to a policy by both OU and group at the same time. -::: - - -As you assign users and groups to the policy, they are displayed on the page. - -![Policy assignments](/images/passwordpolicyenforcer/11.1/administration/usersandgroups2.webp) - -To remove a policy assignment: - -**Step 1 –** Select the user, group, or container. For example, **Administrators** under **Groups**. - -**Step 2 –** Click the trash can icon in the appropriate header. For example, **Groups**. - -## Policy Assignment Conflicts - -A policy assignment conflict occurs when more than one policy is assigned to a user. Password Policy -Enforcer can resolve these conflicts and choose one policy for each user. - -Password Policy Enforcer first tries to resolve a policy assignment conflict by examining the -assignment type. Assignments by user take precedence over assignments by group, which in turn take -precedence over assignments by container. For example, if Policy A is assigned to a user by group, -and Policy B is assigned to the same user by container, then Password Policy Enforcer enforces -Policy A because assignments by group take precedence over assignments by container. - -If all the policies are assigned to the user by container, then Password Policy Enforcer enforces -the policy that is assigned to the nearest parent container. For example, if Policy A is assigned to -the Users OU, and Policy B is assigned to the Users\Students OU, then Password Policy Enforcer -enforces Policy B for all users in the Users\Students and Users\Students\Science OUs because it is -the policy assigned to the nearest parent container. - -If a policy assignment conflict still exists, then Password Policy Enforcer checks the priority of -each remaining policy, and enforces the policy with the highest priority. See the -[Policy Selection Flowchart](manage_policies.md#policy-selection-flowchart) topic for a diagrammatic -representation of this algorithm. - -Click **Test Policy** and expand the **View log** to see which policy Password Policy Enforcer -enforces for a particular user. - -![Expand View log under Test to see which policy is enforced](/images/passwordpolicyenforcer/11.1/administration/testviewlog.webp) diff --git a/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/_category_.json b/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/_category_.json deleted file mode 100644 index 7194f80dac..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Password Policy Client", - "position": 50, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "password_policy_client" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/configuring_the_password_policy_client.md b/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/configuring_the_password_policy_client.md deleted file mode 100644 index 9d28023595..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/configuring_the_password_policy_client.md +++ /dev/null @@ -1,108 +0,0 @@ ---- -title: "Configuring the Password Policy Client" -description: "Configuring the Password Policy Client" -sidebar_position: 10 ---- - -# Configuring the Password Policy Client - -The Password Policy Client is self-configuring and doesn't require manual configuration in most -cases. See the [Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.1/installation/installationclient.md) topic for -additional details. You may need to manually configure the Password Policy Client if: - -- You want to install it in a disabled state to be enabled later. -- You want to change the display settings for small screens. -- Password Policy Client displays policy messages in the wrong language. -- Default communication settings aren't suitable (for example, if you change the default Password - Policy Server Port). - -Password Policy Enforcer includes an administrative template to help configure the Password Policy -Client. You can use Active Directory GPOs to configure many computers, or the Local Group Policy -Editor to configure one computer. The Password Policy Client configuration is stored in the -HKLM\SOFTWARE\Policies\ANIXIS\Password Policy Client\ registry key. - -**Install the Password Policy Client Administrative Template** - -**Step 1 –** Connect to any Domain Controller where you have Password Policy Enforcer installed and -have the group policy management console available. - -**Step 2 –** Go to Password Policy Enforcer install directory (C:\Program Files\Netwrix\Password -Policy Enforcer) and copy the **PPEClt.adml** and **PPEClt.admx** files (highlighted in yellow): - -![ppc_configuration](/images/passwordpolicyenforcer/11.1/administration/ppc_configuration.webp) - -**Step 3 –** Go to C:\Windows\Policy Definitions and paste the .admx file in the root of this -folder. - -![ppc_configuration2](/images/passwordpolicyenforcer/11.1/administration/ppc_configuration2.webp) - -**Step 4 –** Go to C:\Windows\Policy Definitions\en-US and paste the .adml file in the root of this -folder. - -![ppc_configuration1](/images/passwordpolicyenforcer/11.1/administration/ppc_configuration1.webp) - -**Step 5 –** Open **Group Policy Management** console and check if you have a GPO created for -Client. If not, see the topic's section for additional information. - -**Step 6 –** In the left pane, navigate to **Forest: ``** > **Domain** > -**``**, right-click **``** and select **Create a GPO** in this domain and Link -it here. - -After the GPO is configured, this view is available: - -![ppc_configuration3](/images/passwordpolicyenforcer/11.1/administration/ppc_configuration3.webp) - -**Step 7 –** Right-click the newly created GPO and select **Edit** from the pop-up menu. - -**Step 8 –** Expand **Computer Configuration** > **Policies** > **Administrative Templates** > -**Netwrix Password Policy Enforcer** - -![ppc_configuration4](/images/passwordpolicyenforcer/11.1/administration/ppc_configuration4.webp) - -**Step 9 –** Click **Netwrix Password Policy Client** to open a list of modification settings. - -![ppc_configuration5](/images/passwordpolicyenforcer/11.1/administration/ppc_configuration5.webp) - -**Step 10 –** Select the one you need, then modify and save it. - -## Changing the Default Display Settings - -The Windows 10 and 11 Change Password screen has less space for the Password Policy message than -earlier Windows versions. Users may need to scroll to see the message if their screen is small, or -if their computer is set to use large fonts. - -The Password Policy Client for Windows 10 and 11 maximizes the available screen space by hiding -non-essential user interface elements on small screens. It can also display the Password Policy -message in a message box to draw attention to the password policy. - -![the_password_policy_client_3](/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client_3.webp) - -You can change the default display settings to control which user interface elements are hidden, and -the point at which they are hidden. The display of the Password Policy message box is also -configurable. - -Follow the steps to change the default display settings for the Password Policy Client on -Windows 10 and 11. - -**Step 1 –** Use the **Group Policy Management Console** (gpmc.msc) to display the GPOs linked at -the domain level. - -:::note -If you aren't using Active Directory, then open the Local Group Policy Editor -(**gpedit.msc**) and skip step 2. -::: - - -**Step 2 –** Right-click the **Password Policy Client GPO**, then click the **Edit...** button. - -**Step 3 –** Expand the **Computer Configuration**, **Policies** (if visible), **Administrative -Templates**, **Classic Administrative Templates** (**ADM**), **Password Policy Enforcer**, and -**Password Policy Client** items. - -**Step 4 –** Double-click the **Display settings (Windows 10)** setting in the right pane of the -Group Policy Management Editor. - -:::note -Information about each option is shown in the Help box. - -::: diff --git a/docs/passwordpolicyenforcer/11.1/admin/systemaudit.md b/docs/passwordpolicyenforcer/11.1/admin/systemaudit.md deleted file mode 100644 index 0a7ff6f935..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/systemaudit.md +++ /dev/null @@ -1,85 +0,0 @@ ---- -title: "System Audit and Support" -description: "System Audit and Support" -sidebar_position: 40 ---- - -# System Audit and Support - -Password Policy Enforcer can run a discovery and testing of your domain controllers for an overview -on PPE health, versions, and logs. - -Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -Click the **System Audit and Support** tile on the Configuration Console dashboard. This feature is -only available when **domain** is selected with the [Connected To](configconsole.md#connected-to) -configuration setting. System Audit and Support opens on the **Version Tracker** tab. - -## Version Tracker - -![System Audit and Support Version Tracker tab](/images/passwordpolicyenforcer/11.1/administration/systemaudit.webp) - -Click **Run test**. The audit reports the discovered domain controllers and versions. - -:::note -If you don't see the **Configuration Timestamp**, contact your network administrator to -set up the firewall to allow Password Policy Enforcer to communicate. -::: - - -![System Audit results](/images/passwordpolicyenforcer/11.1/administration/systemauditversion.webp) - -You can click the export icon to download your results. The file name is -**Audit\_\_**timestamp**\_.xlxs**, it is downloaded into the default **Downloads** folder. For large -domains, you can apply filters or use the Search feature to make it easier to navigate your list. - -:::note -**Debug logging** should only be enabled when you are actively debugging your system. -Leaving it enabled impacts Password Policy Enforcer performance and uses free disk space to create -the logs. -::: - - -## Support Tools - -Use the **Support Tools** tab to save a configuration report, export/import PPE settings, -and open the property editor. - -![System Audit Support Tools tab](/images/passwordpolicyenforcer/11.1/administration/systemaudittools.webp) - -- **Policies Configuration Report** saves the configuration as a text file. Browse to the folder - where you want the report. The default filename is **PPEConfig.txt**. -- **PPE Settings** export your PPE settings for a backup. You can import the settings to replicate - configurations across systems. - - **Export** exports the PPE settings to an xml file. Browse to the folder where you want the - file. The default filename is **PPEExport.xml**. - - Import imports the settings from an exported xml PPE Settings file. Browse to the location of - the **PPEExport.xml** file. Click **Open**. A status message is displayed when complete. -- **Open Property Editor** launches the Property Editor. - - :::note - Properties should only be changed when advised by Netwrix Support. - ::: - - -### Property Editor - -The Property Editor lets you edit the Password Policy Enforcer configuration. It should only -be used instructed by Netwrix Support. It is accessed from the Configuration Console: - -**Help** > **Open Property Editor** - -**or** - -**System Audit and Support** > **Support Tools** > **Open editor** - -![Property Editor](/images/passwordpolicyenforcer/11.1/administration/propertyeditor.webp) - -- **Policy**: select the policy to edit. -- **Property**: select the property to change. -- **Property ID**: enter the ID supplied by Netwrix Support. -- **Value**: enter the new value supplied by Netwrix Support. Click **Set value**. diff --git a/docs/passwordpolicyenforcer/11.1/admin/troubleshooting.md b/docs/passwordpolicyenforcer/11.1/admin/troubleshooting.md deleted file mode 100644 index c449a9868e..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/troubleshooting.md +++ /dev/null @@ -1,81 +0,0 @@ ---- -title: "Troubleshooting" -description: "Troubleshooting" -sidebar_position: 90 ---- - -# Troubleshooting - -This topic contains troubleshooting information for the most common support questions. Contact -Netwrix support with any questions. - -Password policy assigned to some users is being enforced for all users. Check the Default Policy in -the PPS Properties page. Users must comply with the default policy if no other policy is assigned to -them. Select the first (blank) item in the dropdown list if you don't want a default policy. - -#### Password policy not displayed during password change - -Open the Programs and Features list in Control Panel on the computer you are changing the password -from, and check if the Password Policy Client is in the list of installed programs. If it isn't, -then install the Password Policy Client. See the [Password Policy Client](/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/password_policy_client.md) -topic for additional information. - -If Password Policy Enforcer is enforcing a domain policy, then search the Windows Application Event -Log on every domain controller for events from Password Policy Enforcer. If there are no events from -Password Policy Enforcer since the last restart on any domain controller, then ensure that -Password Policy Enforcer is installed on that domain controller and restart it. Check the Windows -Application Event Log again after the restart to ensure that Password Policy Enforcer started. For -local policies, search the Application Event Log on the local computer. - -If there is a firewall between the client computer and the domain controllers (including Windows -Firewall), then you must create firewall rules to allow the Password Policy Client and Password -Policy Server to communicate. Windows firewall is enabled by default on Windows Server 2008 and -later. - -Use the Test Policies page to test a password for the user. Click the **Log** tab to see if a -password policy is assigned to the user. - -Ensure that the Password Policy Server is enabled. - -Ensure that the Password Policy Client is enabled. See -[Password Policy Client](/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/password_policy_client.md) topic for additional information. - -#### Accepting passwords that don't comply with the policy - -If Password Policy Enforcer is enforcing a domain policy, then search the Windows Application Event -Log on every domain controller for events from Password Policy Enforcer. If there are no events from -Password Policy Enforcer since the last restart on any domain controller, then ensure that -Password Policy Enforcer is installed on that domain controller and restart it. Check the Windows -Application Event Log again after the restart to ensure that Password Policy Enforcer started. For -local policies, search the Application Event Log on the local computer. - -Use the Test Policies page to test a password that Password Policy Enforcer is accepting. Examine -the test results and event log to determine why Password Policy Enforcer accepted the password. If -the Test Policies page rejects the password, you must configure the policy. See the -[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) topic for -additional information. - -If the **Enforce policy when password is reset** checkbox isn't selected in the PPS Properties -page, then Password Policy Enforcer won't enforce the password policy for passwords that are -reset from the Active Directory Users and Computers console, or the Local Users and Groups console. -You should select this option during testing, or test password changes from the Windows Change -Password screen. - -#### Rejecting passwords that comply with the policy - -Use the Test Policies page to test a password that Password Policy Enforcer is rejecting. Examine -the test results and event log to determine why Password Policy Enforcer rejected the password. If -the Test Policies page rejects the password, you must configure the policy. See the -[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) topic for -additional information. - -Set **User must change password at next logon** for the user and repeat the password change test. If -the password is accepted, then either Windows or Password Policy Enforcer is configured to enforce a -minimum password age. Disable the Minimum Age rule in Windows and Password Policy Enforcer to -facilitate testing. If you can't disable the Minimum Age rule, then set User must change password -at next logon before every password change test to bypass the rule. - -#### Passwords that are accepted in the Test Policies page are rejected during a password change - -See the [Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) -topic for additional information. diff --git a/docs/passwordpolicyenforcer/11.1/admin/windowseventviewer.md b/docs/passwordpolicyenforcer/11.1/admin/windowseventviewer.md deleted file mode 100644 index 5d6cca5d42..0000000000 --- a/docs/passwordpolicyenforcer/11.1/admin/windowseventviewer.md +++ /dev/null @@ -1,26 +0,0 @@ ---- -title: "View Event Logs in Windows Event Viewer" -description: "View Event Logs in Windows Event Viewer" -sidebar_position: 100 ---- - -# View Event Logs in Windows Event Viewer - -**Step 1 –** Open **Windows Event Viewer**. - -![View Event Logs](/images/passwordpolicyenforcer/11.1/administration/vieweventlogs.webp) - -**Step 2 –** Navigate to **Windows Logs** > **Application**. - -**Step 3 –** In the Application list, select a Netwrix Password Policy Enforcer event under the -Source column. - -The General tab shows details for the selected event. The Details tab shows... - -## View Log Properties - -To view Log Properties, navigate to the Actions menu and select **Properties**. - -![Log Properties Window](/images/passwordpolicyenforcer/11.1/administration/vieweventlogslogproperties.webp) - -The Log Properties window displays. Configure settings for this log from this window. diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/_category_.json b/docs/passwordpolicyenforcer/11.1/evaluation/_category_.json deleted file mode 100644 index 8ccf8e8f97..0000000000 --- a/docs/passwordpolicyenforcer/11.1/evaluation/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Evaluate Password Policy Enforcer", - "position": 50, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "evaluation_overview" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/creating-a-password-policy/_category_.json b/docs/passwordpolicyenforcer/11.1/evaluation/creating-a-password-policy/_category_.json deleted file mode 100644 index b944d1d256..0000000000 --- a/docs/passwordpolicyenforcer/11.1/evaluation/creating-a-password-policy/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Create a Password Policy", - "position": 30, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "creating_a_password_policy" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/creating-a-password-policy/creating_a_password_policy.md b/docs/passwordpolicyenforcer/11.1/evaluation/creating-a-password-policy/creating_a_password_policy.md deleted file mode 100644 index 529c756543..0000000000 --- a/docs/passwordpolicyenforcer/11.1/evaluation/creating-a-password-policy/creating_a_password_policy.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "Create a Password Policy" -description: "Create a Password Policy" -sidebar_position: 30 ---- - -# Create a Password Policy - -Password Policy Enforcer has no password policies defined when first installed. You can now -create your first Password Policy Enforcer password policy. Password Policy Enforcer accepts all -passwords in this state, so users only need to comply with the Windows password policy rules (if -enabled). - -**Step 1 –** Open the Configuration Console: - -Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** -or -Double click the **PPE Configuration** desktop shortcut. - -![Configuration Console Dashboard](/images/passwordpolicyenforcer/11.1/evaluation/ppedashboard.webp) - -The Configuration Console dashboard shows **No password policies have been set up** when you are -getting started with Password Policy Enforcer. - -**Step 2 –** Click **Add policy**. - -**Step 3 –** Enter a unique policy name. Maximum is 32 characters. **Eval Policy** is used for this -example. - -**Step 4 –** Select a Policy template or **None** if you are creating your own. For a list of -policies see [Policy Templates ](/docs/passwordpolicyenforcer/11.1/evaluation/creating-a-password-policy/policy_templates.md). - -**Step 5 –** Click **Create policy**. - -Password Policy Enforcer creates the policy and opens the policy settings, showing the first item on the **Rules** tab. - -![New policy open for settings](/images/passwordpolicyenforcer/11.1/evaluation/newpolicysettings.webp) - -**Step 6 –** Click the context menu (beside the policy name and select **Make default**. - -![Make the policy the default](/images/passwordpolicyenforcer/11.1/evaluation/evaldefault.webp) diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/creating-a-password-policy/policy_templates.md b/docs/passwordpolicyenforcer/11.1/evaluation/creating-a-password-policy/policy_templates.md deleted file mode 100644 index 04045959ca..0000000000 --- a/docs/passwordpolicyenforcer/11.1/evaluation/creating-a-password-policy/policy_templates.md +++ /dev/null @@ -1,48 +0,0 @@ ---- -title: "Policy Templates" -description: "Policy Templates" -sidebar_position: 10 ---- - -# Policy Templates - -Password Policy Enforcer contains Built-in Policy Templates based on the requirements of the -most popular regulatory frameworks. - -- Center for Internet Security (CIS) Password Policy Guide – See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- Center for Internet Security (CIS) Password Policy Guide MFA – See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- Cybersecurity Information Sharing Act (CISA) -- Criminal Justice Information Services (CJIS) Security Policy -- Cybersecurity Maturity Model Certification (CMMC) -- Defense Federal Acquisition Regulation Supplement (DFARS) -- Gramm-Leach-Bliley Act (FedRAMP) -- Federal Information Security Management Act (FISMA) -- Health Insurance Portability and Accountability Act (HIPPA) – HIPAA Security Rule requires that - organizations must implement procedures for creating, changing, and safeguarding passwords. - - - It also recommends training the workforce on ways to safeguard password information and - establish guidelines to create and change passwords in a periodic cycle. - - HIPAA doesn’t offer any specific password complexity guidelines. To comply with HIPAA, - organizations are better off following NIST password guidelines. - - Most of healthcare institutions use the NIST framework. - -- International Organization for Standardization (ISO/IEC) 27002 – See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. -- North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) – - See the - [CIP-007-6 — Cyber Security – Systems Security Management](https://www.nerc.com/_layouts/15/PrintStandard.aspx?standardnumber=CIP-007-6&title=Cyber%20Security%20-%20System%20Security%20Management&Jurisdiction=United%20States) article - for additional information. -- National Institute of Standards and Technology (NIST) Special Publication 800-171 -- National Institute of Standards and Technology (NIST) Special Publication 800-53 -- National Institute of Standards and Technology (NIST) Special Publication 800-63b – See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. -- Payment Card Industry Data Security Standard (PCI DSS) – See the - [PCI Document Library](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss) web - site for additional information. -- Payment Card Industry Data Security Standard (PCI DSS) (version 4) diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/enforcing_multiple_policies.md b/docs/passwordpolicyenforcer/11.1/evaluation/enforcing_multiple_policies.md deleted file mode 100644 index 56e33d4184..0000000000 --- a/docs/passwordpolicyenforcer/11.1/evaluation/enforcing_multiple_policies.md +++ /dev/null @@ -1,78 +0,0 @@ ---- -title: "Enforce Multiple Policies" -description: "Enforce Multiple Policies" -sidebar_position: 70 ---- - -# Enforce Multiple Policies - -Password Policy Enforcer can enforce up to 256 password policies on each domain or computer. You can -assign policies to users directly, or indirectly through Active Directory security groups and -containers (Organizational Units). - -### Create Additional Password Policy - -If you are in the settings for your first policy, click the left arrow beside the policy name to -return to the Configuration Console dashboard. - -![Return to the dashboard](/images/passwordpolicyenforcer/11.1/evaluation/evaldashboard.webp) - -Create an additional password policy. - -**Step 1 –** Click the context menu beside your first policy and select **Make copy**. - -**Step 2 –** Enter **Admins Policy** for the Policy duplication. - -![Enter Admins Policy](/images/passwordpolicyenforcer/11.1/evaluation/evalcopypolicy2.webp) - -**Step 3 –** Click **Make copy**. - -**Step 4 –** Open the **Users & Groups** tab. - -![Open the Users & Groups tab](/images/passwordpolicyenforcer/11.1/evaluation/evalusergroups.webp) - -**Step 5 –** Click the **+** in the **Groups** list and enter **Domain Admins**. Specify a Domain or -local **Location** depending on your evaluation set up. - -**Step 6 –** Click **OK**. Domain Admins are added to the **Groups**. - -![Domain Admins added](/images/passwordpolicyenforcer/11.1/evaluation/evaldomainadmins.webp) - -- Members of the Domain Admins group (or the PPETestAdmin user, if not using a domain controller) - must now comply with the Administrators policy. All other users must comply with the Users policy. - Users won't notice any difference at this point because the two polices are enforcing identical - rules. - -### Differentiate Password Policies - -To differentiate the policies, change the minimum password length for the Admins policy from seven -to nine characters. - -**Step 1 –** Open the **Rules** tab. - -**Step 2 –** Open the **Length** rule. - -**Step 3 –** Select **9** from the **At Least** dropdown list. - -![Set the length to 9](/images/passwordpolicyenforcer/11.1/evaluation/evallength9.webp) - -**Step 4 –** Click **Save**. - -**Step 5 –** Click **Test policy**. - -**Step 6 –** Select the **PPETestAdmin** user. The results pane shows the **Admins Policy** is being -applied, and the password must **contain at least 9 characters**. - -![Admins policy is being tested](/images/passwordpolicyenforcer/11.1/evaluation/evaladmin.webp) - -Use the Password Policy Enforcer configuration console, the Windows Change Password screen, the -Active Directory Users and Computers console, or the Local Users and Groups console to test password -changes and resets for the **PPETestUser** and **PPETestAdmin** accounts. Password Policy Enforcer -should enforce the Eval policy for **PPETestUser**, and the Admins policy for **PPETestAdmin**. - -:::note -The [Set Priorities](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/manage_policies.md#set-priorities) topic contains -more information about policy assignments, and how Password Policy Enforcer resolves policy -assignment conflicts that occur when more than one policy is assigned to a user. - -::: diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/improving_the_password_policy.md b/docs/passwordpolicyenforcer/11.1/evaluation/improving_the_password_policy.md deleted file mode 100644 index dd28ab0ef7..0000000000 --- a/docs/passwordpolicyenforcer/11.1/evaluation/improving_the_password_policy.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Improve the Password Policy" -description: "Improve the Password Policy" -sidebar_position: 60 ---- - -# Improve the Password Policy - -Password Policy Enforcer rules have properties that control how rules are enforced. You can improve -the effectiveness of the Users policy by enabling character substitution detection and -bi-directional analysis (words typed backwards) for the **Similarity** and **Dictionary** rules. - -When character substitution detection is enabled, Password Policy Enforcer searches passwords for -common character substitutions. For example, an S replaced with a $. If a password only complies -with the policy because of the substitution ( the substitution is needed to make the password -compliant), then Password Policy Enforcer rejects the password. - -Bi-directional analysis tests passwords with their characters reversed to stop users from -circumventing a rule by entering a non-compliant password backwards. For example, "drowssapym" -instead of "mypassword". - -Click your policy name on the Configuration Console dashboard if needed. - -**Step 1 –** Open the **Dictionary** rule. - -![Open the Dictionary rule](/images/passwordpolicyenforcer/11.1/evaluation/evaldict.webp) - -**Step 2 –** Select the **Detect character substitution** and **Detect words typed backwards** check -boxes. - -**Step 3 –** Open the **Similarity** rule. - -**Step 4 –** For **User logon name** select **Yes** for **Character substitution** and **Words typed -backwards**. - -**Step 5 –** Click **Save**. - -Test the improved policy with passwords that were accepted under the previous policy. Password -Policy Enforcer should reject all of them. - -| Password | Result | Reason | -| -------- | -------- | ---------------------------------- | -| tseTEPP | Rejected | Similar to user logon name | -| kravdraA | Rejected | Similar to word in dictionary file | -| Aardv@rk | Rejected | Similar to word in dictionary file | diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer.md b/docs/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer.md deleted file mode 100644 index bae7f42af7..0000000000 --- a/docs/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer.md +++ /dev/null @@ -1,62 +0,0 @@ ---- -title: "Prepare the Computer" -description: "Prepare the Computer" -sidebar_position: 10 ---- - -# Prepare the Computer - -You only need one computer for the evaluation. A Windows Server 2016, 2019, or 2022 domain -controller in its own domain is recommended. You can also use Windows 10 or 11 if you only need to -enforce policies for local accounts. - -## Disable the Windows Password Policy Rules - -If the Password Policy Enforcer and Windows password policies are both enabled, then users must -comply with both policies. This isn't recommended for the evaluation because the Windows policy may -stop users from reusing recent passwords, or from changing their password more than once a day. -These restrictions can make it difficult to evaluate Password Policy Enforcer. - -This procedure disables the Windows password policy: - -**Step 1 –** Open the appropriate policy management tool: - -- If you are evaluating Password Policy Enforcer on a domain, use the Group Policy Management - Console (**gmpc.msc**) to display the GPOs linked at the domain level. Right-click the **Default - Domain Policy GPO** (or whichever GPO you use to set the password policy), then click the - **Edit...** button. -- If you are evaluating Password Policy Enforcer on a standalone server or workstation, open the - **Local Group Policy Editor** (**gpedit.msc**). - -**Step 2 –** Expand the following items: - -- Computer Configuration -- Policies (if it exists) -- Windows Settings -- Security Settings -- Account Policies -- Password Policy - -**Step 3 –** Double-click **Enforce password history** in the right pane of the GPO Editor. - -**Step 4 –** Enter **0** in the text box, then click **OK**. - -**Step 5 –** Repeat the step above for the Maximum Password Age and Minimum Password Length -policies. - -**Step 6 –** Double-click the **Group Policy Management Editor**. - -**Step 7 –** Close the **Group Policy Management Editor**. - -![preparing_the_computer](/images/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer.webp) - -**Step 8 –** Execute the `gpupdate/target:computer` command to refresh the Group Policy. - -## Create Test Accounts - -Create two user accounts for the evaluation: **PPETestUser** and **PPETestAdmin**. - -![preparing_the_computer_1](/images/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer_1.webp) - -Make **PPETestAdmin** a member of the Domain Admins group if you are evaluating Password Policy -Enforcer on a domain controller. diff --git a/docs/passwordpolicyenforcer/11.1/gettingstarted.md b/docs/passwordpolicyenforcer/11.1/gettingstarted.md deleted file mode 100644 index 6e5660f875..0000000000 --- a/docs/passwordpolicyenforcer/11.1/gettingstarted.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Getting Started" -description: "Getting Started" -sidebar_position: 2 ---- - -# Getting Started - -Review the [Domain and Local Policies](/docs/passwordpolicyenforcer/11.1/installation/domain_and_local_policies.md) topic. - -## Install Products - -Install Password Policy Enforcer (PPE Server) on every domain controller to enforce the -password policy for domain user accounts, or on individual servers and workstations to enforce the -password policy for local user accounts. See the -[Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.1/installation/installationserver.md) or -[Install with Group Policy Management](/docs/passwordpolicyenforcer/11.1/installation/installationgpm.md) topics for additional -information. - -You can install the Configuration Console on whatever servers are convenient for you to access. It -is a selectable feature in the server installation **msi** package. See the -[Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.1/installation/installationserver.md) topic for additional -information. - -Install the Mailer Service on a single server in each domain. See the -[Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.1/installation/installationserver.md) topic for additional -information. - -Password Policy Enforcer client is optional, but recommended. Users receive immediate feedback when -setting up their passwords. This saves your users time and frustration when picking compliant -passwords. See the [Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.1/installation/installationclient.md) or -[Install with Group Policy Management](/docs/passwordpolicyenforcer/11.1/installation/installationgpm.md) topics for additional -information. - -Password Policy Enforcer Web is a separate product enabling users to change their Windows domain -password from a web browser. See the [Password Policy Enforcer Web](/docs/passwordpolicyenforcer/11.1/web-overview/web_overview.md) topic for -additional information. - -Create the **Compromised Passwords Base** before enabling the Compromised Password Check. See the -[HIBP Updater](/docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md) topic for additional information. - -## Exclude PPE Files from AntiVirus Checks - -**Domain Controller** - -**PPE.DLL** if this file doesn't load, PPE can't enforce the password policy. - -**Clients** - -**PPEClt.DLL** if this file doesn't load, the client doesn't run. - -## Next Steps - -You can work through the [Evaluate Password Policy Enforcer](/docs/passwordpolicyenforcer/11.1/evaluation/evaluation_overview.md). diff --git a/docs/passwordpolicyenforcer/11.1/index.md b/docs/passwordpolicyenforcer/11.1/index.md deleted file mode 100644 index c5dbfad8ee..0000000000 --- a/docs/passwordpolicyenforcer/11.1/index.md +++ /dev/null @@ -1,47 +0,0 @@ ---- -title: "Netwrix Password Policy Enforcer v11.1" -description: "Netwrix Password Policy Enforcer Introduction" -sidebar_position: 1 ---- - -# Netwrix Password Policy Enforcer v11.1 -Netwrix Password Policy Enforcer (PPE) helps you secure your network by ensuring users choose strong passwords. Password Policy Enforcer rejects new passwords that don't comply with your password policy. If you install the optional Password Policy Client, users can also see which rules their password didn't comply with. - -A typical Windows network has both domain and local user accounts. Password Policy Enforcer can enforce password policies for both account types, but you will most likely use it for domain accounts in Active Directory. - - -## System Requirements -- Windows Server 2016, 2019, 2022, and 2025 -- Windows 10 and 11 -- 50 megabytes free disk space -- 10 megabytes free RAM (75 megabytes if using [Argon2](admin/manage-policies/rules/history_rule.md) hashes) - -:::note -The disk space requirement doesn't include the compromised database. If you want to block known compromised passwords, then add 30 gigabytes of disk space. You can keep the database locally or on a network share. The initial download and extraction temporarily requires approximately 100 gigabytes. Subsequent updates are significantly smaller as they only contain new records. These estimates will increase over time as the database grows. -::: - - -## System Components - -### Password Policy Enforcer Server (PPS) -The PPS is the component that enforces the password policy. Install it on all the domain controllers to enforce a password policy for Active Directory user accounts. You can also install the PPS on individual servers and workstations to enforce a password policy for local user accounts on those computers. - -### Configuration Console -The Configuration Console configures PPE. You will typically install this on your own computer or a management server, but you can also install it on the domain controllers. The Configuration Console also includes some PowerShell cmdlets. Use of the cmdlets is optional. - -The Configuration Console has some additional requirements: -- [.NET Desktop Runtime 8.0.15 or later](https://dotnet.microsoft.com/en-us/download/dotnet/thank-you/runtime-desktop-8.0.26-windows-x64-installer?cid=getdotnetcore) -- [PowerShell 7.4 or later](https://github.com/powershell/powershell/releases) if you intend to use the cmdlets - -### Password Policy Enforcer Mailer Service -This component sends email from Password Policy Enforcer to your mail server. Although not required, this component supports several PPE features, so you'll most likely want to install it on one server in the domain. This component requires the [.NET Desktop Runtime 8.0.15 or later](https://dotnet.microsoft.com/en-us/download/dotnet/thank-you/runtime-desktop-8.0.26-windows-x64-installer?cid=getdotnetcore). - -### Password Policy Client -The Password Policy Client helps users to choose a compliant password by showing them the password policy rules, and also which rules they don't comply with. This component is optional, but very beneficial. It works on all operating systems listed in the System Requirements section, but you'll typically only install it on users' computers and virtual desktops. - -### Password Policy Enforcer Web -Password Policy Enforcer Web is an optional component that runs on Microsoft Internet Information Services (IIS). It has similar features to the Password Policy Client, but via a web interface. Use Password Policy Enforcer Web if you prefer not to install the Password Policy Client, or if you want to integrate Active Directory password changes into your own applications. - -:::note -The [Similarity rule](admin/manage-policies/rules/similarity_rule.md) only works when users change passwords from the Password Policy Client, Password Policy Enforcer Web, or Netwrix Password Reset. -::: diff --git a/docs/passwordpolicyenforcer/11.1/installation/_category_.json b/docs/passwordpolicyenforcer/11.1/installation/_category_.json deleted file mode 100644 index 0f6ac7ae2c..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/_category_.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "label": "Installation", - "position": 30, - "collapsed": true, - "collapsible": true -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.1/installation/disable_windows_rules.md b/docs/passwordpolicyenforcer/11.1/installation/disable_windows_rules.md deleted file mode 100644 index ebf1e18ee2..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/disable_windows_rules.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: "Disable Windows Rules" -description: "Disable Windows Rules" -sidebar_position: 80 ---- - -# Disable Windows Rules - -The Windows password policy rules can place restrictions on password history, age, length, and -complexity. If you enable the Password Policy Enforcer rules and the Windows rules, then users must -comply with both sets of rules. - -Password Policy Enforcer has its own history, minimum age, and maximum age, length, and complexity rules. -See the [Rules](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/rules.md) topic for additional information. You can use the Password Policy Enforcer -and Windows rules together. A password is only accepted if it complies with the Windows and Password -Policy Enforcer password policies. - -These steps disable the Windows password policy rules: - -**Step 1 –** Start the Group Policy Management Console **(gpmc.msc**). - -**Step 2 –** Expand the forest and domain items in the left pane. - -**Step 3 –** Right-click the **Default Domain Policy GPO** (or whichever GPO you use to set your -domain password policy), then click **Edit...** - -**Step 4 –** Expand the **Computer Configuration**, **Policies**, **Windows Settings**, **Security -Settings**, **Account Policies**, and **Password Policy** items. - -**Step 5 –** Double-click **Enforce password history** in the right pane of the GPO Editor. - -**Step 6 –** Enter **0** in the text box, then click **OK**. - -**Step 7 –** Repeat the step above for the **Maximum password age**, **Minimum password age**, and -**Minimum password length** policies. - -**Step 8 –** Double-click **Password must meet complexity requirements** in the right pane. - -**Step 9 –** Select the **Disabled** option, and then click **OK**. - -**Step 10 –** Close the Group Policy Management Editor. - -![installing_ppe_3](/images/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer.webp) - -:::note -You don't have to disable all the Windows password policy rules to use Password Policy -Enforcer. You can use a combination of Password Policy Enforcer and Windows rules together if you -like. Remember that a password is only accepted if it complies with the rules enforced by both -Windows and Password Policy Enforcer. - -::: diff --git a/docs/passwordpolicyenforcer/11.1/installation/domain_and_local_policies.md b/docs/passwordpolicyenforcer/11.1/installation/domain_and_local_policies.md deleted file mode 100644 index b4c234c748..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/domain_and_local_policies.md +++ /dev/null @@ -1,95 +0,0 @@ ---- -title: "Domain and Local Policies" -description: "Domain and Local Policies" -sidebar_position: 10 ---- - -# Domain and Local Policies - -Netwrix Password Policy Enforcer enforces password policies for both domain and local user accounts. - -Domain user accounts exist in Active Directory. The domain controllers store information about these accounts and replicate changes among themselves. - -Local user accounts exist in the SAM database of workstations and servers. The workstations and -servers may be standalone, or domain members. The host computer stores information about these accounts locally and doesn't replicate it to any other computers. - -A typical Windows network has both domain and local user accounts, but you may not want to enforce -Password Policy Enforcer password policies for both account types. If your users normally log on with -a domain account, then you will most likely only use Password Policy Enforcer to enforce password -policies for the domain accounts. - -## Installation Differences - -To enforce password policies for domain user accounts, you should install Password Policy Enforcer -onto all the domain controllers in the domain. If you have read-only domain controllers and aren't -using the [Rules](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/rules.md), [Password Policy Client](/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/password_policy_client.md), or other software -(such as -[Netwrix Password Reset](https://www.netwrix.com/active_directory_password_reset_tool.html)) that -uses the Password Policy Enforcer Client protocol, then you don't need to install Password Policy -Enforcer on the read-only domain controllers. - -To enforce password policies for local user accounts, you should install Password Policy Enforcer -onto the computers containing the user accounts you want to enforce password policies for. These -computers may be workstations or servers, and they may be standalone or domain members. You don't normally need to install Password Policy Enforcer onto all the workstations and servers in -a domain, because most domain users log on with a domain account. If this is the case, you -will most likely only need to install Password Policy Enforcer on the domain controllers. - -## Operational Differences - -Most of Password Policy Enforcer's rules and features work with both domain and local -policies, but there are some differences. When enforcing the password policy for domain accounts, -Password Policy Enforcer queries Active Directory to get information about the accounts. - -Although getting most of this information from the SAM database for local accounts is theoretically possible, a technical limitation prevents password filters from querying the SAM. Some information, such as the user's OU, also doesn't exist in the SAM. Because of these -limitations, you can't use the following rules and features with local password policies: - -- The Minimum Age and Maximum Age rules (you can use the Windows version of these rules with - Password Policy Enforcer). See the [Rules](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/rules.md) topic for additional information. -- Policy assignments by groups and containers. See the - [Assign Policies to Users & Groups](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/usersgroups.md) topic for additional information. - -Password Policy Enforcer stores its configuration in Active Directory for domain password policies, and in the Windows registry for local password policies. The Connect To page in the Password Policy -Enforcer Configuration Console. Use it to choose a configuration source. See the -[Connected To](/docs/passwordpolicyenforcer/11.1/admin/configconsole.md#connected-to) topic for additional information. Changes to Password Policy Enforcer's domain configuration replicate to all domain controllers in the -domain. Changes to a local configuration apply only to the local computer. If you want to use -the same local configuration for many computers, export the HKLM\SOFTWARE\ANIXIS\Password Policy -Enforcer 10.0\ registry key from the configured computer, and import it into the other computers. - -You can also use Group Policy to distribute Password Policy Enforcer's local configuration to many -computers in a domain. This is only necessary for local password policies. Domain password policies -automatically replicate to the domain controllers because they are stored in Active Directory. - -### Distribute the local configuration with Group Policy - -**Step 1 –** Start the Group Policy Management Console (gpmc.msc). - -**Step 2 –** Expand the forest and domain items in the left pane. - -**Step 3 –** Right-click the **Group Policy** object that you would like to use to distribute the -configuration, and then click the **Edit...** button. - -**Step 4 –** Expand the Computer Configuration, Preferences, and Windows Settings items in the left -pane. - -**Step 5 –** Right-click the **Registry** item, and then select **New** > **Registry Wizard**. - -![domain_and_local_policies](/images/passwordpolicyenforcer/11.1/administration/domain_and_local_policies.webp) - -**Step 6 –** Select the computer that contains the Password Policy Enforcer local configuration that -you want to distribute, and then click **Next**. - -**Step 7 –** Expand the **HKEY_LOCAL_MACHINE**, **SOFTWARE**, and **ANIXIS** items. - -**Step 8 –** Click the **Password Policy Enforcer _version_** item, and then select the check boxes -beside each item in the bottom pane of the window. - -![domain_and_local_policies_1](/images/passwordpolicyenforcer/11.1/administration/domain_and_local_policies_1.webp) - -**Step 9 –** Click **Finish**. - -**Step 10 –** Close the Group Policy Management Editor. - -Windows applies Password Policy Enforcer's local configuration to the target computers in the domain. -This doesn't happen immediately, as Windows takes some time to apply the changes to Group Policy. -You can force an immediate refresh of Group Policy on the local computer with this command: -`gpupdate /target:computer` diff --git a/docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md b/docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md deleted file mode 100644 index a63acb2ec7..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md +++ /dev/null @@ -1,177 +0,0 @@ ---- -title: "HIBP Updater" -description: "HIBP Updater" -sidebar_position: 90 ---- - -# HIBP Updater - -Password Policy Enforcer can be configured to use the Have I Been Pwnd (HIBP) database. A copy of -this database is hosted on the Netwrix website. The HIBP database contains a list of the hashes of -known compromised passwords. During password change operations, the application can be configured to -reject passwords with a hash that matches a hash in the HIBP database. See the Password Policy -Enforcer [Compromised Password Check](/docs/passwordpolicyenforcer/11.1/admin/compromisedpasswordcheck.md) topic for HIBP database -information and configuration options. - -The HIBP database must be initially deployed to a server or workstation with an internet connection -that can retrieve and format the file. After the database is formatted, you can distribute the HIBP -database to your domain controllers so the Password Policy Enforcer server can check passwords -against the HIBP database. - -## Considerations When Deploying the HIBP Database - -Before deploying the HIBP database, consider the pros and cons when choosing its deployment -location. - -If the HIBP database is copied to and stored local on the Domain Controllers: - -- The HIBP database takes up additional space on the machine where it is copied. (Aproximetly 13GB but subject to change) -- If doing local the database needs to be on every Domain Controller in the same location as specified in the Rule. -- A network connection doesn't come into play and possibly affect performance of checking the password against the HIBP database -- The pending password candidate is checked against the archived hash file at the local level. If a password hash is matched, the pending password change is rejected. - - -If the HIBP database is kept on a Network Share: - -- The database takes up space only on the Network Share, not on each Domain Controller.  -- Requires a working network connection from the Domain Controllers to the Network Share with Read permissions to check: -- The pending password candidate from Domain Controller against the HIBP Database stored on the Network Share, this could affect LSASS/Password Change performance depending on the environment. -- HIBP database space isn't required on the domain controllers but on one Network Location. -- At the time of a password change, if the Network Share isn't available, the Domain Controller must assume the hash is okay and the possibility of a known compromised password being accepted. - -## Installation and Configuration - -The HIBP Updater is installed when you install the Password Policy Enforcer Configuration Console. - -:::info -Only run this from one server. -::: - - -**Step 1 –** To access the HIBP Updater, navigate to the installation location: - -**...\Program Files\Password Policy Enforcer\HIBP\** - -![hibpfolder](/images/passwordpolicyenforcer/11.1/administration/hibpfolder.webp) - -**Step 2 –** Click HIBPWINUpdater. - -### Passwords Hash Database - -Password Policy Enforcer uses the Passwords Hash database to check if users’ new and pending -password (i.e. during a password reset) matches the hash of a compromised password from a data -breach. - -:::note -First-time configuration of this window requires downloading the HIBP database from the -Netwrix website. -::: - - -![HIBP Updater](/images/passwordpolicyenforcer/11.1/administration/hibpupdater.webp) - -:::warning -Ensure the initial update of the database occurs during non-office hours. Due to the -size of the hash file, this download takes up a significant amount of CPU and download time. -::: - - -- Passwords Hash Database Folder – Central location of the Pwned database on the application server. - The default path is: - -**…\HIBP\DB** - -- Update Type: - - - Full Download – Download all data from the HIBP database hosted on the Netwrix website - - Incremental Update – Download updates from the HIBP database hosted on the Netwrix website - instead of downloading the full HIBP database. This option is enabled after a full download of - the HIBP database has completed. - - :::note - Only the full HIBP database file obtained from the Netwrix website has version - information. That full HIBP database file can be obtained using the Website option. - Alternately, the HIBP database can be obtained outside of the application by downloading it - directly from the Netwrix website using an FTP connection: - ::: - - - - [https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip](https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip) - - [https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip.sha256.txt](https://releases.netwrix.com/resources/stealthintercept/stealthintercept-hibp-database-1.0.0.zip.sha256.txt) - - Then use the File option to enable incremental updates. - -- Location: - - - File – If the application server doesn't have internet access, you can manually download the - HIBP database and select the **File** radio button to browse to your local copy of the - database - - Web Site – This option points to the Netwrix website that hosts a copy of the latest HIBP - database. This is the default option and the preferred method if the application server has - internet access. - -- Apply: - - - If Website is selected, then clicking **Apply** downloads the HIBP database from the Netwrix - website and then processes the database for use by the application - - If File is selected, then clicking **Apply** processes the local copy of the (manually obtained) database for use by the application - -### Hash File Replication - -Password Policy Enforcer doesn't distribute hash file updates to other computers, but you can use -the Windows Distributed File System to ensure that all domain controllers have the latest hash -files. Copy the hash files into the Sysvol share on one domain controller, and the Distributed File -System will copy the files into the Sysvol share of all other domain controllers. Configure the -Compromised rule to read the files from: - -**\\127.0.0.1\sysvol\your.domain\filename.db** - -See the [Compromised Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/compromised_rule.md) topic for additional information. - -The path above only works if the computer has a Sysvol share. This won't be the case if you are -using a workstation for policy testing, or if you are using Password Policy Enforcer to enforce -local policies. If you are using Password Policy Enforcer for local policies and want all computers -to receive hash file updates, then use the Sysvol share for file replication and a script or -scheduled task to copy the file to a local folder. - -:::warning -%SystemRoot%. hash files should only be read from a local disk. Using shared hash files -degrades performance, and could jeopardize security. -::: - - -## Scheduler - -Password Policy Enforcer administrators can use the Scheduler portion of the HIBP Updater to -automate the tool to retrieve and/or prepare the HIBP dataset. The Scheduler uses Microsoft Task -Scheduler technology to execute the process. - -### How to Schedule a Task - -**Step 1 –** Click **Scheduler** in the HIBP Updater. - -**Step 2 –** Click **Add Schedule**. An Edit Schedule window appears that looks similar to the HIBP -Updater window. - -![editschedule](/images/passwordpolicyenforcer/11.1/administration/editschedule.webp) - -**Step 3 –** Enter the Name and Description of the schedule. - -**Step 4 –** Select **Add Trigger** to add the interval that you want to have the schedule run. - -- You can add as many triggers as you want to a schedule. - -**Step 5 –** Select the Update Type and Location to get the update. - -**Step 6 –** After you have set up your schedule, click **OK** to save the schedule. - -The HIBP database is updated according to the schedule. - -### Schedule List - -The Schedule List window shows the names, run times, next run times, and whether the schedule is -enabled or not. - -![schedulelist](/images/passwordpolicyenforcer/11.1/administration/schedulelist.webp) - -Use this window to Add, Edit, or Delete schedules for the HIBP Updater. diff --git a/docs/passwordpolicyenforcer/11.1/installation/installationclient.md b/docs/passwordpolicyenforcer/11.1/installation/installationclient.md deleted file mode 100644 index f3eaf95510..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/installationclient.md +++ /dev/null @@ -1,134 +0,0 @@ ---- -title: "Install Password Policy Enforcer Client" -description: "Install Password Policy Enforcer Client" -sidebar_position: 30 ---- - -# Install Password Policy Enforcer Client - -This procedure is used to install the client on your current workstation. See the -[Install with Group Policy Management](/docs/passwordpolicyenforcer/11.1/installation/installationgpm.md) top for details on installing the client -across your network. You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.1/admin/command_line_interface.md#silent-installation). - -**Step 1 –** Navigate to the folder where you extracted the installers downloaded from Netwrix. - -**Step 2 –** Click the **Netwrix_PPE_Client**version**x64.msi** (64 bit OS) or -**Netwrix_PPE_Client**version**x86.msi** (32 bit OS) installation package. The installer is -launched. - -![Client Setup](/images/passwordpolicyenforcer/11.1/install/clientsetup1.webp) - -**Step 3 –** Click **Next**. - -![Client Setup](/images/passwordpolicyenforcer/11.1/install/clientsetup2.webp) - -**Step 4 –** Review the End-User License Agreement. Click **I accept the terms in the License -Agreement**. - -**Step 5 –** Click **Next**. - -![Client Setup](/images/passwordpolicyenforcer/11.1/install/clientsetup3.webp) - -**Step 6 –** Click **Install**. - -![Client Setup](/images/passwordpolicyenforcer/11.1/install/clientsetup4.webp) - -**Step 7 –** Click **Finish** when installation is complete. - -The client is installed. There is no associated desktop icon or menu item. - -Restart each computer to complete the installation. Windows installs the Password Policy Client -during startup. - -## Testing the Password Policy Client - -Test the Password Policy Client by logging on to a computer and pressing the CTRL + ALT + DEL keys -and clicking the **Change a password** item. If you don't see the password policy, it could be -because a Password Policy Enforcer policy hasn't been assigned to you, or because the firewall -rules haven't been created. - -:::note -The Password Policy Client doesn't store or send passwords or password hashes over the -network. An attacker can't determine user passwords by sniffing the communication protocol. The -protocol is also encrypted by default for additional protection. -::: - - -## Creating Firewall Rules for the Password Policy Client - -You may need to create firewall rules for the Password Policy Client if your domain controllers are -running a software (host) firewall, or if the Password Policy Client and Password Policy Server -communicate through a firewall. Firewall rules aren't necessary for local policies because the -Password Policy Client and Password Policy Server are on the same computer. - -### Windows Firewall - -If Windows Firewall is enabled on your domain controllers, then you must create a port exception to -allow connections to the Password Policy Server. Windows Firewall is enabled by default on Windows -Server 2008 and later. - -Follow the steps to create the port exception on all domain controllers. - -**Step 1 –** Use the **Group Policy Management Console** (gpmc.msc) to display the GPOs linked to -the Domain Controllers OU. - -**Step 2 –** Right-click the **Password Policy Enforcer GPO**, and then click **Edit...**. - -:::note -You need to create the GPO if you chose the Express Setup option. -::: - - -**Step 3 –** Expand the **Computer Configuration**, **Policies**, **Administrative Templates**, -**Network**, **Network Connections**, and **Windows Firewall** items. - -**Step 4 –** Click **Domain Profile** in the left pane then double-click **Windows Firewall: Define -inbound port exceptions** in the right pane. - -![the_password_policy_client_3](/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_3.webp) - -**Step 5 –** Select the **Enabled** option, and then click **Show...**. - -![the_password_policy_client_4](/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_4.webp) - -**Step 6 –** Select the **Enabled** option, and then click **Show...**. - -![the_password_policy_client_5](/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_5.webp) - -**Step 7 –** Click **OK** until you return to the Group Policy Management Editor. - -**Step 8 –** Close the **Group Policy Management Editor**. - -### Other Firewalls - -Use the information on this page to create appropriate rules for your firewall that allow the -Password Policy Client and Password Policy Server to communicate through the firewall. - -The Password Policy Client initiates a request by sending a datagram with the following attributes -to the Password Policy Server: - -| Attribute | Result | -| ------------------- | ---------------------------- | -| Protocol | UDP | -| Source Address | Client Computer IP address | -| Source Port | Any | -| Destination address | Domain controller IP address | -| Destination port | 1333 | - -The Password Policy Server responds by sending a datagram with the following attributes back to the -Password Policy Client: - -| Attribute | Result | -| ------------------- | ---------------------------- | -| Protocol | UDP | -| Source Address | Domain controller IP address | -| Source Port | Any | -| Destination address | Client Computer IP address | -| Destination port | Any | - -:::note -If your firewall performs Stateful Packet Inspection, then only create a rule for the -request datagram as the firewall automatically recognizes and allows the response datagram. - -::: diff --git a/docs/passwordpolicyenforcer/11.1/installation/installationconfigconsole.md b/docs/passwordpolicyenforcer/11.1/installation/installationconfigconsole.md deleted file mode 100644 index d030e568b4..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/installationconfigconsole.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -title: "Install the Configuration Console" -description: "Install the Configuration Console" -sidebar_position: 50 ---- - -# Install the Configuration Console - -The Configuration Console configures and manages Netwrix Password Policy Enforcer on your domain. - -Install the Password Policy Enforcer Configuration Console on any server or workstation where you need it. - -The Configuration Console is a feature package included in the server installation **.msi** file: - -- PPE Server – enforces password policies. It can be installed on Domain Controllers for domain - password policy, or on servers and workstations for local account password policy. -- Configuration Console – manages policy configuration. Install wherever needed. -- Mailer Service – sends email reminders. Install on any server. - -Follow the procedure in [Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.1/installation/installationserver.md), -selecting the **Configuration Console** feature. You can select the other features if appropriate -for the server. - -You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.1/admin/command_line_interface.md#silent-installation). diff --git a/docs/passwordpolicyenforcer/11.1/installation/installationgpm.md b/docs/passwordpolicyenforcer/11.1/installation/installationgpm.md deleted file mode 100644 index 949d1b7f2c..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/installationgpm.md +++ /dev/null @@ -1,86 +0,0 @@ ---- -title: "Install with Group Policy Management" -description: "Install with Group Policy Management" -sidebar_position: 40 ---- - -# Install with Group Policy Management - -An automated installation uses Group Policy to distribute Password Policy Enforcer. This type of -installation is recommended when you need to install Password Policy Enforcer on many computers. -This section shows you how to install Password Policy Enforcer on domain controllers to enforce -domain policies, but you can also use Group Policy to target member servers and workstations if you -need to enforce local policies. See the -[Domain and Local Policies](/docs/passwordpolicyenforcer/11.1/installation/domain_and_local_policies.md) topic for additional -information. - -## Create a Distribution Point - -A distribution point can either be a UNC path to a server share, or a DFS (Distributed File System) -path. To create a Password Policy Enforcer distribution point: - -**Step 1 –** Log on to a server as an administrator. - -**Step 2 –** Create a shared network folder to distribute the files from. - -**Step 3 –** Give the **Domain Controllers** security group read access to the share, and limit -write access to authorized personnel only. - -**Step 4 –** Download the Netwrix Password Policy Enforcer installation package from Netwrix. - -**Step 5 –** Extract the installers from the compressed file. - -**Step 6 –** Copy the **.msi** files to the distribution folder. - -## Create a Group Policy Object - -**Step 1 –** Start the Group Policy Management Console (**gpmc.msc**). - -**Step 2 –** Expand the forest and domain items in the left pane. - -**Step 3 –** Right-click the **Domain Controllers OU** in the left pane, and then click **Create a -GPO in this domain, and Link it here...** - -![GPM installation](/images/passwordpolicyenforcer/11.1/install/gpm1.webp) - -**Step 4 –** Enter **Password Policy Enforcer** in the provided field, and then press **Enter**. - -![GPM Install](/images/passwordpolicyenforcer/11.1/install/gpm2.webp) - -## Edit the Group Policy Object - -**Step 1 –** Right-click the **Password Policy Enforcer GPO**, and then click the **Edit...** -button. - -**Step 2 –** Expand the **Computer Configuration**, **Policies**, and **Software Settings** items. - -**Step 3 –** Right-click the **Software installation** item, and then select **New** > -**Package...** - -**Step 4 –** Enter the full **UNC path** to your **msi** files. - -:::note -You must enter a UNC path so that other computers can access this file over the network. -For example: \\file server\distribution point share\Netwrix*PPE\_\_version*.msi -::: - - -**Step 5 –** Click **Open**. - -![installing_ppe_2](/images/passwordpolicyenforcer/11.1/install/installing_ppe_2.webp) - -**Step 6 –** Select **Assigned** as the deployment method. - -**Step 7 –** Click **OK**. - -**Step 8 –** Close the Group Policy Management Editor. - -## Complete the Installation - -Restart each domain controller to complete the installation. Windows installs Password Policy -Enforcer during startup, and then immediately restarts the computer a second time to complete the -installation. - -Password Policy Enforcer doesn't enforce a password policy until the policies are defined. Users -can still change their password, and must comply only with the Windows password policy rules -(if enabled). diff --git a/docs/passwordpolicyenforcer/11.1/installation/installationmailer.md b/docs/passwordpolicyenforcer/11.1/installation/installationmailer.md deleted file mode 100644 index 3efdb85528..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/installationmailer.md +++ /dev/null @@ -1,33 +0,0 @@ ---- -title: "Install Mailer Service" -description: "Install Mailer Service" -sidebar_position: 60 ---- - -# Install Mailer Service - -Netwrix Password Policy Enforcer sends email reminders to domain users before their passwords -expire. This is especially useful for users who log on infrequently, and for remote users who access -the network without logging on to the domain. You must install the Password Policy Enforcer Mailer -and configure the email delivery and email message options to send email reminders to users. See the -[Notifications](/docs/passwordpolicyenforcer/11.1/admin/configconsole.md#notifications) topic for additional information. - -Add your email address to a service account, and the Password Policy Enforcer Mailer reminds you to -change the service account password before it expires. - -The Password Policy Enforcer Mailer isn't installed by default. Only install it on one server in -each domain. The Password Policy Enforcer Mailer can be installed on any server. - -The mailer is a feature package included in the server installation **.msi** file: - -- PPE Server – enforces password policies. It can be installed on Domain Controllers for domain - password policy, or on servers and workstations for local account password policy. -- Configuration Console – manages policy configuration. Install wherever needed. -- Mailer Service – sends email reminders. Install on any server. - -Follow the procedure in [Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.1/installation/installationserver.md), -selecting the **Mailer Service** feature. You can select the other features if appropriate for the -server. - -You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.1/admin/command_line_interface.md#silent-installation). diff --git a/docs/passwordpolicyenforcer/11.1/installation/installationserver.md b/docs/passwordpolicyenforcer/11.1/installation/installationserver.md deleted file mode 100644 index 9c65452fbb..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/installationserver.md +++ /dev/null @@ -1,79 +0,0 @@ ---- -title: "Install Password Policy Enforcer on a Server" -description: "Install Password Policy Enforcer on a Server" -sidebar_position: 20 ---- - -# Install Password Policy Enforcer on a Server - -Password Policy Enforcer server should be installed on every domain controller to enforce the -password policy for domain user accounts, or on individual servers and workstations to enforce the -password policy for local user accounts. - -If your domain contains some read-only domain controllers, then installation of Password Policy -Enforcer on these servers is only necessary if you are using the following features: - -- [Rules](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/rules.md) -- [Password Policy Client](/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/password_policy_client.md) -- [Netwrix Password Reset](https://helpcenter.netwrix.com/category/passwordreset) -- [Password Policy Enforcer Web](/docs/passwordpolicyenforcer/11.1/web-overview/web_overview.md) - -The Server installation package includes multiple features selected during installation: - -- PPE Server – enforces password policies. It can be installed on Domain Controllers for domain - password policy, or on servers and workstations for local account password policy. -- Configuration Console – manages policy configuration. Install wherever needed. -- Mailer Service – sends email reminders. Install on any server. - -**Step 1 –** Download the installation package from Netwrix. - -**Step 2 –** Extract the installers from the compressed file. If you are going to use Group Policy -Manager to install Netwrix Password Policy Enforcer, copy the **msi** files to a distribution -folder. See the [Install with Group Policy Management](/docs/passwordpolicyenforcer/11.1/installation/installationgpm.md) topic for additional -details. You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.1/admin/command_line_interface.md#silent-installation). - -:::note -Continue with these steps to install one or more features on your current server or domain -controller. You must repeat these steps for each server where the features are installed. -::: - - -**Step 3 –** Click the **Netwrix_PPE_Server_version_x64.msi** installation package. The -installer is launched. - -![Server Setup](/images/passwordpolicyenforcer/11.1/install/serversetup1.webp) - -**Step 4 –** Click **Next**. - -![Server Setup](/images/passwordpolicyenforcer/11.1/install/serversetup2.webp) - -**Step 5 –** Review the End-User License Agreement. Click **I accept the terms in the License -Agreement**. - -**Step 6 –** Click **Next**. - -![Server Setup](/images/passwordpolicyenforcer/11.1/install/serversetup3.webp) - -**Step 7 –** Select the features to install. The required storage is shown for each selection. - -- PPE Server – enforces password policies. It can be installed on Domain Controllers for domain - password policy, or on servers and workstations for local account password policy. It isn't - selected by default. -- Configuration Console – manages policy configuration. Install wherever needed. Selected by - default. -- Mailer Service – sends email reminders. It isn't selected by default. - -**Step 8 –** The default location is shown. Click **Browse** and select a new location if needed. - -**Step 9 –** Click **Next**. - -![Server Setup](/images/passwordpolicyenforcer/11.1/install/serversetup4.webp) - -**Step 10 –** Review your selections. Click **Back** to make any changes. When ready, click -**Install**. - -![Server Setup](/images/passwordpolicyenforcer/11.1/install/serversetup5.webp) - -**Step 11 –** Click **Finish** when installation is complete. You are prompted to restart your -system for the changes to take effect. diff --git a/docs/passwordpolicyenforcer/11.1/installation/installationweb.md b/docs/passwordpolicyenforcer/11.1/installation/installationweb.md deleted file mode 100644 index a4d21f3558..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/installationweb.md +++ /dev/null @@ -1,80 +0,0 @@ ---- -title: "Install Password Policy Enforcer Web" -description: "Install Password Policy Enforcer Web" -sidebar_position: 70 ---- - -# Install Password Policy Enforcer Web - -Password Policy Enforcer Web V7.11 is a web server enabling users to change their Windows domain -password from a web browser. - -Click the following link to download Password Policy Enforcer Web: - -[Password_Policy_Enforcer_WEB_7.11.zip](https://www.netwrix.com/download/commercial/Password_Policy_Enforcer_WEB_7.11.zip) - -## The PPE Web Setup Wizard - -The Setup Wizard copies the required files onto the server and configures IIS to run the Password -Policy Enforcer Web application. - -Follow the steps to install PPE Web. - -**Step 1 –** Start the Password Policy Enforcer Web Setup Wizard (PPEWeb711.exe). - -**Step 2 –** If another version of Password Policy Enforcer Web is detected, the Setup Wizard may -required older files to be backed up. Back up these files if the original files have been modified. -Click **Next**. - -**Step 3 –** Click **Next**. - -**Step 4 –** Read the License Agreement. Click **I accept the terms of the license agreement**, then -click **Next** if you accept all the terms. - -**Step 5 –** Click **Browse...** if you want to choose a different folder for the Password Policy -Enforcer Web documentation and tools, then click **Next**. - -**Step 6 –** Select an **IIS Web Site** from the dropdown. Change the default Virtual Directory, if -needed. - -:::note -Password Policy Enforcer Web should be installed in its own virtual directory. -::: - - -**Step 7 –** Click **Next** twice. - -**Step 8 –** Wait for Password Policy Enforcer Web to install, then click **Finish**. - -#### Upgrading from PPE Web V7.x - -Some planning is needed to ensure a smooth upgrade from PPE Web V7.x. A trial run on a lab network -is recommended. - -#### Before You Begin - -The HTML templates and associated images are overwritten during an upgrade. You must back up and -customized HTML templates and images before upgrading. The HTML templates and images are installed -in the `\Inetpub\wwwroot\ppeweb\` folder by default. - -:::note -A full backup of the PPE Web server is recommended. Use it to roll back to the -previous version if the upgrade can't be completed. You may need to restart Windows after -upgrading. -::: - - -:::warning -PPE Web V7.11 is only compatible with Password Policy Enforcer V7.0 and later. Upgrade -Password Policy Enforcer to a compatible version if you have enabled Password Policy Enforcer -integration. -::: - - -#### Upgrading to V7.11 - -**Step 1 –** Start the PPE Web Setup Wizard and follow the prompts. The Setup Wizard uninstalls the -previous version. There is no need to manually uninstall previous versions. - -**Step 2 –** Restore any customized HTML templates and images after upgrading. Don't restore -PPEWeb.dll from the backup as it belongs to the previous version. diff --git a/docs/passwordpolicyenforcer/11.1/installation/uninstall.md b/docs/passwordpolicyenforcer/11.1/installation/uninstall.md deleted file mode 100644 index 521ad471d7..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/uninstall.md +++ /dev/null @@ -1,29 +0,0 @@ ---- -title: "Uninstall Netwrix Password Policy Enforcer" -description: "Uninstall Netwrix Password Policy Enforcer" -sidebar_position: 120 ---- - -# Uninstall Netwrix Password Policy Enforcer - -You can uninstall Password Policy Enforcer on every domain server and computer, or use Group Policy -Management to remove the PPE Server and PPE Client on all machines. - -You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.1/admin/command_line_interface.md#silent-installation). - -**Step 1 –** Open **Start** > **Control Panel** > **Programs and Features** on each system where a -PPE component is installed. - -**Step 2 –** Click **Uninstall a program**. - -**Step 3 –** Select Netwrix Password Policy Enforcer to uninstall the PPE Server, PPE Configuration -Console and Mailer. - -**Step 4 –** Click **Uninstall**. - -**Step 5 –** Select Netwrix Password Policy Client to uninstall the client. - -**Step 6 –** Click **Uninstall**. - -**Step 7 –** Reboot the Domain Controller. diff --git a/docs/passwordpolicyenforcer/11.1/installation/upgrading.md b/docs/passwordpolicyenforcer/11.1/installation/upgrading.md deleted file mode 100644 index 2deed524e8..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/upgrading.md +++ /dev/null @@ -1,56 +0,0 @@ ---- -title: "Upgrading Password Policy Enforcer" -description: "Upgrading Password Policy Enforcer" -sidebar_position: 110 ---- - -# Upgrading Password Policy Enforcer - -Upgrades are supported for versions 9.0 and above. Contact Customer Support at -[https://www.netwrix.com/support.html](https://www.netwrix.com/support.html) if you need assistance -upgrading older versions - -You can also install/uninstall the products using command line -[Silent Installation](/docs/passwordpolicyenforcer/11.1/admin/command_line_interface.md#silent-installation). - -**Upgrading the Password Policy Server** - -The Password Policy Enforcer installer detects existing installations and upgrades them to 11. See -the [Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.1/installation/installationserver.md) topic for additional -information. If you are performing an automated installation with Group Policy, then add the new -**.msi** installer files to the same Group Policy Object used to install the older version. See the -[Install with Group Policy Management](/docs/passwordpolicyenforcer/11.1/installation/installationgpm.md) topic for additional information. - -:::note -Upgrade all your servers and domain controllers. Configuration changes performed with the -new version don't affect servers running an older version. If you have multiple versions, you must -make configuration changes in both configuration consoles until all domain controllers are upgraded -to 11. Failure to do so may lead to inconsistent enforcement of the password policy. -::: - - -Open the [License](/docs/passwordpolicyenforcer/11.1/admin/configconsole.md#license) settings on the Configuration Console -after an upgrade to check your license details. Password Policy Enforcer reverts to a 30-day -evaluation license if it can't import the license key. - -**Upgrading the Password Policy Client** - -The Password Policy Client installer detects existing installations and upgrades them to 11. See the -[Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.1/installation/installationclient.md)[Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.1/installation/installationclient.md) -topic for additional information. If you are distributing the Password Policy Client with Group -Policy, then add the new client **.msi** file to the same Group Policy Object used to install the -older version. Upgrade and reboot the Password Policy Servers before upgrading the clients. - -The Password Policy Enforcer 11 Password Policy Server is backwards compatible with the V10.x and -V9.x Password Policy Client. You aren't required to update the Password Policy Clients, but it is -recommended. - -**Upgrading the Mailer** - -The Password Policy Enforcer installer detects existing installations of the Password Policy -Enforcer Mailer and upgrades them to 11. See the [Install Mailer Service](/docs/passwordpolicyenforcer/11.1/installation/installationmailer.md) -topic for additional information. - -**Upgrade Notes** - -- Versions 9.x and above don't support perpetual license keys. diff --git a/docs/passwordpolicyenforcer/11.1/installation/writeback.md b/docs/passwordpolicyenforcer/11.1/installation/writeback.md deleted file mode 100644 index 78e5beb5e8..0000000000 --- a/docs/passwordpolicyenforcer/11.1/installation/writeback.md +++ /dev/null @@ -1,19 +0,0 @@ ---- -title: "Enforce Password Reset with Azure Password Writeback" -description: "Enforce Password Reset with Azure Password Writeback" -sidebar_position: 100 ---- - -# Enforce Password Reset with Azure Password Writeback - -You can use Password Policy Enforcer to enforce password policies for passwords reset from Microsoft -Entra ID and O365 by enabling password writeback in Microsoft Entra ID. See the -[How does self-service password reset writeback work in Microsoft Entra ID?](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-writeback) -Microsoft knowledge base article for additional information on password writeback in Microsoft Entra -ID. Password writeback sends all new passwords from Microsoft Entra ID to an available, on-premises -domain controller to check with Password Policy Enforcer. This happens while the user is resetting -their password. See the -[Tutorial: Enable Microsoft Entra self-service password reset writeback to an on-premises environment](https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr-writeback) -and -[How it works: Microsoft Entra self-service password reset](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks#how-it-works-microsoft-entra-self-service-password-reset) Microsoft -knowledge base articles for additional information on password writeback for Microsoft Entra ID. diff --git a/docs/passwordpolicyenforcer/11.1/web-overview/_category_.json b/docs/passwordpolicyenforcer/11.1/web-overview/_category_.json deleted file mode 100644 index 641fa612e9..0000000000 --- a/docs/passwordpolicyenforcer/11.1/web-overview/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Password Policy Enforcer Web", - "position": 60, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "web_overview" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.1/web-overview/editing_html_templates.md b/docs/passwordpolicyenforcer/11.1/web-overview/editing_html_templates.md deleted file mode 100644 index 1a80ad4189..0000000000 --- a/docs/passwordpolicyenforcer/11.1/web-overview/editing_html_templates.md +++ /dev/null @@ -1,212 +0,0 @@ ---- -title: "Edit HTML Templates" -description: "Edit HTML Templates" -sidebar_position: 60 ---- - -# Edit HTML Templates - -Password Policy Enforcer Web's user interface is built with customizable templates. Modify the user interface by editing the templates. - -### User Interface Files - -Password Policy Enforcer Web installs four .htm files for every language. Each filename starts with -a language code. The files for the US English language are: - -| Filename | Content | -| --------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -| en_default.htm | Static HTML for the Welcome page. See the [Launch Password Policy Enforcer Web](/docs/passwordpolicyenforcer/11.1/web-overview/using_web.md) topic for additional information. | -| en_ppeweb.htm | Template for the Password Change page. See the [Change Password](using_web.md#change-password) topic for additional information. | -| en_finished.htm | Template for the Finished page. | -| en_error.htm | Template for the Password Critical Error page. See the [Error Messages](using_web.md#error-messages) topic for additional information. | - -The other user interface files are language independent. Most of the formatting is in ppeweb.css, -and some additional CSS for Internet Explorer is in ppeweb_ie.css. The image files are in the images -folder. These files are installed into the `\Inetpub\wwwroot\ppeweb\` folder by default. - -:::note -Always backup the user interface files before and after editing them. Your changes may be -overwritten when Password Policy Enforcer Web is upgraded, and some changes could stop Password -Policy Enforcer Web from working correctly. Web browsers display pages differently, so test your -changes with several versions of the most popular browsers to ensure compatibility. -::: - - -The en_default.htm contains static HTML, but the other .htm files contain special comment tags that -are used to prepare the pages. Some of these comments define ranges. A range looks like this: - -`Some text or HTML` - -Password Policy Enforcer Web deletes ranges (and the text inside them) when they aren't needed. -Some ranges span only one word, while others span several lines. The other type of comment tag is -called a field. - -`` - -Fields are replaced by some other information. For example, the field above is replaced with a -username. - -#### Resource Strings - -Templates end with a resource string section. - -`` - -Resource strings are mostly validation error messages, but they can contain any text Password Policy -Enforcer Web may need to build the page. See the [Error Messages](using_web.md#error-messages) topic -for additional information. Don't modify the identifiers on the left, only edit the text on the -right. Resource strings are always inside a range called RESOURCE_STRINGS. Password Policy Enforcer -Web deletes this range before sending the page to the user's web browser. - -:::warning -You may rebrand the Password Policy Enforcer Web user interface, but it is a violation -of the License Agreement to modify, remove, or obscure any copyright notice. -::: - - -## Examples - -This topic contains examples of common customizations. Use these examples to gain a better -understanding of Password Policy Enforcer Web's templates. You don't need to be an expert in HTML to -follow these examples, but a basic understanding of HTML will help. Work through them carefully, and -backup files before you edit them. The examples in this section are from the US English files, but -the format is the same for all languages. - -### Replacing the Netwrix Logo - -The Netwrix logo is shown in the top left corner of the Welcome page. The logo is installed into the -`\Inetpub\wwwroot\ppeweb\images\` folder by default, and it is called logo.gif. You can replace this -file with one containing your organization's logo. - -Your logo may appear distorted if it isn't the same size as the Netwrix logo. You can fix this by -opening en_default.htm in a text editor such as Notepad. Search for the following line, and replace the width (116) and height (69) with the dimensions of your logo in pixels. - -`` - -### Edit Page Instructions - -Instructions appear at the top of the Password Change page in the white section above the input -fields. You can edit these instructions by opening `en_ppeweb.htm` and searching for the text you -want to modify. - -Instructions are inside ranges called SECTION_A and SECTION_B. Each section contains the -instructions for a page in the template. Ensure you edit the instructions in the correct section, -or they may be displayed on the wrong page. - -`` - -`

Enter your username and domain, and then click Next to continue…` - -`` - -`` - -`

Enter your old and new passwords in the text boxes below.

` - -`` - -### Edit Validation Error Messages - -Validation error messages are shown in a yellow box below the page instructions. Validation errors -are normally caused by invalid user input. - -![using_ppe_web_1](/images/passwordpolicyenforcer/11.1/web/using_ppe_web_1.webp) - -Validation error messages are defined in en_ppeweb.htm. The error messages are in the resource -strings section near the end of the file. See the Resource Strings topic for additional information. - -| String | Error Message | -| ----------------------------- | ---------------------------------------- | -| @RES_EMPTY_FIELD_USERNAME | Enter your username in the Username box. | -| @RES_EMPTY_FIELD_DOMAIN | Enter your domain name in the Domain bo… | -| @RES_BAD_USERNAME_OR_PASSWORD | The username, domain, or old password i… | - -### Edit Critical Error Messages - -All the critical error messages are defined in `en_error.htm`. The error messages are in the -resource strings section near the end of the file. See the Resource Strings topic for additional -information. - -![using_ppe_web_2](/images/passwordpolicyenforcer/11.1/web/using_ppe_web_2.webp) - -You may see placeholders like %1 and %2 in some error messages. These are replaced with more -information about the error. You should keep these as they provide important information about the -error, but you can delete them if you don't want them. - -| String | Error Message | -| ----------------------- | ---------------------------------------------- | -| @RES_ACCESS_DENIED | You don't have permission to change your pas… | -| @RES_ACCOUNT_LOCKED_OUT | Your account is locked out. Try aga… | -| @RES_LICENSE_MISSING | License reminder. Your password wasn't chang… | - -If you want to display some text for all error messages, then insert your text above or below the -`

{/*ERROR*/}

` line. For example: - -```html -` -

{/*ERROR*/}

-` ` -

The help desk phone number is 555-555-5555.

-` -``` - -### Edit Finished Message - -The finished message is shown after users successfully change their password. This message is -defined in en_finished.htm. - -![editing_the_html_templates_1](/images/passwordpolicyenforcer/11.1/web/editing_the_html_templates_1.webp) - -`

Finished

` - -`

Your password has been changed. You can now logon with your new pass…` - -### Change Font Sizes and Colors - -`ppeweb.css` contains most of the user interface formatting information. Change font sizes and colors by editing this file. To reposition and resize items, you need some understanding of CSS. For example, this is the CSS for the validation error box: - -``` -.error { - -background-color: #ffffd6; - -border: 3px solid #ff8080; - -color: #333333; - -font: bold 1.3em/1.2em Arial, sans-serif; - -margin: 3px 0 0 4px; - -padding: 6px 22px 6px 8px; - -width: 499px; - -} -``` - -Edit these properties to change the appearance of the error box. You may need to clear your web -browser's cache to see the changes. - -:::note -Web browsers display pages differently, so test your changes with several versions of the -most popular browsers to ensure compatibility. -::: - - -### Replace URLs to the Welcome Page - -Password Policy Enforcer Web shows the Welcome page when users click OK or Cancel on the Password -Change, Error, and Finished pages. - -To display a different page when users click OK or Cancel, search for `en_default.htm` in -`en_ppeweb.htm`, `en_finished.htm`, and `en_error.htm` and replace `en_default.htm` with an -alternative URL. For example: - -`https://myserver/accounts/login.htm` diff --git a/docs/passwordpolicyenforcer/11.1/web-overview/securing_web.md b/docs/passwordpolicyenforcer/11.1/web-overview/securing_web.md deleted file mode 100644 index 111fa59091..0000000000 --- a/docs/passwordpolicyenforcer/11.1/web-overview/securing_web.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -title: "Secure Password Policy Enforcer Web" -description: "Secure Password Policy Enforcer Web" -sidebar_position: 50 ---- - -# Secure Password Policy Enforcer Web - -Password Policy Enforcer Web is designed to operate securely, but you must ensure that the web -server is also secure. Follow Microsoft's recommendations to secure the web server, and always -install and use an SSL certificate if Password Policy Enforcer Web is used on an unencrypted network. - -## Install an SSL Certificate - -Password Policy Enforcer Web sends passwords to the domain controllers over a secure connection, but -you need to set up SSL (Secure Sockets Layer) encryption for the connection between the web browser -and the web server. - -:::warning -Don't use Password Policy Enforcer Web on a production network without SSL encryption. -::: - - -You can use a self-signed certificate, but most organizations purchase certificates from a -certificate authority. This is a recurring cost, and you must complete forms for the certificate authority to verify your identity. You can install Password Policy Enforcer Web on a server that already has an SSL certificate to avoid purchasing another one. - -The IIS documentation explains how request, install, and use SSL certificates. - -See the -[Configure Server Certificates in IIS 7](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc732230(v=ws.10)?redirectedfrom=MSDN) -Microsoft knowledge base article for additional information. - -Ensure that users only access Password Policy Enforcer Web over an encrypted connection after the -SSL certificate is installed. The URL should start with https://. Web browsers can be redirected to -always use the secure URL. diff --git a/docs/passwordpolicyenforcer/11.1/web-overview/web_overview.md b/docs/passwordpolicyenforcer/11.1/web-overview/web_overview.md deleted file mode 100644 index 3514475236..0000000000 --- a/docs/passwordpolicyenforcer/11.1/web-overview/web_overview.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -title: "Password Policy Enforcer Web" -description: "Password Policy Enforcer Web" -sidebar_position: 60 ---- - -# Password Policy Enforcer Web - -Password Policy Enforcer Web lets users change their Windows domain password from a web browser. It can optionally integrate with Password Policy Enforcer to enforce customizable password -policies and help users set compliant passwords. - -Download Password Policy Enforcer Web: - -[PasswordPolicyEnforcer-Web-10.2.0.1.msi](https://releases.netwrix.com/products/passwordpolicyenforcer/10.2/passwordpolicyenforcer-web-10.2.0.1.msi) - -![introduction_4](/images/passwordpolicyenforcer/11.1/web/introduction_4.webp) - -Password Policy Enforcer Web communicates directly with the domain controllers, so it works best -when both the web server and domain controllers are on the same network. If you need to put the web -server in a DMZ for extra security, then consider using Netwrix Password Reset instead of Password -Policy Enforcer Web. - -Password Reset also lets users change their password from a web browser, but it has many other -features including the ability to work in a DMZ without any domain controllers. Use Password Reset -if you need to: - -- Users can reset a forgotten password or unlock their account by answering questions about - themselves, such as their date of birth, first pet's name, etc. Users can access APR from the web - browser, or from the Windows Logon and Unlock screens if the APR Client is installed. -- Send e-mail alerts to users whenever their account is used in the password management system. -- Keep a detailed, searchable audit log of all user activity. -- Separate the web server from he internal network for extra security. - -See the [Netwrix Help Center](https://helpcenter.netwrix.com/) page for documentation on the -Password Reset product. diff --git a/docs/passwordpolicyenforcer/11.2/admin/_category_.json b/docs/passwordpolicyenforcer/11.2/admin/_category_.json deleted file mode 100644 index 5874d2dc57..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Administration", - "position": 40, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "administration_overview" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/_category_.json b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/_category_.json deleted file mode 100644 index 56191c74b1..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "PPE cmdlets", - "position": 60, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "cmdlets" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdconnectppe.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdconnectppe.md deleted file mode 100644 index 47d9859094..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdconnectppe.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -title: "Connect-PPE" -description: "Connect-PPE" -sidebar_position: 10 ---- - -# Connect-PPE - -The **Connect-PPE** cmdlet establishes a connection to the PPE Server. - -**SYNTAX** - -**Connect-PPE** [[__-Local__] `<_SwitchParameter_>`] [[__-Domain__] `<_string_>`] -[`<_CommonParameters_>`] - -**PARAMETERS** - -**-Domain** `<_string_>` - -Name of the domain controller to connect. Can also use **-D** or **-d**. - -**-Local** `<_SwitchParameter_>` - -Connect to PPE Server installed locally. Can also use **-L** or **-l**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5) -[about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Connect-PPE -d "DCNAME1.COMPANY.COM" - -Connection to PPE was established. Connection to Domain "DCNAME1.COMPANY.COM" diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdcopyppepolicy.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdcopyppepolicy.md deleted file mode 100644 index 23f1ad5d9c..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdcopyppepolicy.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Copy-PPEPolicy" -description: "Copy-PPEPolicy" -sidebar_position: 20 ---- - -# Copy-PPEPolicy - -The **CopyPPEPolicy** cmdlet makes a copy of a PPE policy. - -**SYNTAX** - -**Copy-PPEPolicy -DestPolicyName** `<_string_>` **-SrcPolicyName** `<_string_>` -[`<_CommonParameters_>`] - -**PARAMETERS** - -**-SrcPolicyName** `<_string_>` - -Source PPE Policy Name. Can also use **-S** or **-s**. - -**-DestPolicyName** `<_string_>` - -Destination PPE Policy Name. Can also use **-D** or **-d**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Copy-PPEPolicy -s "Eval Policy" -d "User Policy" - -The "User Policy" policy was created based on the "Eval Policy". diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdexportppeconfig.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdexportppeconfig.md deleted file mode 100644 index 8c7c2996b1..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdexportppeconfig.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: "Export-PPEConfig" -description: "Export-PPEConfig" -sidebar_position: 30 ---- - -# Export-PPEConfig - -The **Export-PPEConfig** cmdlet exports the Password Policy Enforcer configuration to a file. - -**SYNTAX** - -**Export-PPEConfig** [__-File__ `<_string_>`] [`<_CommonParameters_>`] - -**PARAMETERS** - -**-File** `<_string_>` - -Name of the file to create. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Export-PPEConfig -file c:\ppe\ppe_config - -Configuration export has been successfully completed. The file "c:\ppe\ppe_config" has been created. diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdexportppepolicy.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdexportppepolicy.md deleted file mode 100644 index 0b747fc05a..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdexportppepolicy.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "Export-PPEPolicy" -description: "Export-PPEPolicy" -sidebar_position: 40 ---- - -# Export-PPEPolicy - -The **Export-PPEPolicy** exports a Password Policy Enforcer policy to a file. - -:::note -This cmdlet calls the **PPE Tool**. You must be an administrator to run this cmdlet. Start -PowerShell with the **Run as Administrator** option. -::: - - -**SYNTAX** - -**Export-PPEPolicy** -PolicyName `<_string_>` [__-File__ `<_string_>`] [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PolicyName** `<_string_>` - -Name of the to export. - -**-File** `<_string_>` - -Name of the file to create. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Export-PPEPolicy -PolicyName "Eval Policy" -File C:\ppe\EvalPolicy - -Configuration export has been successfully completed. The file "C:\ppe\EvalPolicy" has been created. diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeconfigreport.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeconfigreport.md deleted file mode 100644 index 166574733f..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeconfigreport.md +++ /dev/null @@ -1,39 +0,0 @@ ---- -title: "Get-PPEConfigReport" -description: "Get-PPEConfigReport" -sidebar_position: 60 ---- - -# Get-PPEConfigReport - -The **Get-PPEConfigReport** cmdlet saves a Password Policy Enforcer configuration report. - -:::note -This cmdlet calls the PPE Tool. You must be an administrator to run this cmdlet. Start -PowerShell with the **Run as Administrator** option. -::: - - -**SYNTAX** - -**Get-PPEConfigReport** **-Folder** `<_string_>` - -**PARAMETERS** - -**-Folder** `<_string_>` - -Name of the folder to save the report. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEConfigReport -Folder C:\PPE - -The report is created: "C:\PPE\report.html". - -![Creates the PPE Configuration report](/images/passwordpolicyenforcer/11.2/administration/cmdletgetppeconfigreport.webp) diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppedefaultpolicy.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppedefaultpolicy.md deleted file mode 100644 index 4ca6cd8998..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppedefaultpolicy.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: "Get-PPEDefaultPolicy" -description: "Get-PPEDefaultPolicy" -sidebar_position: 70 ---- - -# Get-PPEDefaultPolicy - -The **Get-PPEDefaultPolicy** cmdlet reports the name of the Password Policy Enforcer default Policy. - -**SYNTAX** - -**Get-PPEDefaultPolicy** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEDefaultPolicy - -**Default policy : Eval Policy** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeenabled.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeenabled.md deleted file mode 100644 index 42a8cc2dbc..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeenabled.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: "Get-PPEEnabled" -description: "Get-PPEEnabled" -sidebar_position: 80 ---- - -# Get-PPEEnabled - -The **Get-PPEEnabled** cmdlet returns the enabled/disabled status of the PPE Server. - -**SYNTAX** - -**Get-PPEEnabled** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEEnabled - -**Status PPE : Enabled** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppehelp.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppehelp.md deleted file mode 100644 index 1fde1f675f..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppehelp.md +++ /dev/null @@ -1,60 +0,0 @@ ---- -title: "Get-PPEHelp" -description: "Get-PPEHelp" -sidebar_position: 90 ---- - -# Get-PPEHelp - -The **Get-PPEHelp** cmdlet lists the available Password Policy Enforcer cmdlets. If a cmdlet is -specified, returns help for the cmdlet. - -**SYNTAX** - -**Get-PPEHelp** [[__-Cmdlet__] `<_string_>`] - -**PARAMETERS** - -**-Cmdlet** `<_string_>` - -Name of the cmdlet for help. Can also use **-C** or **-c**. - -`` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> get-ppehelp get-ppehelp - -**NAME** - -Get-PPEHelp - -**SYNOPSIS** - -Get a list of the PPE Cmdlet - -**SYNTAX** - -Get-PPEHelp [[-Cmdlet] ``] `[]` - -**DESCRIPTION** - -Get a list of the PPE Cmdlet - -**RELATED LINKS** - -https://www.netwrix.com/password_policy_enforcer.html - -**REMARKS** - -To see the examples, type: "get-help Get-PPEHelp -examples". - -For detailed information, type: "get-help Get-PPEHelp -detailed". - -For technical information, type: "get-help Get-PPEHelp -full". - -**For online help, type: "get-help Get-PPEHelp -online"** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppelicenseinfo.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppelicenseinfo.md deleted file mode 100644 index 180bc324d0..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppelicenseinfo.md +++ /dev/null @@ -1,63 +0,0 @@ ---- -title: "Get-PPELicenseInfo" -description: "Get-PPELicenseInfo" -sidebar_position: 100 ---- - -# Get-PPELicenseInfo - -The **Get-PPELicenseInfo** cmdlet returns the Password Policy Enforcer license information. - -**SYNTAX** - -**Get-PPELicenseInfo** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -``` -PS C:\> Get-PPELicenseInfo - -**ANIXIS Software License Certificate** - -Product: Password Policy Enforcer - -**License type: Perpetual** - -Licensed to: test - -**Version: 11** - -Users: 100 - -**JrPQdyhsxWrLj7RsuX322Ni8vwIRr6ozC+sY3M16aJba** - -XuRXG6VjOjWUMT1XwqO4c3VA0eIB8+z4KyUNEzLjmSZKvtLsHb0kFYi1zRiL - -**6EBVflEmzxYIsCvAlsg1fNfK1JgjFefOc1gENy2CBikDTbe+HnHf3aVBq6p2** - -Va1eXmMXToi3NDNJCNFzQHy7ZGC5AhQ8GIjQfgK8z9s1sHzpdj2Gn+9BEyQQ - -**nv833QdoFhjKoAXN/xCecZclkCkP9f1GLuq4kN0Emsh5qqXl686JBJlisA3o** - -XWQrEQ0Me9P3TkSUpb742JCngQaGcjKHvQoufBJ+GIrcwWG2DZJ1i9xrOJMT - -**g8D5eFDz/OiqXuZyBHFTInbq77V59x/xtIlUffBW7sCUmY8B+ZhLR2XpLdxr** - -S+4E37Lhf46bScltZxfHZbDQKZuT4hdMKnnzgNHEzkMh8Q3T/40sMvQbAV4O - -**tDF633YsQMH3Ttbyc+vAvIvbAHJOVhBpNd9TCybfas+j6uQL5fa4qo8dFrx+** - -+UrPakOmSL/eDR7xB5/zmB37shDXIPfzfG/Vu7I1/EQuH01rZDyafHnzTmmm - -**1hCMqyi+oVzxZtN8I3sIpAH3FLu+1N37CuHJFrXD97Iu6RjKi+11nG9BmZ2Q** - -0SX5EYc= -``` diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepasswordtest.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepasswordtest.md deleted file mode 100644 index 621da3b866..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepasswordtest.md +++ /dev/null @@ -1,72 +0,0 @@ ---- -title: "Get-PPEPasswordTest" -description: "Get-PPEPasswordTest" -sidebar_position: 110 ---- - -# Get-PPEPasswordTest - -The **Get-PPEPasswordTest** cmdlet runs the Password Policy Enforcer password test for a user. - -**SYNTAX** - -**Get-PPEPasswordTest** **-Password** `<_string_>` **-Username** `<_string_>` [__-OldPassword__ -`<_string_>`] [`<_CommonParameters_>`] - -**PARAMETERS** - -**-Password** `<_string_>` - -The password to test. - -**-User** `<_string_>` - -The username to test. Can also use **-U** or **-u**. - -**-OldPassword** `<_string_>` - -The old password to test. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEPasswordTest -Password qwerty -User PPETestUser - -**Assigning default policy "Eval Policy"** - -Log - -- Info : Reading configuration from NT-DC03.nwxtech.com. - -- Info : DN is "CN=PPE Test User,CN=Users,DC=NWXTECH,DC=COM" - -- Info : Current password is 5 days old. - -- Info : Extended Maximum Age group not found. - -- Info : Dictionary rule found "QWERTY". - -- Info : Password rejected. - -Password must: - -- Accepted : contain a lower alpha character - -- Rejected : contain an upper alpha character - -- Accepted : contain at least 1 of these character types: - -- upper alpha - -- lower alpha - -- Rejected : not be similar to a common password - -- Rejected : contain at least 7 characters - -- Accepted : not be similar to your logon name diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepolicies.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepolicies.md deleted file mode 100644 index b900e6a131..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepolicies.md +++ /dev/null @@ -1,33 +0,0 @@ ---- -title: "Get-PPEPolicies" -description: "Get-PPEPolicies" -sidebar_position: 120 ---- - -# Get-PPEPolicies - -The **Get-PPEPolicies** cmdlet returns the Password Policy Enforcer policies. - -**SYNTAX** - -**Get-PPEPolicies** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEPolicies - -**Admins Policy** - -Eval Policy - -**Test** - -User Policy diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepolicyenabled.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepolicyenabled.md deleted file mode 100644 index a90cb7246f..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepolicyenabled.md +++ /dev/null @@ -1,32 +0,0 @@ ---- -title: "Get-PPEPolicyEnabled" -description: "Get-PPEPolicyEnabled" -sidebar_position: 130 ---- - -# Get-PPEPolicyEnabled - -The **Get-PPEPolicyEnabled** cmdlet returns the enabled/disabled status of a Password Policy -Enforcer policy. - -**SYNTAX** - -**Get-PPEPolicyEnabled** **-PolicyName** `<_string_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PolicyName** `<_string_>` - -Name of the policy. Can also use **-P** or **-p**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEPolicyEnabled -PolicyName "Eval Policy" - -**Policy "Eval Policy" is Enabled** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeserverversion.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeserverversion.md deleted file mode 100644 index cf879a4d71..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeserverversion.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Get-PPEServerVersion" -description: "Get-PPEServerVersion" -sidebar_position: 140 ---- - -# Get-PPEServerVersion - -The **Get-PPEServerVersion** cmdlet returns the Password Policy Enforcer server version. - -**SYNTAX** - -**Get-PPEServerVersion** [__-DC__] `<_string_>`] [`<_CommonParameters_>`] - -**PARAMETERS** - -**-DC** `<_string_>` - -Name of the domain controller running the PPE Server. If not specified, the current domain -controller is used. - -**-Local** `<_SwitchParameter_>` - -Connect to PPE Server installed locally. Can also use **-L** or **-l**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEServerVersion -DC NT-DC03.NWXTECH.COM - -**Version: 11.2.0.148** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeversion.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeversion.md deleted file mode 100644 index 4ab5ef92c6..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeversion.md +++ /dev/null @@ -1,27 +0,0 @@ ---- -title: "Get-PPEVersion" -description: "Get-PPEVersion" -sidebar_position: 150 ---- - -# Get-PPEVersion - -The **Get-PPEVersion** cmdlet returns the version of the Password Policy Enforcer PowerShell module. - -**SYNTAX** - -**Get-PPEVersion** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Get-PPEVersion - -**Version: 11.2.0.148** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdimportppeconfig.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdimportppeconfig.md deleted file mode 100644 index e502ee0fe9..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdimportppeconfig.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -title: "Import-PPEConfig" -description: "Import-PPEConfig" -sidebar_position: 160 ---- - -# Import-PPEConfig - -The **Import-PPEConfig** cmdlet imports a Password Policy Enforcer configuration file. - -:::note -This cmdlet calls the **PPE Tool**. You must be an administrator to run this cmdlet. Start -PowerShell with the **Run as Administrator** option. -::: - - -**SYNTAX** - -**Import-PPEConfig** **-File**] `<_string_>` `<_CommonParameters_>`] - -**PARAMETERS** - -**-File** `<_string_>` - -Name of the configuration file. Can also use **-F** or **-f**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See -[about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Import-PPEConfig -File C:\PPE\ppe_config - -Config import successful. diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdimportppepolicy.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdimportppepolicy.md deleted file mode 100644 index cc1b8b5b5f..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdimportppepolicy.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -title: "Import-PPEPolicy" -description: "Import-PPEPolicy" -sidebar_position: 170 ---- - -# Import-PPEPolicy - -The **Import-PPEPolicy** cmdlet imports a Password Policy Enforcer policy from a file. - -:::note -This cmdlet calls the **PPE Tool**. You must be an administrator to run this cmdlet. Start -PowerShell with the **Run as Administrator** option. -::: - - -**SYNTAX** - -**Import-PPEPolicy** **-File**] `<_string_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-File** `<_string_>` - -Name of the policy file. Can also use **-F** or **-f**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Import-PPEPolicy -File "C:\PPE\EvalPolicy" - -Config import successful. diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdlets.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdlets.md deleted file mode 100644 index 2c15361685..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdlets.md +++ /dev/null @@ -1,55 +0,0 @@ ---- -title: "PPE cmdlets" -description: "PPE cmdlets" -sidebar_position: 60 ---- - -# PPE cmdlets - -Cmdlets are available to manage Password Policy Enforcer from a Windows PowerShell. The -cmdlets aren't case-sensitive. - -Install the [.NET Desktop Runtime 10.0 or later](https://aka.ms/dotnet/10.0/windowsdesktop-runtime-win-x64.exe) and [PowerShell 7.4 or later](https://github.com/powershell/powershell/releases) to use the PowerShell cmdlets. - -To establish the connection: - -**Step 1 –** Open a Windows PowerShell. Some cmdlets require administrative permissions. You can use -the **Run as Administrator** option. - -**Step 2 –** Import the PPE cmdlets module: -**Import-Module "$env:ProgramFiles\Netwrix\Password Policy Enforcer\PS\PPEConf.PowerShell.dll"** - -**Step 3 –** Connect to your domain: -**Connect-PPE -d "_domain_"** where _domain_ is the full name of your domain controller. -**NT-DC03.NWXTECH.COM** in this example. - -**Get-PPEHelp** with no parameters, displays a list of available cmdlets. Use the PowerShell -**get-help** _Cmdlet_ for information about the cmdlet. - -![PPE cmdlets Connect](/images/passwordpolicyenforcer/11.2/administration/cmdletconnect.webp) - -Click a PPE cmdlet name for details. - -- [Connect-PPE](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdconnectppe.md) -- [Copy-PPEPolicy](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdcopyppepolicy.md) -- [Export-PPEConfig](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdexportppeconfig.md) -- [Export-PPEPolicy](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdexportppepolicy.md) -- [Get-PPEBulkPasswordTest](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppebulkpasswordtest.md) -- [Get-PPEConfigReport](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeconfigreport.md) -- [Get-PPEDefaultPolicy](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppedefaultpolicy.md) -- [Get-PPEEnabled](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeenabled.md) -- [Get-PPEHelp](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppehelp.md) -- [Get-PPELicenseInfo](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppelicenseinfo.md) -- [Get-PPEPasswordTest](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepasswordtest.md) -- [Get-PPEPolicies](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepolicies.md) -- [Get-PPEPolicyEnabled](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppepolicyenabled.md) -- [Get-PPEServerVersion](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeserverversion.md) -- [Get-PPEVersion](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppeversion.md) -- [Import-PPEConfig](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdimportppeconfig.md) -- [Import-PPEPolicy](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdimportppepolicy.md) -- [Remove-PPEPolicy](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdremoveppepolicy.md) -- [Set-PPEDefaultPolicy](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppedefaultpolicy.md) -- [Set-PPEEnabled](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppeenabled.md) -- [Set-PPEPolicyEnabled](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppepolicyenabled.md) -- [Start-PPECompromisedPasswordChecker](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md) -- [Start-PPEHibpUpdater](/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdstartppehibpupdater.md) diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdremoveppepolicy.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdremoveppepolicy.md deleted file mode 100644 index a3cceb3344..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdremoveppepolicy.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: "Remove-PPEPolicy" -description: "Remove-PPEPolicy" -sidebar_position: 180 ---- - -# Remove-PPEPolicy - -The **Remove-PPEPolicy** cmdlet removes a Password Policy Enforcer policy. - -**SYNTAX** - -**Remove-PPEPolicy** **-PolicyName**] `<_string_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PolicyName** `<_string_>` - -Name of the policy. Can also use **-P** or **-p**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Remove-PPEPolicy -PolicyName Test - -**PS C:\>** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppedefaultpolicy.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppedefaultpolicy.md deleted file mode 100644 index e3c39399cf..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppedefaultpolicy.md +++ /dev/null @@ -1,31 +0,0 @@ ---- -title: "Set-PPEDefaultPolicy" -description: "Set-PPEDefaultPolicy" -sidebar_position: 190 ---- - -# Set-PPEDefaultPolicy - -The **Set-PPEDefaultPolicy** cmdlet sets the Password Policy Enforcer policy as the default. - -**SYNTAX** - -**Set-PPEDefaultPolicy** **-PolicyName**] `<_string_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PolicyName** `<_string_>` - -Name of the policy. Can also use **-P** or **-p**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Set-PPEDefaultPolicy -PolicyName "Eval Policy" - -**Default policy : Eval Policy** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppeenabled.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppeenabled.md deleted file mode 100644 index 515242af8b..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppeenabled.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Set-PPEEnabled" -description: "Set-PPEEnabled" -sidebar_position: 200 ---- - -# Set-PPEEnabled - -The **Set-PPEEnabled** cmdlet sets the enabled/disabled status for the PPE Server. - -**SYNTAX** - -**Set-PPEEnabled** **-Enable**] `<_int_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-Enable** `<_int_>` - -Specify **1** to enable the PPE Server, specify **0** to disable the PPE Server. Can also use **-E** -or **-e**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLES** - -PS C:\> Set-PPEEnabled -Enable 0 - -**Status PPE : Disabled** - -PS C:\> Set-PPEEnabled -Enable 1 - -**Status PPE : Enabled** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppepolicyenabled.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppepolicyenabled.md deleted file mode 100644 index 72605efcf3..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdsetppepolicyenabled.md +++ /dev/null @@ -1,42 +0,0 @@ ---- -title: "Set-PPEPolicyEnabled" -description: "Set-PPEPolicyEnabled" -sidebar_position: 210 ---- - -# Set-PPEPolicyEnabled - -The **Set-PPEPolicyEnabled** cmdlet sets the enabled/disabled status for a Password Policy Enforcer -policy. - -**SYNTAX** - -**Set-PPEPolicyEnabled\_\_**-PolicyName** `<_string_>` **-Enable\__] -`<\_int_>` [`<_CommonParameters_>`] - -**PARAMETERS** - -**-PolicyName** `<_string_>` - -The policy name. - -**-Enable** `<_int_>` - -Specify **1** to enable the policy, specify **0** to dis -Poliable the policy. Can also use **-E** -or **-e**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLES** - -PS C:\> Set-PPEPolicyEnabled -PolicyName "Eval Policy" -Enable 0 - -**Policy "Eval Policy" is Disabled** - -PS C:\> Set-PPEPolicyEnabled -PolicyName "Eval Policy" -Enable 1 - -**Policy "Eval Policy" is Enabled** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md deleted file mode 100644 index 7cf47bdc8f..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md +++ /dev/null @@ -1,28 +0,0 @@ ---- -title: "Start-PPECompromisedPasswordChecker" -description: "Start-PPECompromisedPasswordChecker" -sidebar_position: 220 ---- - -# Start-PPECompromisedPasswordChecker - -The **Start-PPECompromisedPasswordChecker** cmdlet runs the Password Policy Enforcer Compromised -Password Checker. - -**SYNTAX** - -**Start-PPECompromisedPasswordChecker** [`<_CommonParameters_>`] - -**PARAMETERS** - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Start-PPECompromisedPasswordChecker - -**PS C:\>** diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdstartppehibpupdater.md b/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdstartppehibpupdater.md deleted file mode 100644 index b2a1cf9fd3..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdstartppehibpupdater.md +++ /dev/null @@ -1,48 +0,0 @@ ---- -title: "Start-PPEHibpUpdater" -description: "Start-PPEHibpUpdater" -sidebar_position: 230 ---- - -# Start-PPEHibpUpdater - -The **Start-PPEHibpUpdater** cmdlet starts an update of the Hibp database. - -**SYNTAX** - -**Start-PPEHibpUpdater** [[__-Web__] `<_SwitchParameter_>`] **-Folder** `<_string_>` [__-File__ -`<_string_>`] **[-Inc** `<_SwitchParameter_>`] - -[`<_CommonParameters_>`] - -**PARAMETERS** - -**-Web** `<_SwitchParameter_>` - -Specify the update uses the NTLM Hashes file from the netwrix website. - -**-Folder** `<_string_>` - -Folder with the HIBP database. Can also use **-D** or **-d**. - -**-Inc** `<_SwitchParameter_>` - -Type of update. Specify **full** to update the entire database or **incremental**to add new entries -to the existing database. Can also use **-I** or **-i**. - -**-File** `<_string_>` - -File with list of NTLM hashes. Can also use **-S** or **-s**. - -`<_CommonParameters_>` - -This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorAction**, -**ErrorVariable**, **WarningAction**, **WarningVariable**, **OutBuffer**, **PipelineVariable**, and -**OutVariable**. See [about_CommonParameters](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_commonparameters?view=powershell-7.5). - -**EXAMPLE** - -PS C:\> Start-PPEHibpUpdater -Folder "C:\HIBP\DB" -File "C:\Users\Administrator\Desktop\db for HIBP -Updater not real small\stealthintercept-hibp-database-1.0.0.zip - -![HIBP Update](/images/passwordpolicyenforcer/11.2/administration/cmdletstartppehibpupdater.webp) diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/_category_.json b/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/_category_.json deleted file mode 100644 index 278fe80f06..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Rules", - "position": 10, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "rules" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/testpolicy.md b/docs/passwordpolicyenforcer/11.2/admin/manage-policies/testpolicy.md deleted file mode 100644 index b768040759..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/testpolicy.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Test Policy" -description: "Test Policy" -sidebar_position: 60 ---- - -# Test Policy - -You can quickly test your Password Policy Enforcer configuration by simulating a password change. -Click **Test Policy** from the Configuration Console dashboard or when you are setting up a policy. -Test policy opens in a separate window. Remember to **Save** your rules and changes before -testing. - -Test policy opens on the **By user** tab. - -![Test by User](/images/passwordpolicyenforcer/11.2/administration/testuser.webp) - -## By User - -Policy testing simulates a password change, but it doesn't change the password. - -**Step 1 –** Click **Test policy** from the Configuration Console dashboard or when you are setting -up a policy. - -**Step 2 –** Select a **user**. - -**Step 3 –** **Type in a password to simulate its change**. As you type, Password Policy Enforcer evaluates the new password and displays the results. - -![Failing Password](/images/passwordpolicyenforcer/11.2/administration/testuserfail.webp) - -The entered password is failing in this example, due to not meeting the length requirement. There is -a red x indicating the failure. You can hover over the requirements to see the rule name. - -In this example, the password passes. Notice the green check beside the entered password. - -![Passing password](/images/passwordpolicyenforcer/11.2/administration/testuserpass.webp) - -Expand the **View log** for details: - -- Computer the configuration was read from. -- Policy was assigned to the user, and why. -- Dictionary word or keyboard pattern matched with the password. -- Errors or warnings occurred during testing. - -Turn on **Verbose Logging** to view the performed tests and results. - -![Verbose logging](/images/passwordpolicyenforcer/11.2/administration/testuserverbose.webp) - -## Bulk Password Test - -The Bulk Password Test feature lets you check a large number of passwords against a selected policy and get a report of the accepted and rejected passwords. - -**Step 1 –** Click **Test policy** from the Configuration Console dashboard or when you are setting -up a policy. - -**Step 2 –** Open the **Password bulk test** tab. - -![Password bulk test](/images/passwordpolicyenforcer/11.2/administration/testbulk.webp) - -**Step 3 –** Select a policy for the test. - -**Step 4 –** **Browse** to the text file containing the passwords to test. Processing is faster if -the file isn't on a shared drive. - -**Step 5 –** Click **Test passwords**. The **Statistics** are displayed. - -![Test results](/images/passwordpolicyenforcer/11.2/administration/testbulkresult.webp) - -| Statistics of the Bulk Password Testing | | -| --------------------------------------- | --------------------------------------------------------------------------------------- | -| Status | Shows whether the operation is ready for scanning, processing, terminated, or finished. | -| Tested | Number of tested passwords. | -| Accepted | Number of accepted passwords. | -| Rejected | Number of rejected passwords. | -| Number of lines | Number of lines within the file. | -| Lines processed | Shows the number of the processed lines. | - -Click **Show full report** to view the test details. - -![Test Bulk Report](/images/passwordpolicyenforcer/11.2/administration/testbulkreport.webp) - -You can use the **Report settings** to customize the report: - -- Result report folder. Processing is faster if this isn't a shared drive. -- Show accepted passwords -- Show rejected passwords - -## Policy Testing vs. Password Changes - -- Policy testing simulates a password change, but it may not always reflect what happens when a user - changes their password. A password change may yield different results to a policy test because: -- Policy testing doesn't simulate the Windows password policy rules. If the Windows password rules - are enabled, then Windows may reject a password even though it complies with all the Password - Policy Enforcer rules. -- Policy testing doesn't enforce the Minimum Age rule. -- Policy testing doesn't enforce the History rule. -- Policy testing enforces the password policy even if Password Policy Enforcer or the assigned - policy is disabled. Use this to test your configuration before enabling Password Policy - Enforcer, or a new password policy. -- Policy testing occurs on the computer that the Configuration Console is running on. If the Configuration Console - is connected to a remote domain configuration, then it may not find the dictionary file on - the local computer, or the local dictionary file may be different to the one on the domain - controller. Copy the dictionary file onto the local computer (in the same path) to avoid this - problem. -- If the Configuration Console is connected to a domain configuration and you recently modified the Password Policy Enforcer - configuration, then Active Directory may still be propagating the new - configuration to the other domain controllers. diff --git a/docs/passwordpolicyenforcer/11.2/admin/password-policy-client/password_policy_client.md b/docs/passwordpolicyenforcer/11.2/admin/password-policy-client/password_policy_client.md deleted file mode 100644 index 7c3578ecae..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/password-policy-client/password_policy_client.md +++ /dev/null @@ -1,29 +0,0 @@ ---- -title: "Password Policy Client" -description: "Password Policy Client" -sidebar_position: 50 ---- - -# Password Policy Client - -The Password Policy Client helps users to choose a compliant password. Detailed information is -provided if their new password is rejected. - -The Password Policy Client is optional. If it isn't installed, the -[Similarity Rule](/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/similarity_rule.md) can't be enforced. Users only see the default Windows error -message if their password is rejected, not the detailed help they receive from the Password Policy -Client. - -![the_password_policy_client](/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client.webp) - -![the_password_policy_client_1](/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client_1.webp) - -The Password Policy Client displays the password policy during a password change so that users can -see the policy while they choose their password. The Password Policy Client also displays a detailed -rejection message to explain why a password was rejected. Both these messages are customizable. - -:::note -The Password Policy Client doesn't modify any Windows system files. It also doesn't send -passwords or password hashes over the network. - -::: diff --git a/docs/passwordpolicyenforcer/11.2/admin/ppe_tool.md b/docs/passwordpolicyenforcer/11.2/admin/ppe_tool.md deleted file mode 100644 index ed70ed2e1b..0000000000 --- a/docs/passwordpolicyenforcer/11.2/admin/ppe_tool.md +++ /dev/null @@ -1,179 +0,0 @@ ---- -title: "PPE Tool" -description: "PPE Tool" -sidebar_position: 80 ---- - -# PPE Tool - -The PPE Tool is designed to configure local and domain instances of Password Policy Enforcer and -produce reports pertaining to the configuration of Password Policy Enforcer. The PPE Tool is -designed to perform the following functions: - -- Export the configuration from the existing instance of Password Policy Enforcer, regardless if the - server is local or domain. -- Import existing PPE configurations on another PPE server instance. -- Generate user-friendly reports that contain configuration values and descriptions. -- Create HTML reports with configuration values and descriptions of the PPE server instance. - -This topic covers how to install the PPE Tool, how to customize and run reports, and how to review configuration options in the PPE Tool. - -## Using the PPE Tool - -The PPE Tool installs with the default installation of Password Policy Enforcer under the -`C:\Program Files\Netwrix\Password Policy Enforcer\ppetool` folder. After installation, the PPE Tool supports a number of operations related to Password Policy Enforcer functionality, which are described in the following table. - -:::note -All PPE Tool operations can be executed from the Command Prompt, if run with administrator -rights. -::: - - -### PPE Tool Operations - -:::info -PPE Tool operations should only be executed one at a time. For example, you -shouldn't execute the /e (Export) and /i (Import) operations simultaneously; you shouldn't run /e -(Export) and /r (Report) operations simultaneously. -::: - - -**Common PPE Tool Operations** - -| Operation | Operation Name | Operation Description | -| --------- | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| /? | help |

  • Displays Help and exits the application. All other options are ignored.
| -| /m | minimal |
  • Configures the PPE Tool to operate in Minimal mode.
  • This operation strips away all extraneous information (e.g., policy messages, license information, etc.) while importing or exporting to the PPE Tool.
  • By default, the PPE Tool imports and exports all information available (e.g., policy messages, license information, etc.).
| -| /d | domain [in controller] |
  • Configures the PPE Tool to operate in Domain mode.
  • The default controller is localhost.
  • This operation makes PPE Tool work with the LDAP Password Policy Enforcer instance. PPE Tool imports or exports configurations from the local registry.
  • To use this operation , you must run PPE Tool as a domain administrator user. However, this operation can be used on both the domain controller and on any member. If an invalid domain controller is provided as an argument, then the PPE Tool will fail at the import / export stage.
  • This operation is ignored when used to create reports from the file source (present with the /c (Config [in file name]) option). When the PPE Tool starts in a domain environment without the /d (Domain [in controller]) operation, a warning message appears. However, this won't prevent the PPE Tool from operating on a local environment.
| -| /c | config [in file name] |
  • Uses a config file instead of Password Policy Enforcer export when exporting reports (in the case of /i (Import), /h (Human [out file name]), and /r (Report [out file name]).
  • The default file is `config.xml`.
  • This operation defines the input file for the i/ (Import) operation, and thus is necessary for importing files to the PPE Tool. An error message will appear if the /c (Config [in file name]) option is omitted.
  • By default, the /h (Human [out file name]) and /r (Report [out file name]) operations use the Password Policy Enforcer instance as the reporting source. The /c (Config [in file name]) operation should provide the source configuration file as an argument to create reports. If an invalid file name is provided as an argument in this operation, the PPE Tool displays the appropriate error message and exits.
| - - -Operations PPE Tool options are as follows: - -| Task | Task Name | Task Description | -| ---- | ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| /e | export [out file name] |
  • Exports config data (default) from the Password Policy Enforcer instance to the file.
  • This operations is enabled by default.
  • This operation can't be used with /c (Config [in file name]) or i/ (Import) operations, but can be combined with /h (Human [out file name]).
| -| /i | import |
  • Imports the config file.
  • Imports existing configuration using the input configuration file defined by the /d (Domain [in controller]) . If the /c (Config [in file name]) operation is omitted, the PPE Tool displays an error message and exits.
  • When i/ (Import) is used with the /h (Human [out file name]) or /r (Report [out file name]) operations, the latter is ignored.
  • /d (Domain [in controller]) and /m (Minimal) operations may affect the result of the import.
| -| /h | human [out file name] |
  • Converts the config file to a human-readable format and produces a human-readable report based on the current Password Policy Enforcer instance configuration or the configuration provided by the /d (Domain [in controller]).
  • If no custom file name is provided, the default file name is `config_human_readable.xml`.
| -| /r | report [out file name] |
  • Converts the config file to HTML and produces an HTML report file based on the current Password Policy Enforcer instance configuration or the configuration provided by the /d (Domain [in controller]).
  • Generates the HTML report into `C:\Program Files\Netwrix\Password Policy Enforcer\Report` alongside the .css file.
  • The default files name is `report.html`.
| - - -### PPE Usage Samples - -This section covers some sample operations usable in either the PPE Tool or in the Command console -(with administrator rights). Each operation can be executed after the following commands have been -executed: - -C:\Windows/system32>cd.. - -`C:\`[location of PPE Tool]`>`[operation] - -After this location has been accessed in the Command console, enter one of the following commands in -the [operation] variable above to execute a PPE Tool operation in the Command console. - -| Action | Operation | Message | -| -------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Simple Config export operation |
  • ppetool
| Warning: PPETool started in domain environment without /d option. Using local source. Hope you know what are you doing. Config successfully exported. | -| Simple Config export in domain environment with DC %Full computer name of Domain Controller% |
  • ppetool /d localhost
  • ppetool /d %Full computer name of Domain Controller%
| Config successfully exported. | -| Export local config into local.xml and create it from the HR.xml and report.html reports |
  • ppetool /e local.xml /h HR.xml /r Report.html
| Warning: PPETool started in domain environment without /d option. Using local source. Hope you know what are you doing. Config successfully exported. Human readable config representation successfully exported. HTML config representation exported successfully. | -| Import Config from config.xml |
  • ppetool /c config.xml /i
| Warning: PPETool started in domain environment without /d option. Using local source. Hope you know what are you doing. Config import successful. | - - -### Generating Reports with Custom Descriptions - -The PPE Tool generates user-friendly reports by processing configuration tags (i.e., ``). For -example, the PPE Tool searches for the file tagname.xml (or, ppe.xml in this case). This file has -root elements which name match each file name. Each root tag contains child tags (e.g., ``). -Each tag has the following attributes: - -- name — Contains the original tag name from the input configuration file. If this attribute is - missed, then the original tag and its value are absent in the human-readable report. -- DisplayName — Contains the user-friendly description for the original tag. If this attribute is - missed, then the original tag and its value appear in the report without a description. - -The `` tag can also contain the child `` tag. This tag can have an optional attribute -'mode' and this attribute can have the following values: - -- value (default) — With the default value, the report contains only tag descriptions for the - child `` tag. The 'value' attribute matches the child `` tag with the value of the - original tag. -- combined — With the combined value, the report contains the child `` tags which contain - values that are bitwise or are the result of the original values. - -#### Example of 'value' mode - -**Original configuration** - -```xml -1 -``` - -**Transform configuration** - -```xml - - - - - - - -``` - -**Transformation result** - -```xml - - - - - - - -``` - -#### Example of 'combined' mode - -**Original configuration** - -`25` - -**Transformation configuration** - -```xml - - - - - - - - - - - -``` - -**Result human-readable report** - -```xml - - - - - - - - - - - -``` - -### Customize HTML Report - -The PPE Tool comes with a pre-defined template.css file in the configuration folder, found here: -`C:\Program Files\Netwrix\Password Policy Enforcer\ppetool\config`. The template.css defines the visual design -(formatting, colors, fonts etc.) of HTML report. See the -[XSLT - Transformation](https://www.w3schools.com/xml/xsl_transformation.asp) article for additional -information of transforming .xml to .xhtml. diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/_category_.json b/docs/passwordpolicyenforcer/11.2/evaluation/_category_.json deleted file mode 100644 index 8ccf8e8f97..0000000000 --- a/docs/passwordpolicyenforcer/11.2/evaluation/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Evaluate Password Policy Enforcer", - "position": 50, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "evaluation_overview" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/conclusion.md b/docs/passwordpolicyenforcer/11.2/evaluation/conclusion.md deleted file mode 100644 index 02f9c9c8fc..0000000000 --- a/docs/passwordpolicyenforcer/11.2/evaluation/conclusion.md +++ /dev/null @@ -1,17 +0,0 @@ ---- -title: "Conclusion" -description: "Conclusion" -sidebar_position: 80 ---- - -# Conclusion - -You have successfully installed, configured, and tested Netwrix Password Policy -Enforcer. This guide is an introduction to Password Policy Enforcer's capabilities. You can enforce -almost any password policy imaginable with Password Policy Enforcer, customize the Password Policy -Client messages, and even synchronize passwords with other networks and applications. The -[Administration](/docs/passwordpolicyenforcer/11.2/admin/administration_overview.md) topic contains more information to -help you get the most out of Password Policy Enforcer. - -The [Password Policy Enforcer Web](/docs/passwordpolicyenforcer/11.2/web-overview/web_overview.md) application lets users securely manage their passwords from a web browser, ensuring passwords comply with the password policy, and -helping users choose compliant passwords. diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/configuring_policy_rules.md b/docs/passwordpolicyenforcer/11.2/evaluation/configuring_policy_rules.md deleted file mode 100644 index 7e1eb4fa07..0000000000 --- a/docs/passwordpolicyenforcer/11.2/evaluation/configuring_policy_rules.md +++ /dev/null @@ -1,94 +0,0 @@ ---- -title: "Configure Policy Rules" -description: "Configure Policy Rules" -sidebar_position: 40 ---- - -# Configure Policy Rules - -The policy you created doesn't enforce any password requirements yet. You can now configure -the policy to enforce these rules: - -- Password must contain at least seven characters. -- Password must contain at least one lowercase alpha character. -- Password must contain at least one uppercase character. -- Password must not be similar to the user's logon name. -- Password must not exist in a dictionary of common passwords. - -When you create a policy, the policy settings are opened. You can open the settings for a policy at -any time by clicking the policy name on the Configuration Console dashboard. - -![New policy open for settings](/images/passwordpolicyenforcer/11.2/evaluation/newpolicysettings.webp) - -Requirement: Password must contain at least seven characters. - -This condition is set with the **Length** rule. - -**Step 1 –** Select **Length**. - -**Step 2 –** Click the **Length** checkbox to enable the rule. - -**Step 3 –** Select **7** for the **At least...** value. Depending on the template, this might be -the default. - -![Set the Length](/images/passwordpolicyenforcer/11.2/evaluation/evallength.webp) - -Requirement: Password must contain at least one lowercase alpha character. - -This condition is set with the **Characters (Complexity)** rule. - -**Step 1 –** Select **Characters (Complexity)**. - -**Step 2 –** Click the **Characters (Complexity)** checkbox to enable the rule. - -**Step 3 –** Select **1** as the **Must contain at least...** value. - -**Step 4 –** Select **Lower Alpha (a-z)**. - -**Step 5 –** Select **Upper Alpha (A-Z)** for the next requirement while you are here. - -![Set upper and lower case requirements](/images/passwordpolicyenforcer/11.2/evaluation/evalchars.webp) - -Password must contain at least one uppercase character. - -This condition is set with the **Characters (Granular)** rule. - -**Step 1 –** Select **Characters (Granular)**. - -**Step 2 –** Click the **Characters (Granular)** checkbox to enable the rule. - -**Step 3 –** Select **1** as the **Must contain at least...** value. - -**Step 4 –** Select **Upper Alpha (A-Z)** **Contain** **1** or more characters. - -**Step 5 –** Select **Lower Alpha (a-z)** **Contain** **1** or more characters. - -![set character granularity](/images/passwordpolicyenforcer/11.2/evaluation/evalcharsgran.webp) - -Requirement: Password must not be similar to the user's logon name. - -This condition is set with the **Similarity** rule. - -**Step 1 –** Select **Similarity**. - -**Step 2 –** Click the **Similarity** checkbox to enable the rule. - -**Step 3 –** Select **User logon name**. - -![Set Similarity rule](/images/passwordpolicyenforcer/11.2/evaluation/evalsimilarity.webp) - -Requirement: Password must not exist in a dictionary of common passwords. - -This condition is set with the **Dictionary** rule. - -**Step 1 –** Select **Dictionary**. - -**Step 2 –** Click the **Dictionary** checkbox to enable the rule. - -**Step 3 –** Click **Browse**. - -**Step 4 –** Navigate to **\Program Files\Password Policy Enforcer** folder and select**Dict.txt**. - -![Enable the sample dictionary](/images/passwordpolicyenforcer/11.2/evaluation/evaldict.webp) - -When you have added all the rules, click **Save** to save your new policy. diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/creating-a-password-policy/_category_.json b/docs/passwordpolicyenforcer/11.2/evaluation/creating-a-password-policy/_category_.json deleted file mode 100644 index b944d1d256..0000000000 --- a/docs/passwordpolicyenforcer/11.2/evaluation/creating-a-password-policy/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Create a Password Policy", - "position": 30, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "creating_a_password_policy" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/creating-a-password-policy/policy_templates.md b/docs/passwordpolicyenforcer/11.2/evaluation/creating-a-password-policy/policy_templates.md deleted file mode 100644 index 04045959ca..0000000000 --- a/docs/passwordpolicyenforcer/11.2/evaluation/creating-a-password-policy/policy_templates.md +++ /dev/null @@ -1,48 +0,0 @@ ---- -title: "Policy Templates" -description: "Policy Templates" -sidebar_position: 10 ---- - -# Policy Templates - -Password Policy Enforcer contains Built-in Policy Templates based on the requirements of the -most popular regulatory frameworks. - -- Center for Internet Security (CIS) Password Policy Guide – See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- Center for Internet Security (CIS) Password Policy Guide MFA – See the - [CIS Password Policy Guide](https://www.cisecurity.org/insights/white-papers/cis-password-policy-guide) - article for additional information. -- Cybersecurity Information Sharing Act (CISA) -- Criminal Justice Information Services (CJIS) Security Policy -- Cybersecurity Maturity Model Certification (CMMC) -- Defense Federal Acquisition Regulation Supplement (DFARS) -- Gramm-Leach-Bliley Act (FedRAMP) -- Federal Information Security Management Act (FISMA) -- Health Insurance Portability and Accountability Act (HIPPA) – HIPAA Security Rule requires that - organizations must implement procedures for creating, changing, and safeguarding passwords. - - - It also recommends training the workforce on ways to safeguard password information and - establish guidelines to create and change passwords in a periodic cycle. - - HIPAA doesn’t offer any specific password complexity guidelines. To comply with HIPAA, - organizations are better off following NIST password guidelines. - - Most of healthcare institutions use the NIST framework. - -- International Organization for Standardization (ISO/IEC) 27002 – See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. -- North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) – - See the - [CIP-007-6 — Cyber Security – Systems Security Management](https://www.nerc.com/_layouts/15/PrintStandard.aspx?standardnumber=CIP-007-6&title=Cyber%20Security%20-%20System%20Security%20Management&Jurisdiction=United%20States) article - for additional information. -- National Institute of Standards and Technology (NIST) Special Publication 800-171 -- National Institute of Standards and Technology (NIST) Special Publication 800-53 -- National Institute of Standards and Technology (NIST) Special Publication 800-63b – See the - [NIST Special Publication 800-63B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf) article - for additional information. -- Payment Card Industry Data Security Standard (PCI DSS) – See the - [PCI Document Library](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss) web - site for additional information. -- Payment Card Industry Data Security Standard (PCI DSS) (version 4) diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/evaluation_overview.md b/docs/passwordpolicyenforcer/11.2/evaluation/evaluation_overview.md deleted file mode 100644 index c1f7272970..0000000000 --- a/docs/passwordpolicyenforcer/11.2/evaluation/evaluation_overview.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -title: "Evaluate Password Policy Enforcer" -description: "Evaluate Password Policy Enforcer" -sidebar_position: 50 ---- - -# Evaluate Password Policy Enforcer - -Netwrix Password Policy Enforcer is an advanced password filter for Windows. Use this guide to -quickly install, configure, and test an evaluation version of Password Policy Enforcer. Netwrix -Password Policy Enforcer helps secure your network by ensuring users set strong passwords. When a -user enters a password that doesn't comply with the password policy, Password Policy Enforcer -immediately rejects the password and details why the password was rejected. - -![introduction_3](/images/passwordpolicyenforcer/11.2/evaluation/introduction_3.webp) - -Unlike password cracking products that check passwords after they are accepted by the operating -system, Password Policy Enforcer checks new passwords immediately to ensure that weak passwords do -not jeopardize system security. - -:::note -You can also use Password Policy Enforcer to ensure that passwords are compatible with -other systems, and to synchronize passwords with other systems and applications. - -::: diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/improving_the_password_policy.md b/docs/passwordpolicyenforcer/11.2/evaluation/improving_the_password_policy.md deleted file mode 100644 index 56d15b6a89..0000000000 --- a/docs/passwordpolicyenforcer/11.2/evaluation/improving_the_password_policy.md +++ /dev/null @@ -1,45 +0,0 @@ ---- -title: "Improve the Password Policy" -description: "Improve the Password Policy" -sidebar_position: 60 ---- - -# Improve the Password Policy - -Password Policy Enforcer rules have properties that control how rules are enforced. You can improve -the effectiveness of the Users policy by enabling character substitution detection and -bi-directional analysis (words typed backwards) for the **Similarity** and **Dictionary** rules. - -When character substitution detection is enabled, Password Policy Enforcer searches passwords for -common character substitutions. For example, an S replaced with a $. If a password only complies -with the policy because of the substitution ( the substitution is needed to make the password -compliant), then Password Policy Enforcer rejects the password. - -Bi-directional analysis tests passwords with their characters reversed to stop users from -circumventing a rule by entering a non-compliant password backwards. For example, "drowssapym" -instead of "mypassword". - -Click your policy name on the Configuration Console dashboard if needed. - -**Step 1 –** Open the **Dictionary** rule. - -![Open the Dictionary rule](/images/passwordpolicyenforcer/11.2/evaluation/evaldict.webp) - -**Step 2 –** Select the **Detect character substitution** and **Detect words typed backwards** check -boxes. - -**Step 3 –** Open the **Similarity** rule. - -**Step 4 –** For **User logon name** select **Yes** for **Character substitution** and **Words typed -backwards**. - -**Step 5 –** Click **Save**. - -Test the improved policy with passwords that were accepted under the previous policy. Password -Policy Enforcer should reject all of them. - -| Password | Result | Reason | -| -------- | -------- | ---------------------------------- | -| tseTEPP | Rejected | Similar to user logon name | -| kravdraA | Rejected | Similar to word in dictionary file | -| Aardv@rk | Rejected | Similar to word in dictionary file | diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/installforeval.md b/docs/passwordpolicyenforcer/11.2/evaluation/installforeval.md deleted file mode 100644 index cf1e299991..0000000000 --- a/docs/passwordpolicyenforcer/11.2/evaluation/installforeval.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -title: "Install Password Policy Enforcer for Evaluation" -description: "Install Password Policy Enforcer for Evaluation" -sidebar_position: 20 ---- - -# Install Password Policy Enforcer for Evaluation - -The evaluation installation uses the standard installation packages: - -- Server Installation: install on each server and domain controller in the domain you are - evaluating. You can install manually using the procedure in - [Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.2/installation/installationserver.md) or automatically - with [Install with Group Policy Management](/docs/passwordpolicyenforcer/11.2/installation/installationgpm.md) procedure. Installing - Password Policy Enforcer doesn't extend the Active Directory schema. Be sure and install the - **Configuration Console** feature on at least one server. -- Client Installation: install on each workstation you are evaluating. The Password Policy Client is - an optional Password Policy Enforcer component to help users choose compliant passwords. Follow - the [Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.2/installation/installationclient.md) procedure, or - [Install with Group Policy Management](/docs/passwordpolicyenforcer/11.2/installation/installationgpm.md). - -You may need to create a firewall port exception on the domain controllers if you are evaluating the -Password Policy Client on a domain with client computers. See the -[Password Policy Client](/docs/passwordpolicyenforcer/11.2/admin/password-policy-client/password_policy_client.md) topic for additional -information. diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/testing_the_password_policy.md b/docs/passwordpolicyenforcer/11.2/evaluation/testing_the_password_policy.md deleted file mode 100644 index b77654438c..0000000000 --- a/docs/passwordpolicyenforcer/11.2/evaluation/testing_the_password_policy.md +++ /dev/null @@ -1,140 +0,0 @@ ---- -title: "Test the Password Policy" -description: "Test the Password Policy" -sidebar_position: 50 ---- - -# Test the Password Policy - -You can test the policy from the policy settings right where you are in the policy settings. You can -also test it from the Password Policy Enforcer configuration console dashboard, the Windows Change -Password screen, or the Active Directory Users and Computers / Local Users and Groups consoles. - -## Configuration Console - -Test policy is available in the policy settings and on the configuration console dashboard. This -option shows you the most information about the policy. - -**Step 1 –** Click **Test policy**. - -**Step 2 –** Select the **PPETestUser** you created. The details pane displays the policy applied to -the selected user. - -![Enter user name for the test](/images/passwordpolicyenforcer/11.2/evaluation/evaltestuser.webp) - -**Step 3 –** Enter a password to test. - -The Password Policy Enforcer configuration console tests the password by simulating a password -change, but it doesn't change the user's password. A green check mark indicates the password -complies, a red and white x indicates the password fails. Detailed test results appear in the -results pane. - -**mypassword** fails two requirements. You can hover over the requirements to view the associated -rule. - -![mypassword fails](/images/passwordpolicyenforcer/11.2/evaluation/evaltestuserfail.webp) - -Click **View log** to expand Password Policy Enforcer's internal event log. The information in the -event log can help you to understand why Password Policy Enforcer accepted or rejected a password. - -:::note -Policy testing simulates a password change, but it may not always reflect what happens -when a user changes their password. See the -[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.2/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) -topic for additional information. -::: - - -## Windows Change Password Screen - -This is how most users change their password. Testing password policies from the Windows Change -Password screen is useful because it shows you exactly what your users see. - -From the Windows Change Password screen: - -**Step 1 –** Press **CTRL + ALT + DEL**. - -**Step 2 –** Click the **Change a password** option. - -**Step 3 –** Enter a user name in the User name text box. - -**Step 4 –** Enter passwords in the Old Password, New Password, and Confirm Password text boxes. - -**Step 5 –** Click the **submit arrow**. - -You may have noticed that the Change Password screen looks different after installing Password -Policy Enforcer. The Password Policy Enforcer password policy is shown during password changes if -the Password Policy Client is installed. This helps users to choose a compliant password. The -Password Policy Client also changes the message that users see when their password is rejected. Both -these messages are customizable. - -![introduction_3](/images/passwordpolicyenforcer/11.2/evaluation/introduction_3.webp) - -The Password Policy Client doesn't modify any Windows system files, and you don't have to install -it to enforce a Password Policy Enforcer password policy. Web browser based versions of the Password -Policy Enforcer Client are also available. - -## Active Directory Users / Computers Console and local Users and Groups Console - -Administrators often change domain passwords from the Active Directory Users and Computers console -and local passwords from the Local Users and Groups console. In fact, these consoles don't change -passwords; they reset them. This is an important distinction because a password reset is: - -- Restricted to privileged users -- Performed without knowing the current password - -Password Policy Enforcer can enforce the password policy for both password changes and password -resets. It does this by default, but you can configure it to only enforce the password policy for -password changes. The Minimum Age rule is never enforced when a password is reset. - -Follow the steps to test password policies from these consoles. - -**Step 1 –** Open the appropriate console: - -- If Password Policy Enforcer is enforcing a domain policy, open the Active Directory Users and - Computers console -- If Password Policy Enforcer is enforcing a local policy, open the Local Users and Groups console - -**Step 2 –** Right-click a user, then click **Reset Password**. - -**Step 3 –** Enter a password in the **New password** and **Confirm password** text boxes. - -**Step 4 –** Click **OK**. - -:::note -These consoles don't explain why a password was rejected. Use the Password Policy -Enforcer configuration console, or the Change Password screen with the Password Policy Enforcer -Client installed to see this information. -::: - - -Here are some sample passwords and expected test results when the Users policy is enforced. Try to -change the password for the PPETestUser account to confirm that Password Policy Enforcer is -enforcing the password policy correctly. - -| Password | Result | Reason | -| -------- | -------- | -------------------------------------------- | -| AbdF6 | Rejected | Doesn't contain at least 7 characters | -| abd65fgo | Rejected | Doesn't contain an upper alpha character | -| ABD65FGO | Rejected | Doesn't contain a lower alpha character | -| PPETest1 | Rejected | Similar to user logon name | -| Aardvark | Rejected | Similar to common password (dictionary file) | -| tseTEPP | Accepted | N/A | -| kravdraA | Accepted | N/A | -| Aardv@rk | Accepted | N/A | - -Password Policy Enforcer accepts the last three passwords in the table because they comply with the -password policy, but this highlights some weaknesses in this policy: - -- tseTEPP is part of the user logon name with the characters reversed -- kravdraA is Aardvark with the characters reversed -- Aardv@rk is Aardvark with an @ substituting an "a." - -These three passwords are only marginally stronger than the rejected passwords. The next section -shows you how to improve the password policy so Password Policy Enforcer rejects these passwords. - -:::note -Contact [Netwrix support](mailto:support@anixis.com) if Password Policy Enforcer isn't -working as expected. - -::: diff --git a/docs/passwordpolicyenforcer/11.2/installation/_category_.json b/docs/passwordpolicyenforcer/11.2/installation/_category_.json deleted file mode 100644 index 0f6ac7ae2c..0000000000 --- a/docs/passwordpolicyenforcer/11.2/installation/_category_.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "label": "Installation", - "position": 30, - "collapsed": true, - "collapsible": true -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.2/web-overview/_category_.json b/docs/passwordpolicyenforcer/11.2/web-overview/_category_.json deleted file mode 100644 index 641fa612e9..0000000000 --- a/docs/passwordpolicyenforcer/11.2/web-overview/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "Password Policy Enforcer Web", - "position": 60, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "web_overview" - } -} \ No newline at end of file diff --git a/docs/passwordpolicyenforcer/11.2/web-overview/configuration.md b/docs/passwordpolicyenforcer/11.2/web-overview/configuration.md deleted file mode 100644 index d54297fd37..0000000000 --- a/docs/passwordpolicyenforcer/11.2/web-overview/configuration.md +++ /dev/null @@ -1,85 +0,0 @@ ---- -title: "Configuration" -description: "Configuration" -sidebar_position: 40 ---- - -# Configuration - -Click **Start** >**[All] Programs** > **PPE Web Configuration Console** to open the Password Policy -Enforcer Web Configuration Console. - -## General Tab - -Use the General tab to maintain the list of managed domains, and to configure Password Policy -Enforcer integration. See the Password Policy Enforcer topic for additional information. - -![configuring_ppe_web](/images/passwordpolicyenforcer/11.2/web/configuring_ppe_web.webp) - -### Domain List - -When Password Policy Enforcer Web is first installed, the Domain List is empty and users must type -their domain name. You can configure Password Policy Enforcer Web to display a list of domains -instead of an empty text box. - -**Add Domain** - -Follow the steps to add a domain to the list. - -**Step 1 –** Click the **Add...** button. - -**Step 2 –** Enter a NetBIOS (NT Compatible) or DNS domain name. - -**Step 3 –** Click **OK**, the click **Apply**. - -:::note -Put the most frequently used domain first in the list — it is the default. You -can rearrange the domains by dragging them to another position. You can also click **Sort** to sort -them alphabetically. -::: - - -**Remove Domain** - -Follow the steps to remove a domain from the list. - -**Step 1 –** Select the domain name from the Domain List. - -**Step 2 –** Click **Remove**, then click **Yes** when asked to confirm. - -**Step 3 –** Click **Apply**. - -### Password Policy Enforcer - -Password Policy Enforcer is a configurable password filter that enforces granular password policies -with many advanced features. Password Policy Enforcer Web can integrate with Password Policy -Enforcer to help users choose a compliant password. - -![configuring_ppe_web_1](/images/passwordpolicyenforcer/11.2/web/configuring_ppe_web_1.webp) - -Password Policy Enforcer Web displays the Password Policy Enforcer password policy message when a -user is prompted for their new password, and the Password Policy Enforcer rejection message if the -new password doesn't comply with the password policy. Select the **Password Policy Enforcer -integration** checkbox if you have installed and configured Password Policy Enforcer on your domain -controllers. - -You can also set the Port, Timeout, and number of Retries for the Password Policy Protocol if the -defaults aren't suitable. - -:::note -A Password Policy Enforcer Web license doesn't include a Password Policy Enforcer -license. See [Netwrix Password Policy Enforcer](https://www.netwrix.com/password_policy_enforcer.html) for licensing information. -::: - - -## About Tab - -The **About** tab contains version and license key information. - -To install a new license key. - -**Step 1 –** Copy the entire license e-mail to the clipboard. - -**Step 2 –** Click **Get license from clipboard**. - -**Step 3 –** Click **Apply**. diff --git a/docs/passwordpolicyenforcer/11.2/web-overview/securing_web.md b/docs/passwordpolicyenforcer/11.2/web-overview/securing_web.md deleted file mode 100644 index 111fa59091..0000000000 --- a/docs/passwordpolicyenforcer/11.2/web-overview/securing_web.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -title: "Secure Password Policy Enforcer Web" -description: "Secure Password Policy Enforcer Web" -sidebar_position: 50 ---- - -# Secure Password Policy Enforcer Web - -Password Policy Enforcer Web is designed to operate securely, but you must ensure that the web -server is also secure. Follow Microsoft's recommendations to secure the web server, and always -install and use an SSL certificate if Password Policy Enforcer Web is used on an unencrypted network. - -## Install an SSL Certificate - -Password Policy Enforcer Web sends passwords to the domain controllers over a secure connection, but -you need to set up SSL (Secure Sockets Layer) encryption for the connection between the web browser -and the web server. - -:::warning -Don't use Password Policy Enforcer Web on a production network without SSL encryption. -::: - - -You can use a self-signed certificate, but most organizations purchase certificates from a -certificate authority. This is a recurring cost, and you must complete forms for the certificate authority to verify your identity. You can install Password Policy Enforcer Web on a server that already has an SSL certificate to avoid purchasing another one. - -The IIS documentation explains how request, install, and use SSL certificates. - -See the -[Configure Server Certificates in IIS 7](https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc732230(v=ws.10)?redirectedfrom=MSDN) -Microsoft knowledge base article for additional information. - -Ensure that users only access Password Policy Enforcer Web over an encrypted connection after the -SSL certificate is installed. The URL should start with https://. Web browsers can be redirected to -always use the secure URL. diff --git a/docs/passwordpolicyenforcer/11.2/web-overview/using_web.md b/docs/passwordpolicyenforcer/11.2/web-overview/using_web.md deleted file mode 100644 index c084bff0cf..0000000000 --- a/docs/passwordpolicyenforcer/11.2/web-overview/using_web.md +++ /dev/null @@ -1,78 +0,0 @@ ---- -title: "Launch Password Policy Enforcer Web" -description: "Launch Password Policy Enforcer Web" -sidebar_position: 30 ---- - -# Launch Password Policy Enforcer Web - -The default URL for Password Policy Enforcer Web is: `http://[server]/ppeweb/` - -Where [server] is the name or IP address of the server hosting Password Policy Enforcer Web. - -![Web Welcome page](/images/passwordpolicyenforcer/11.2/web/webwelcome.webp) - -The default page is called the Welcome page. You can customize the information on this page by -editing **en_default.htm**, or you can bypass this page and send users directly to the Password -Change page: - -`http://[server]/ppeweb/ppeweb.dll` - -You can also include the username and/or domain in the URL: - -`http://[server]/ppeweb/ppeweb.dll?username=maryjones&domain=ANIXIS` - -:::info -Install the SSL Certificate the web server and use the HTTPS protocol if Password -Policy Enforcer Web is used on an unencrypted network. See the -[Install an SSL Certificate](/docs/passwordpolicyenforcer/11.2/web-overview/securing_web.md) topic for additional -information. -::: - - -:::note -A license reminder message is shown occasionally when Password Policy Enforcer Web is used -without a license key. Contact Netwrix support if you would like to evaluate Password Policy -Enforcer Web without the reminder message. -::: - - -## Change Password - -To change a password with Password Policy Enforcer Web: - -**Step 1 –** Click **Change Password** on the Welcome page. - -![using_ppe_web](/images/passwordpolicyenforcer/11.2/web/using_ppe_web.webp) - -**Step 2 –** Enter a **Username** and **Domain**, then click **Next**. - -![introduction_4](/images/passwordpolicyenforcer/11.2/web/introduction_4.webp) - -**Step 3 –** Enter the **Old Password**, **New Password**, and **Confirm Password**, then click -**Next**. - -:::note -Windows increments the bad password count in Active Directory every time a user enters -their old password incorrectly. This may trigger a lockout if the Windows account lockout policy is -enabled. -::: - - -## Error Messages - -Validation errors are shown in a yellow box below the page instructions. Validation errors are -normally caused by invalid user input. They can often be overcome by changing the value of one or -more input fields and resubmitting the form. - -![using_ppe_web_1](/images/passwordpolicyenforcer/11.2/web/using_ppe_web_1.webp) - -Critical errors are shown on their own page. These errors are mostly a result of configuration or -system errors. Users can sometimes overcome a critical error by following the instructions in the -error message, but most critical errors are beyond the user's control. - -![using_ppe_web_2](/images/passwordpolicyenforcer/11.2/web/using_ppe_web_2.webp) - -Validation and critical error messages are stored in the HTML templates. You can modify the default -messages by editing the templates. See the [Edit HTML Templates](/docs/passwordpolicyenforcer/11.2/web-overview/editing_html_templates.md) topic -for additional information. diff --git a/docs/passwordpolicyenforcer/CLAUDE.md b/docs/passwordpolicyenforcer/CLAUDE.md index 689695cd17..2f37e4838a 100644 --- a/docs/passwordpolicyenforcer/CLAUDE.md +++ b/docs/passwordpolicyenforcer/CLAUDE.md @@ -13,37 +13,20 @@ This file scopes guidance to the **Password Policy Enforcer (PPE)** product docu ## Versions -| Version | Status | Notes | -|---|---|---| -| `11.2` | Latest (default) | Active version — most edits land here | -| `11.1` | Hidden | Previous minor; don't surface in navigation | -| `11.0` | Hidden | Kept for users on 11.0; don't surface in navigation | -| `10.2` | Hidden | Legacy; different section layout (see below) | +PPE is a **single-version (SaaS-style)** product using `version: "current"` — there is no version selector. All content lives directly under `docs/passwordpolicyenforcer/` with no version subfolder. -Edits to one version **do not** propagate. Apply changes to each version explicitly when they apply to more than one. When a change only applies to 11.2 (new feature, renamed control), note that clearly and skip the older versions. +## Section Layout -## Section Layout Differences - -The layout was reorganized between 10.2 and 11.x. When moving content between versions, map sections — don't assume paths match. - -**11.x (`11.2/`, `11.1/`, `11.0/`):** - `admin/` — Administration overview, cmdlets, Configuration Console, Compromised Password Check, Password Policy Client, PPE Tool, system audit, troubleshooting, Windows Event Viewer, `manage-policies/` (policies, messages, passphrases, properties, test, users/groups, `rules/`) - `installation/` — Server, Client, Configuration Console, Mailer, Web, GPM, HIBP Updater, domain vs. local policies, upgrade, uninstall, writeback - `web-overview/` — Web component overview, configuration, securing, using, editing HTML templates - `evaluation/` — Evaluation-mode walkthrough -- `gettingstarted.md`, `index.md` at the root +- `index.md` at the root - `kb/` — product-specific KB categories -**10.2:** -- `administration/` — merges what 11.x splits across `admin/` + `installation/` (installation, management console, managing policies, rules, passwordpolicyclient, mailer, properties, etc.) -- `web/` — equivalent to 11.x `web-overview/`, plus `installation.md` (in 11.x this moved to `installation/installationweb.md`) -- `evaluation/`, `kb/`, `index.md` - -When porting or comparing content, expect renames: `administration/managementconsole/` ↔ `admin/configconsole.md`, `administration/installation/` ↔ `installation/`, `web/installation.md` ↔ `installation/installationweb.md`. - ## Knowledge Base -The in-version `kb/` folder is organized into categories the PPE KB actually uses: +The in-product `kb/` folder is organized into categories the PPE KB actually uses: - `authentication-and-integration/` - `email-and-mailer-configuration/` @@ -52,18 +35,18 @@ The in-version `kb/` folder is organized into categories the PPE KB actually use - `troubleshooting-and-errors/` - `ppe-supportability.md` (top-level) -KB articles are **canonically** in `/docs/kb/` and copied into each version's `kb/` folder by `scripts/copy-kb-to-versions.mjs` at build. Never hand-edit files inside `docs/passwordpolicyenforcer//kb/` — edit the source in `/docs/kb/` instead. KB images live in `0-images/` subdirectories and are managed by the same script. +KB articles are **canonically** in `/docs/kb/` and copied into `docs/passwordpolicyenforcer/kb/` by `scripts/copy-kb-to-versions.mjs` at build. Never hand-edit files inside `docs/passwordpolicyenforcer/kb/` — edit the source in `/docs/kb/` instead. KB images live in `0-images/` subdirectories and are managed by the same script. ## Images -- Path: `static/images/passwordpolicyenforcer//...` (`.webp`) -- Reference in markdown with absolute paths: `/images/passwordpolicyenforcer//
/.webp` -- Some PPE pages reference images stored under `static/images/passwordreset/` because PPE and Password Reset share UI surfaces — don't "fix" these cross-product references without verifying the target doesn't exist under PPE. +- Path: `static/images/passwordpolicyenforcer/...` (`.webp`) +- Reference in markdown with absolute paths: `/images/passwordpolicyenforcer/
/.webp` +- Some PPE pages reference images stored under `static/images/passwordreset/`, and Password Reset pages reference images under `static/images/passwordpolicyenforcer/passwordreset/` and `static/images/passwordpolicyenforcer/password_reset/` — PPE and Password Reset share UI surfaces. Don't "fix" these cross-product references without verifying the target doesn't exist under PPE. ## Cmdlets Convention -PowerShell cmdlet pages under `11.2/admin/cmdlets/` follow a fixed naming pattern: `cmd.md` (e.g., `cmdgetppepolicies.md`, `cmdsetppeenabled.md`). New cmdlet pages should match that pattern and be added to both the cmdlets index (`cmdlets.md`) and the sidebar (auto-generated — verify after build). +PowerShell cmdlet pages under `admin/cmdlets/` follow a fixed naming pattern: `cmd.md` (e.g., `cmdgetppepolicies.md`, `cmdsetppeenabled.md`). New cmdlet pages should match that pattern and be added to both the cmdlets index (`cmdlets.md`) and the sidebar (auto-generated — verify after build). ## Rules Pages -Each password rule under `11.2/admin/manage-policies/rules/` is its own file (character, complexity, compromised, dictionary, history, length, min/max age, patterns, repetition, similarity, unique characters). When adding a new rule type, create a new file in this folder and link from `rules.md` — don't collapse into an existing file. +Each password rule under `admin/manage-policies/rules/` is its own file (character, complexity, compromised, dictionary, history, length, min/max age, patterns, repetition, similarity, unique characters). When adding a new rule type, create a new file in this folder and link from `rules.md` — don't collapse into an existing file. diff --git a/docs/passwordpolicyenforcer/11.0/admin/_category_.json b/docs/passwordpolicyenforcer/admin/_category_.json similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/_category_.json rename to docs/passwordpolicyenforcer/admin/_category_.json diff --git a/docs/passwordpolicyenforcer/11.2/admin/administration_overview.md b/docs/passwordpolicyenforcer/admin/administration_overview.md similarity index 68% rename from docs/passwordpolicyenforcer/11.2/admin/administration_overview.md rename to docs/passwordpolicyenforcer/admin/administration_overview.md index 703ee84375..f9adcf2600 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/administration_overview.md +++ b/docs/passwordpolicyenforcer/admin/administration_overview.md @@ -8,12 +8,12 @@ sidebar_position: 40 Netwrix Password Policy Enforcer helps secure your network by ensuring users set strong passwords. When a user enters a password that doesn't comply with the password policy, Password Policy Enforcer immediately rejects the password and explains why. -![introduction_2](/images/passwordpolicyenforcer/11.2/evaluation/introduction_3.webp) +![introduction_2](/images/passwordpolicyenforcer/evaluation/introduction_3.webp) Unlike password cracking products that check passwords after the operating system accepts them, Password Policy Enforcer checks new passwords immediately to ensure that weak passwords don't jeopardize network security. You can also use Password Policy Enforcer to ensure that passwords are compatible with other systems, and to synchronize passwords with other networks and applications. :::note -The [Evaluate Password Policy Enforcer](/docs/passwordpolicyenforcer/11.2/evaluation/evaluation_overview.md) contains step-by-step instructions to help you install, configure, and evaluate Password Policy Enforcer. Consider using the Evaluation Guide if you are using Password Policy Enforcer for the first time, before installing and deploying on your domains. +The [Evaluate Password Policy Enforcer](/docs/passwordpolicyenforcer/evaluation/evaluation_overview.md) contains step-by-step instructions to help you install, configure, and evaluate Password Policy Enforcer. Consider using the Evaluation Guide if you are using Password Policy Enforcer for the first time, before installing and deploying on your domains. ::: diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/_category_.json b/docs/passwordpolicyenforcer/admin/cmdlets/_category_.json similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/_category_.json rename to docs/passwordpolicyenforcer/admin/cmdlets/_category_.json diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdconnectppe.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdconnectppe.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdconnectppe.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdconnectppe.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdcopyppepolicy.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdcopyppepolicy.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdcopyppepolicy.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdcopyppepolicy.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdexportppeconfig.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdexportppeconfig.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdexportppeconfig.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdexportppeconfig.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdexportppepolicy.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdexportppepolicy.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdexportppepolicy.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdexportppepolicy.md diff --git a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppebulkpasswordtest.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppebulkpasswordtest.md similarity index 95% rename from docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppebulkpasswordtest.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppebulkpasswordtest.md index fa9914339e..74afe06d18 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/cmdlets/cmdgetppebulkpasswordtest.md +++ b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppebulkpasswordtest.md @@ -44,4 +44,4 @@ Bulk test is running... The report is created: "C:\PPE\password.txt_Result_2209222024122350.html". -![Results of the Get-PPEBulkPasswordTest cmdlet](/images/passwordpolicyenforcer/11.2/administration/cmdletgetppebulkpasswordtest.webp) +![Results of the Get-PPEBulkPasswordTest cmdlet](/images/passwordpolicyenforcer/administration/cmdletgetppebulkpasswordtest.webp) diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeconfigreport.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeconfigreport.md similarity index 94% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeconfigreport.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeconfigreport.md index 0f6f9314b1..ddd2e16ef2 100644 --- a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeconfigreport.md +++ b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeconfigreport.md @@ -36,4 +36,4 @@ PS C:\> Get-PPEConfigReport -Folder C:\PPE The report is created: "C:\PPE\report.html". -![Creates the PPE Configuration report](/images/passwordpolicyenforcer/11.0/administration/cmdletgetppeconfigreport.webp) +![Creates the PPE Configuration report](/images/passwordpolicyenforcer/administration/cmdletgetppeconfigreport.webp) diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppedefaultpolicy.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppedefaultpolicy.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppedefaultpolicy.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppedefaultpolicy.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeenabled.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeenabled.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppeenabled.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeenabled.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppehelp.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppehelp.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppehelp.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppehelp.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppelicenseinfo.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppelicenseinfo.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppelicenseinfo.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppelicenseinfo.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppepasswordtest.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppepasswordtest.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppepasswordtest.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppepasswordtest.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppepolicies.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppepolicies.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppepolicies.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppepolicies.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppepolicyenabled.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppepolicyenabled.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdgetppepolicyenabled.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppepolicyenabled.md diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeserverversion.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeserverversion.md similarity index 97% rename from docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeserverversion.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeserverversion.md index 07f54b1073..89034d0da6 100644 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeserverversion.md +++ b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeserverversion.md @@ -33,4 +33,4 @@ This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorActio PS C:\> Get-PPEServerVersion -DC NT-DC03.NWXTECH.COM -**Version: 11.1.0.74** +**Version: x.x.x.x** diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeversion.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeversion.md similarity index 96% rename from docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeversion.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeversion.md index c4ef9ff3e6..c71398dd15 100644 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdgetppeversion.md +++ b/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeversion.md @@ -24,4 +24,4 @@ This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorActio PS C:\> Get-PPEVersion -**Version: 11.1.0.74** +**Version: x.x.x.x** diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdimportppeconfig.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdimportppeconfig.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdimportppeconfig.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdimportppeconfig.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdimportppepolicy.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdimportppepolicy.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdimportppepolicy.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdimportppepolicy.md diff --git a/docs/passwordpolicyenforcer/admin/cmdlets/cmdlets.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdlets.md new file mode 100644 index 0000000000..0f95a95379 --- /dev/null +++ b/docs/passwordpolicyenforcer/admin/cmdlets/cmdlets.md @@ -0,0 +1,55 @@ +--- +title: "PPE cmdlets" +description: "PPE cmdlets" +sidebar_position: 60 +--- + +# PPE cmdlets + +Cmdlets are available to manage Password Policy Enforcer from a Windows PowerShell. The +cmdlets aren't case-sensitive. + +Install the [.NET Desktop Runtime 10.0 or later](https://aka.ms/dotnet/10.0/windowsdesktop-runtime-win-x64.exe) and [PowerShell 7.4 or later](https://github.com/powershell/powershell/releases) to use the PowerShell cmdlets. + +To establish the connection: + +**Step 1 –** Open a Windows PowerShell. Some cmdlets require administrative permissions. You can use +the **Run as Administrator** option. + +**Step 2 –** Import the PPE cmdlets module: +**Import-Module "$env:ProgramFiles\Netwrix\Password Policy Enforcer\PS\PPEConf.PowerShell.dll"** + +**Step 3 –** Connect to your domain: +**Connect-PPE -d "_domain_"** where _domain_ is the full name of your domain controller. +**NT-DC03.NWXTECH.COM** in this example. + +**Get-PPEHelp** with no parameters, displays a list of available cmdlets. Use the PowerShell +**get-help** _Cmdlet_ for information about the cmdlet. + +![PPE cmdlets Connect](/images/passwordpolicyenforcer/administration/cmdletconnect.webp) + +Click a PPE cmdlet name for details. + +- [Connect-PPE](/docs/passwordpolicyenforcer/admin/cmdlets/cmdconnectppe.md) +- [Copy-PPEPolicy](/docs/passwordpolicyenforcer/admin/cmdlets/cmdcopyppepolicy.md) +- [Export-PPEConfig](/docs/passwordpolicyenforcer/admin/cmdlets/cmdexportppeconfig.md) +- [Export-PPEPolicy](/docs/passwordpolicyenforcer/admin/cmdlets/cmdexportppepolicy.md) +- [Get-PPEBulkPasswordTest](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppebulkpasswordtest.md) +- [Get-PPEConfigReport](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeconfigreport.md) +- [Get-PPEDefaultPolicy](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppedefaultpolicy.md) +- [Get-PPEEnabled](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeenabled.md) +- [Get-PPEHelp](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppehelp.md) +- [Get-PPELicenseInfo](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppelicenseinfo.md) +- [Get-PPEPasswordTest](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppepasswordtest.md) +- [Get-PPEPolicies](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppepolicies.md) +- [Get-PPEPolicyEnabled](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppepolicyenabled.md) +- [Get-PPEServerVersion](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeserverversion.md) +- [Get-PPEVersion](/docs/passwordpolicyenforcer/admin/cmdlets/cmdgetppeversion.md) +- [Import-PPEConfig](/docs/passwordpolicyenforcer/admin/cmdlets/cmdimportppeconfig.md) +- [Import-PPEPolicy](/docs/passwordpolicyenforcer/admin/cmdlets/cmdimportppepolicy.md) +- [Remove-PPEPolicy](/docs/passwordpolicyenforcer/admin/cmdlets/cmdremoveppepolicy.md) +- [Set-PPEDefaultPolicy](/docs/passwordpolicyenforcer/admin/cmdlets/cmdsetppedefaultpolicy.md) +- [Set-PPEEnabled](/docs/passwordpolicyenforcer/admin/cmdlets/cmdsetppeenabled.md) +- [Set-PPEPolicyEnabled](/docs/passwordpolicyenforcer/admin/cmdlets/cmdsetppepolicyenabled.md) +- [Start-PPECompromisedPasswordChecker](/docs/passwordpolicyenforcer/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md) +- [Start-PPEHibpUpdater](/docs/passwordpolicyenforcer/admin/cmdlets/cmdstartppehibpupdater.md) diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdremoveppepolicy.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdremoveppepolicy.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdremoveppepolicy.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdremoveppepolicy.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdsetppedefaultpolicy.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdsetppedefaultpolicy.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdsetppedefaultpolicy.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdsetppedefaultpolicy.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdsetppeenabled.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdsetppeenabled.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdsetppeenabled.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdsetppeenabled.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdsetppepolicyenabled.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdsetppepolicyenabled.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdsetppepolicyenabled.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdsetppepolicyenabled.md diff --git a/docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdstartppecompromisedpasswordchecker.md diff --git a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdstartppehibpupdater.md b/docs/passwordpolicyenforcer/admin/cmdlets/cmdstartppehibpupdater.md similarity index 93% rename from docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdstartppehibpupdater.md rename to docs/passwordpolicyenforcer/admin/cmdlets/cmdstartppehibpupdater.md index 499878b779..6b6c6a44eb 100644 --- a/docs/passwordpolicyenforcer/11.1/admin/cmdlets/cmdstartppehibpupdater.md +++ b/docs/passwordpolicyenforcer/admin/cmdlets/cmdstartppehibpupdater.md @@ -45,4 +45,4 @@ This cmdlet supports the common parameters: **Verbose**, **Debug**, **ErrorActio PS C:\> Start-PPEHibpUpdater -Folder "C:\HIBP\DB" -File "C:\Users\Administrator\Desktop\db for HIBP Updater not real small\stealthintercept-hibp-database-1.0.0.zip -![HIBP Update](/images/passwordpolicyenforcer/11.1/administration/cmdletstartppehibpupdater.webp) +![HIBP Update](/images/passwordpolicyenforcer/administration/cmdletstartppehibpupdater.webp) diff --git a/docs/passwordpolicyenforcer/11.2/admin/compromisedpasswordcheck.md b/docs/passwordpolicyenforcer/admin/compromisedpasswordcheck.md similarity index 91% rename from docs/passwordpolicyenforcer/11.2/admin/compromisedpasswordcheck.md rename to docs/passwordpolicyenforcer/admin/compromisedpasswordcheck.md index c0e075af45..7e73fcfc63 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/compromisedpasswordcheck.md +++ b/docs/passwordpolicyenforcer/admin/compromisedpasswordcheck.md @@ -12,7 +12,7 @@ You can schedule the check to run at any time to verify existing passwords again :::note Create the **Compromised Passwords Base** file before enabling the Compromised Password -Check. See the [HIBP Updater](/docs/passwordpolicyenforcer/11.2/admin/hibpupdater.md) topic for instructions. +Check. See the [HIBP Updater](/docs/passwordpolicyenforcer/admin/hibpupdater.md) topic for instructions. ::: @@ -29,10 +29,10 @@ set to **None**. Click the **Compromised Password Check** toggle to enable/disable the feature. -![Compromised Password Check](/images/passwordpolicyenforcer/11.2/administration/compromisedpasswords.webp) +![Compromised Password Check](/images/passwordpolicyenforcer/administration/compromisedpasswords.webp) - **Compromised Passwords Base** specify the database to use when checking for compromised - passwords. Netwrix recommends using the [HIBP Updater](/docs/passwordpolicyenforcer/11.2/admin/hibpupdater.md) to create this database. + passwords. Netwrix recommends using the [HIBP Updater](/docs/passwordpolicyenforcer/admin/hibpupdater.md) to create this database. Click **Browse** to navigate to the folder. Default is **C:\HIBP\DB** - **Domain Controller (FQDN)** specify the fully qualified domain controller name where you want to run the password check. Click **Browse** and select from the list. @@ -50,7 +50,7 @@ Click the **Compromised Password Check** toggle to enable/disable the feature. - **Set up email** click to set up the email message for users. Enter the **From** address and edit the subject and body template as needed. Click **Apply** to save changes. - ![Email user notification of compromised password](/images/passwordpolicyenforcer/11.2/administration/emailusernotification.webp) + ![Email user notification of compromised password](/images/passwordpolicyenforcer/administration/emailusernotification.webp) Click **Save** to save your settings before running the check or setting up a schedule. @@ -82,7 +82,7 @@ Guest (S-1-5-21-1006207104-1546379664-2458629591-501) Click **Schedule** to set up a schedule to run the Compromised Password Check. -![Schedule the Compromised Password Policy Check](/images/passwordpolicyenforcer/11.2/administration/compromisedpasswordsschedule.webp) +![Schedule the Compromised Password Policy Check](/images/passwordpolicyenforcer/administration/compromisedpasswordsschedule.webp) Select the **Frequency**: diff --git a/docs/passwordpolicyenforcer/11.2/admin/configconsole.md b/docs/passwordpolicyenforcer/admin/configconsole.md similarity index 96% rename from docs/passwordpolicyenforcer/11.2/admin/configconsole.md rename to docs/passwordpolicyenforcer/admin/configconsole.md index 58957ce40d..13cc5c2dba 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/configconsole.md +++ b/docs/passwordpolicyenforcer/admin/configconsole.md @@ -10,7 +10,7 @@ The Password Policy Enforcer (PPE) Configuration Console is a graphical user int Use the **PPE Configuration** desktop shortcut or Start menu item to open the console. If these don't exist, then use the [server components installer](../installation/installationserver.md) to install the Configuration Console. -![Configuration Console Dashboard](/images/passwordpolicyenforcer/11.2/evaluation/ppedashboard.webp) +![Configuration Console Dashboard](/images/passwordpolicyenforcer/evaluation/ppedashboard.webp) When you connect the console to a [domain configuration](../installation/domain_and_local_policies.md), the configuration changes you make in the console replicate to all the domain controllers in the domain. Active Directory (AD) replication propagates the changes at normal replication intervals. The console applies configuration changes only to the local computer's registry when connected to a [local configuration](../installation/domain_and_local_policies.md). @@ -18,7 +18,7 @@ When you connect the console to a [domain configuration](../installation/domain_ Use the toggle switch in the upper-left corner of the home page to enable and disable Password Policy Enforcer. PPE is enabled by default, but it doesn't enforce any rules when first installed because you haven't defined any policies yet. -![Enable/Disable PPE](/images/passwordpolicyenforcer/11.2/administration/enabledisableppeconsole.webp) +![Enable/Disable PPE](/images/passwordpolicyenforcer/administration/enabledisableppeconsole.webp) ## Get help diff --git a/docs/passwordpolicyenforcer/11.2/admin/hibpupdater.md b/docs/passwordpolicyenforcer/admin/hibpupdater.md similarity index 93% rename from docs/passwordpolicyenforcer/11.2/admin/hibpupdater.md rename to docs/passwordpolicyenforcer/admin/hibpupdater.md index db986c9188..e6c28a48da 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/hibpupdater.md +++ b/docs/passwordpolicyenforcer/admin/hibpupdater.md @@ -10,7 +10,7 @@ You can configure Password Policy Enforcer to use the Have I Been Pwnd (HIBP) da a copy of this database on its website. The HIBP database contains a list of the hashes of known compromised passwords. During password change operations, you can configure the application to reject passwords with a hash that matches a hash in the HIBP database. See the Password Policy -Enforcer [Compromised Password Check](/docs/passwordpolicyenforcer/11.2/admin/compromisedpasswordcheck.md) topic for HIBP database +Enforcer [Compromised Password Check](/docs/passwordpolicyenforcer/admin/compromisedpasswordcheck.md) topic for HIBP database information and configuration options. You must initially deploy the HIBP database to a server or workstation with an internet connection @@ -52,7 +52,7 @@ Only run this from one server. **...\Program Files\Password Policy Enforcer\HIBP\** -![hibpfolder](/images/passwordpolicyenforcer/11.2/administration/hibpfolder.webp) +![hibpfolder](/images/passwordpolicyenforcer/administration/hibpfolder.webp) **Step 2 –** Click HIBPWINUpdater. @@ -68,7 +68,7 @@ Netwrix website. ::: -![HIBP Updater](/images/passwordpolicyenforcer/11.2/administration/hibpupdater.webp) +![HIBP Updater](/images/passwordpolicyenforcer/administration/hibpupdater.webp) :::warning Ensure the initial update of the database occurs during non-office hours. Due to the @@ -126,7 +126,7 @@ Compromised rule to read the files from: **\\127.0.0.1\sysvol\your.domain\filename.db** -See the [Compromised Rule](/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/compromised_rule.md) topic for additional information. +See the [Compromised Rule](/docs/passwordpolicyenforcer/admin/manage-policies/rules/compromised_rule.md) topic for additional information. The preceding path only works if the computer has a Sysvol share. This won't be the case if you are using a workstation for policy testing, or if you are using Password Policy Enforcer to enforce @@ -153,7 +153,7 @@ Scheduler technology to execute the process. **Step 2 –** Click **Add Schedule**. An Edit Schedule window appears that looks similar to the HIBP Updater window. -![editschedule](/images/passwordpolicyenforcer/11.2/administration/editschedule.webp) +![editschedule](/images/passwordpolicyenforcer/administration/editschedule.webp) **Step 3 –** Enter the Name and Description of the schedule. @@ -172,6 +172,6 @@ PPE updates the HIBP database according to the schedule. The Schedule List window shows the names, run times, next run times, and whether the schedule is enabled. -![schedulelist](/images/passwordpolicyenforcer/11.2/administration/schedulelist.webp) +![schedulelist](/images/passwordpolicyenforcer/administration/schedulelist.webp) Use this window to Add, Edit, or Delete schedules for the HIBP Updater. diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/_category_.json b/docs/passwordpolicyenforcer/admin/manage-policies/_category_.json similarity index 100% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/_category_.json rename to docs/passwordpolicyenforcer/admin/manage-policies/_category_.json diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/manage_policies.md b/docs/passwordpolicyenforcer/admin/manage-policies/manage_policies.md similarity index 94% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/manage_policies.md rename to docs/passwordpolicyenforcer/admin/manage-policies/manage_policies.md index cde1f80b19..1cf782d0af 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/manage_policies.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/manage_policies.md @@ -10,11 +10,11 @@ Password Policy Enforcer (PPE) can enforce up to 256 different password policies PPE doesn't enforce any policies when you first install it, so the policy list is empty when you open the [configuration console](../configconsole.md) for the first time. -![Configuration Console Dashboard](/images/passwordpolicyenforcer/11.2/evaluation/ppedashboard.webp) +![Configuration Console Dashboard](/images/passwordpolicyenforcer/evaluation/ppedashboard.webp) PPE adds the policies you create to the policy list. Use the buttons above the policy list to [test policies](testpolicy.md), set policy priorities, and export the configuration. Use the options menu (**⋮**) to the right of each policy to perform actions on that policy. -![Dashboard with Policies](/images/passwordpolicyenforcer/11.2/administration/ppedashboardpolicies.webp) +![Dashboard with Policies](/images/passwordpolicyenforcer/administration/ppedashboardpolicies.webp) ## Add a policy @@ -46,7 +46,7 @@ Policy priorities help Password Policy Enforcer resolve [policy assignment confl Click **Set priorities** to view or modify policy priorities. This button is only visible if you have more than one password policy. -![Set priorities](/images/passwordpolicyenforcer/11.2/administration/policypriority.webp) +![Set priorities](/images/passwordpolicyenforcer/administration/policypriority.webp) Select the policy you want to reprioritize, then click **Higher** or **Lower** to move the policy up or down. Click **Apply priorities** to accept the new priority order. @@ -60,7 +60,7 @@ Click **Export** to create an HTML configuration report in `%ProgramFiles%\Netwr Click the policy options menu to perform one of the following actions on the policy. The policy options menu appears as three vertical dots (**⋮**) to the right of each policy in the policy list. -![Policy Options Menu](/images/passwordpolicyenforcer/11.2/administration/policy_options_menu.webp) +![Policy Options Menu](/images/passwordpolicyenforcer/administration/policy_options_menu.webp) ### Copy a policy diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/messages.md b/docs/passwordpolicyenforcer/admin/manage-policies/messages.md similarity index 90% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/messages.md rename to docs/passwordpolicyenforcer/admin/manage-policies/messages.md index e321ffd2ea..67e4e595d3 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/messages.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/messages.md @@ -12,7 +12,7 @@ The [Password Policy Client](../password-policy-client/password_policy_client.md 2. Click the name of a policy in the policy list. 3. Select the **Messages** tab. -![Messages](/images/passwordpolicyenforcer/11.2/administration/messages.webp) +![Messages](/images/passwordpolicyenforcer/administration/messages.webp) Password Policy Enforcer (PPE) automatically generates messages in English from the policy settings, but you can define messages in other languages by selecting a different language from the language dropdown in the left pane. You can also override the generated English messages by selecting **English** in the language dropdown. @@ -34,11 +34,11 @@ The [Password Policy Client](../password-policy-client/password_policy_client.md When you select **Password policy** in the left pane, you see a multiline text box with the template in the right pane, a **Preview** below it, and a **Macro** dropdown on the right. -![Message template](/images/passwordpolicyenforcer/11.2/administration/message_template.webp) +![Message template](/images/passwordpolicyenforcer/administration/message_template.webp) The default password policy template includes several macros in square brackets. The most important is `[LIVE_POLICY]`. PPE populates this macro with a list of rules that the password must comply with. An icon beside each line indicates if the new password complies with the rule. The icons update automatically as the user types to give them constant feedback. If you prefer a static policy message without the icons, then change `[LIVE_POLICY]` to `[POLICY]`. You must use [Password Policy Client](../password-policy-client/password_policy_client.md) 10.2 or later for live policies. -![Live policy](/images/passwordpolicyenforcer/11.2/administration/mesages2.webp) +![Live policy](/images/passwordpolicyenforcer/administration/mesages2.webp) PPE shows the other macros in the default message only when the policy configuration requires them. Leave them for now and replace them with your own text later if necessary. @@ -50,7 +50,7 @@ You can insert macros into the policy message template by positioning the text c The **Rejection reason** template editor also has a multiline text box for the template, but no preview. The default message text includes only one macro, `[REASON]`. PPE populates this macro with the list of rules that the password doesn't comply with. PPE generates the reason text for each rule from the policy settings, but you can override the default rule insert text by entering your own text in the relevant text box below the template text box. See the tip in [Message macros](#message-macros) for how to format rule inserts. -![Rejection reason template](/images/passwordpolicyenforcer/11.2/administration/message_rejection_reason_template.webp) +![Rejection reason template](/images/passwordpolicyenforcer/administration/message_rejection_reason_template.webp) :::note The [Dictionary rule](rules/dictionary_rule.md) inserts only one line into the `[REASON]` macro by default, even if the password matches a word in both dictionary files. If you enter different text in the **Dictionary > Main** and **Secondary dictionary** text boxes, the rule inserts the text for whichever file contains the matching word. If the word appears in both files, the rule inserts both lines. @@ -60,13 +60,13 @@ The [Dictionary rule](rules/dictionary_rule.md) inserts only one line into the ` The **Generic rejection** template editor has only a multiline text box for the template. You can't include any macros in this template. -![Generic rejection template](/images/passwordpolicyenforcer/11.2/administration/message_generic_rejection_template.webp) +![Generic rejection template](/images/passwordpolicyenforcer/administration/message_generic_rejection_template.webp) ## Message macros Select **[POLICY]** or **[LIVE_POLICY]** in the left pane to edit the rule inserts for these macros. In the right pane, enter the text you want the respective rules to insert. The **[LIVE_POLICY]** editor has three additional text boxes below the rule inserts. Use these text boxes to define the legend text for the three icons in the live policy. -![Live policy macro](/images/passwordpolicyenforcer/11.2/administration/message_live_policy_macro.webp) +![Live policy macro](/images/passwordpolicyenforcer/administration/message_live_policy_macro.webp) :::tip Rule inserts should generally begin with two spaces, a hyphen, and a space. While not mandatory, PPE recognizes this sequence and displays it as either a bullet point or a compliance icon. If the insert doesn't begin with this character sequence, then PPE adds the text to the macro without any decoration. diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/passphrases.md b/docs/passwordpolicyenforcer/admin/manage-policies/passphrases.md similarity index 95% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/passphrases.md rename to docs/passwordpolicyenforcer/admin/manage-policies/passphrases.md index 2f4d189c52..359a1db41f 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/passphrases.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/passphrases.md @@ -15,7 +15,7 @@ Rules like [Complexity](rules/complexity_rule.md) and [Dictionary](rules/diction 3. Select the **Passphrase** tab. 4. Select the **Passphrase** checkbox to enable this feature. - ![Enable Passphrases](/images/passwordpolicyenforcer/11.2/administration/passphrase.webp) + ![Enable Passphrases](/images/passwordpolicyenforcer/administration/passphrase.webp) 5. Select the minimum number of characters from the **contains** dropdown. PPE disables the specified rules when a password contains at least this many characters. 6. Select the rules you want to disable for passphrases. diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/policy_properties.md b/docs/passwordpolicyenforcer/admin/manage-policies/policy_properties.md similarity index 98% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/policy_properties.md rename to docs/passwordpolicyenforcer/admin/manage-policies/policy_properties.md index f033bf9810..26480707e7 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/policy_properties.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/policy_properties.md @@ -12,7 +12,7 @@ The **Properties** tab contains general settings for the displayed policy. 2. Click the name of a policy in the policy list. 3. Select the **Properties** tab. -![Set the Policy Properties](/images/passwordpolicyenforcer/11.2/administration/properties.webp) +![Set the Policy Properties](/images/passwordpolicyenforcer/administration/properties.webp) **Name**. Every policy must have a unique name. You can change the name in this text box if you want to rename the policy. diff --git a/docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/_category_.json b/docs/passwordpolicyenforcer/admin/manage-policies/rules/_category_.json similarity index 100% rename from docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/_category_.json rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/_category_.json diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/character_rules.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/character_rules.md similarity index 92% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/character_rules.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/character_rules.md index 1fdeb912f2..a29d3b2e38 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/character_rules.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/character_rules.md @@ -8,7 +8,7 @@ sidebar_position: 40 Selecting the **Characters (Granular)** item in the rules pane displays the settings for nine related rules. Unlike the [Complexity rule](complexity_rule.md), these rules offer granular control over which characters to require or reject, and can even require certain character types at specific character positions. Use these rules to increase password strength or to ensure password compatibility with other systems. -![Character (Granular) Rule](/images/passwordpolicyenforcer/11.2/administration/chargranular.webp) +![Character (Granular) Rule](/images/passwordpolicyenforcer/administration/chargranular.webp) :::note You must select the **Characters (Granular)** checkbox at the top of the page before you can enable any of the other rules on the page. @@ -26,13 +26,13 @@ These rules require passwords to contain certain characters by default. The word When you select **Contain**, PPE defaults to requiring at least one character from this character set. If you want to require more than one character, select the required number from the dropdown beside **Contain**. For example, you might want to specify that passwords must contain at least two special characters. -![Passwords must contain at least two special characters](/images/passwordpolicyenforcer/11.2/administration/characters_granular_must_contain_two_special.webp) +![Passwords must contain at least two special characters](/images/passwordpolicyenforcer/administration/characters_granular_must_contain_two_special.webp) Click **+** to add more specific positional requirements for this rule. Two options appear: **In position** and **Embedded**. Select **In position** to specify the character positions where the characters must (or must not) appear in the password. For example, you might have a legacy system that requires a special character in the first three characters of a password. You can configure PPE to enforce this rule by selecting **In position**, then selecting **1** and **3** in the next two dropdowns. -![Restricting Characters](/images/passwordpolicyenforcer/11.2/administration/chargranularrestrict.webp) +![Restricting Characters](/images/passwordpolicyenforcer/administration/chargranularrestrict.webp) :::tip Select the same number for the start and end position if you want the rule to only check one character position. @@ -42,7 +42,7 @@ Select **Embedded** to specify that the characters must (or must not) be embedde Click **Characters** if you want to redefine the character set. -![Set up custom character set](/images/passwordpolicyenforcer/11.2/administration/chargranularvowel.webp) +![Set up custom character set](/images/passwordpolicyenforcer/administration/chargranularvowel.webp) Enter a **Name** for the character set, then enter the characters making up the set in the **Characters set** text box. Don't enter any delimiters, just the characters. For example, `AaEeIiOoUu` for vowels. Your custom character set name doesn't appear throughout the user interface — it only appears in the [Policy and Rejection messages](../messages.md). Clear one or both of these text boxes, then click **Apply** to revert them to their default values. @@ -68,6 +68,6 @@ These rules require passwords to begin or end with certain characters by default Select the character set names to enable them. A checkmark appears next to the selected character sets. For example, selecting **Not end** with **Numeric** and **Special** rejects passwords that end with a numeric or special character: -![Characters (Last) rule](/images/passwordpolicyenforcer/11.2/administration/last_character_rule.webp) +![Characters (Last) rule](/images/passwordpolicyenforcer/administration/last_character_rule.webp) The First and Last Character rules use custom character set definitions defined by the granular character rules. If you haven't defined custom character sets, these rules use the [default character sets](../policy_properties.md). diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/complexity_rule.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/complexity_rule.md similarity index 95% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/complexity_rule.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/complexity_rule.md index 4778228408..8189568635 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/complexity_rule.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/complexity_rule.md @@ -8,7 +8,7 @@ sidebar_position: 30 The Complexity rule rejects passwords that don't contain characters from a variety of character sets. A complex password takes longer to brute-force crack than a simple password of the same length. -![Character Complexity Rule](/images/passwordpolicyenforcer/11.2/administration/charcomplexity.webp) +![Character Complexity Rule](/images/passwordpolicyenforcer/administration/charcomplexity.webp) Select the **Characters (Complexity)** checkbox to enable the Complexity rule. diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/compromised_rule.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/compromised_rule.md similarity index 92% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/compromised_rule.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/compromised_rule.md index e13e25ef78..5ef177deb8 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/compromised_rule.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/compromised_rule.md @@ -8,7 +8,7 @@ sidebar_position: 50 The Compromised rule rejects passwords found in data breaches. Blocking these passwords reduces the risk of a successful credential stuffing attack. -![Compromised password rule](/images/passwordpolicyenforcer/11.2/administration/compromised.webp) +![Compromised password rule](/images/passwordpolicyenforcer/administration/compromised.webp) Select the **Compromised** checkbox to enable the Compromised rule. diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/dictionary_rule.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/dictionary_rule.md similarity index 99% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/dictionary_rule.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/dictionary_rule.md index 159a8d563b..4ed1f893a9 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/dictionary_rule.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/dictionary_rule.md @@ -8,7 +8,7 @@ sidebar_position: 60 The Dictionary rule rejects passwords that are vulnerable to guessing, hybrid, and precomputed attacks. These attacks can crack weak passwords in seconds, and they are very effective if users base their passwords on common words. -![Dictionary rule configuration options](/images/passwordpolicyenforcer/11.2/administration/dictionary.webp) +![Dictionary rule configuration options](/images/passwordpolicyenforcer/administration/dictionary.webp) Select the **Dictionary** checkbox to enable the Dictionary rule. diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/history_rule.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/history_rule.md similarity index 97% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/history_rule.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/history_rule.md index 37eb540ef1..76e96c1e30 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/history_rule.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/history_rule.md @@ -8,7 +8,7 @@ sidebar_position: 70 The History rule stops users from reusing passwords or cycling through a fixed set of passwords. Password reuse defeats the purpose of enforced password changes. Password Policy Enforcer (PPE) can stop users from reusing passwords for a number of password changes or a number of days. -![History rule](/images/passwordpolicyenforcer/11.2/administration/history.webp) +![History rule](/images/passwordpolicyenforcer/administration/history.webp) Select the **History** checkbox to enable the History rule. @@ -63,7 +63,7 @@ To create a new Active Directory attribute for the password history: ``` 4. Check the output. You should see the two success messages highlighted by the yellow box in the following screenshot. - ![ppe_rules_8](/images/passwordpolicyenforcer/11.2/administration/ppe_rules_8.webp) + ![ppe_rules_8](/images/passwordpolicyenforcer/administration/ppe_rules_8.webp) ### Use an existing attribute for the password history diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/length_rule.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/length_rule.md similarity index 92% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/length_rule.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/length_rule.md index 4d7a3f9d4e..f8eeba92e3 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/length_rule.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/length_rule.md @@ -8,7 +8,7 @@ sidebar_position: 80 The Length rule rejects passwords that contain too few or too many characters. Longer passwords are generally stronger, so only specify a maximum password length if you must maintain password compatibility with a system that can't accept long passwords. -![Length rule](/images/passwordpolicyenforcer/11.2/administration/length.webp) +![Length rule](/images/passwordpolicyenforcer/administration/length.webp) Select the **Length** checkbox to enable the Length rule. diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/maximum_age_rule.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/maximum_age_rule.md similarity index 97% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/maximum_age_rule.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/maximum_age_rule.md index 81159c3fe1..88cb9121da 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/maximum_age_rule.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/maximum_age_rule.md @@ -8,7 +8,7 @@ sidebar_position: 10 The Maximum Age rule forces users to change their passwords regularly. This decreases the likelihood of an attacker finding a password that is still in use. Only [domain policies](../../../installation/domain_and_local_policies.md) can enforce this rule. -![Maximum Age rule](/images/passwordpolicyenforcer/11.2/administration/agemax.webp) +![Maximum Age rule](/images/passwordpolicyenforcer/administration/agemax.webp) Select the **Age (Max)** checkbox to enable the Maximum Age rule. @@ -40,7 +40,7 @@ Select **Send email reminders at** if you want PPE to send email reminders to us Click **Set up email** to edit the email template for the email reminders. -![Email Template Editor](/images/passwordpolicyenforcer/11.2/administration/email_template_editor.webp) +![Email Template Editor](/images/passwordpolicyenforcer/administration/email_template_editor.webp) The correct format for the **From** text box is `"Display Name" `. You can edit the email body with a visual editor or raw HTML editor by clicking **Visual** or **HTML**. diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/minimum_age_rule.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/minimum_age_rule.md similarity index 94% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/minimum_age_rule.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/minimum_age_rule.md index 1ad3f25930..8947b79657 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/minimum_age_rule.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/minimum_age_rule.md @@ -8,7 +8,7 @@ sidebar_position: 20 The Minimum Age rule stops users from quickly cycling through a series of passwords to evade the [History rule](history_rule.md) and [Similarity rule](similarity_rule.md). Only [domain policies](../../../installation/domain_and_local_policies.md) can enforce this rule. -![Minimum age rule](/images/passwordpolicyenforcer/11.2/administration/agemin.webp) +![Minimum age rule](/images/passwordpolicyenforcer/administration/agemin.webp) Select the **Age (Min)** checkbox to enable the Minimum Age rule. diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/patterns.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/patterns.md similarity index 93% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/patterns.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/patterns.md index 9c3dda3121..fe67db10b2 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/patterns.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/patterns.md @@ -8,7 +8,7 @@ sidebar_position: 90 The Patterns rule rejects passwords that contain sequential character patterns like abcde and keyboard patterns like qwerty. Passwords with predictable character patterns are easier to guess and crack. -![Patterns rule](/images/passwordpolicyenforcer/11.2/administration/patterns.webp) +![Patterns rule](/images/passwordpolicyenforcer/administration/patterns.webp) ## Sequential character patterns @@ -26,7 +26,7 @@ Increase the tolerance if [testing](../testpolicy.md#by-user) shows that this ru Click **Character patterns** to select which sequential character patterns PPE detects. -![Character patterns](/images/passwordpolicyenforcer/11.2/administration/character_patterns.webp) +![Character patterns](/images/passwordpolicyenforcer/administration/character_patterns.webp) ## Keyboard patterns @@ -52,4 +52,4 @@ Increase the tolerance if [testing](../testpolicy.md#by-user) shows that this ru Click **Keyboard layouts** to select which international keyboard layouts PPE detects. -![Keyboard layouts](/images/passwordpolicyenforcer/11.2/administration/keyboard_layouts.webp) +![Keyboard layouts](/images/passwordpolicyenforcer/administration/keyboard_layouts.webp) diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/repetition.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/repetition.md similarity index 96% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/repetition.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/repetition.md index 6be82f4fb4..d540c35af6 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/repetition.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/repetition.md @@ -8,7 +8,7 @@ sidebar_position: 100 The Repetition rule rejects passwords that contain repeating patterns like abbbbc and pwdpwdpwd. Excessive repetition decreases password entropy, making passwords easier to guess or crack. -![Repetition Rule](/images/passwordpolicyenforcer/11.2/administration/repetition.webp) +![Repetition Rule](/images/passwordpolicyenforcer/administration/repetition.webp) ## Character repetition diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/rules.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/rules.md similarity index 98% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/rules.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/rules.md index 9aa8f7e9c7..a94275b1fb 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/rules.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/rules.md @@ -15,7 +15,7 @@ The left pane of the policy editor lists the available rules. A check mark appea Click **Save** in the upper-right corner of the policy editor to apply your changes. The toggle switch in the upper-left corner of the policy editor enables and disables the entire policy. -![Enabled rules are checked](/images/passwordpolicyenforcer/11.2/administration/enabledrules.webp) +![Enabled rules are checked](/images/passwordpolicyenforcer/administration/enabledrules.webp) Several PPE rules have **Detect character substitution** and **Tolerance** settings. Understanding how these settings work helps you fine-tune your policies. diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/similarity_rule.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/similarity_rule.md similarity index 97% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/similarity_rule.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/similarity_rule.md index ef78636efd..c85a920601 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/similarity_rule.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/similarity_rule.md @@ -8,7 +8,7 @@ sidebar_position: 110 The Similarity rule rejects passwords that are similar to a user's current password, display name, or logon name. These passwords are predictable and relatively easy to guess. -![Similarity rule](/images/passwordpolicyenforcer/11.2/administration/similarity.webp) +![Similarity rule](/images/passwordpolicyenforcer/administration/similarity.webp) Select the **Similarity** checkbox at the top of the page, then select the types of similarity that you want Password Policy Enforcer (PPE) to detect: diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/unique_characters.md b/docs/passwordpolicyenforcer/admin/manage-policies/rules/unique_characters.md similarity index 91% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/unique_characters.md rename to docs/passwordpolicyenforcer/admin/manage-policies/rules/unique_characters.md index 7f9945cdc8..c6ab0fd77f 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/rules/unique_characters.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/rules/unique_characters.md @@ -8,7 +8,7 @@ sidebar_position: 120 The Unique Characters rule rejects passwords that don't contain a minimum number of unique characters. For example, the password aaaaaaaa only contains one unique character (a), whereas mypassword contains nine unique characters (mypasword). Increasing the number of unique characters in a password reduces repetition. This increases password entropy and makes the password harder to guess or crack. -![Unique characters rule](/images/passwordpolicyenforcer/11.2/administration/unique.webp) +![Unique characters rule](/images/passwordpolicyenforcer/administration/unique.webp) Select the **Unique characters** checkbox to enable the Unique Characters rule. diff --git a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/testpolicy.md b/docs/passwordpolicyenforcer/admin/manage-policies/testpolicy.md similarity index 88% rename from docs/passwordpolicyenforcer/11.1/admin/manage-policies/testpolicy.md rename to docs/passwordpolicyenforcer/admin/manage-policies/testpolicy.md index 25b5c2a93d..1d56c906c4 100644 --- a/docs/passwordpolicyenforcer/11.1/admin/manage-policies/testpolicy.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/testpolicy.md @@ -13,7 +13,7 @@ testing. Test policy opens on the **By user** tab. -![Test by User](/images/passwordpolicyenforcer/11.1/administration/testuser.webp) +![Test by User](/images/passwordpolicyenforcer/administration/testuser.webp) ## By User @@ -26,14 +26,14 @@ up a policy. **Step 3 –** **Type in a password to simulate its change**. As you type, Password Policy Enforcer evaluates the new password and displays the results. -![Failing Password](/images/passwordpolicyenforcer/11.1/administration/testuserfail.webp) +![Failing Password](/images/passwordpolicyenforcer/administration/testuserfail.webp) The entered password is failing in this example, due to not meeting the length requirement. There is a red x indicating the failure. You can hover over the requirements to see the rule name. In this example, the password passes. Notice the green check beside the entered password. -![Passing password](/images/passwordpolicyenforcer/11.1/administration/testuserpass.webp) +![Passing password](/images/passwordpolicyenforcer/administration/testuserpass.webp) Expand the **View log** for details: @@ -44,7 +44,7 @@ Expand the **View log** for details: Turn on **Verbose Logging** to view the performed tests and results. -![Verbose logging](/images/passwordpolicyenforcer/11.1/administration/testuserverbose.webp) +![Verbose logging](/images/passwordpolicyenforcer/administration/testuserverbose.webp) ## Bulk Password Test @@ -55,7 +55,7 @@ up a policy. **Step 2 –** Open the **Password bulk test** tab. -![Password bulk test](/images/passwordpolicyenforcer/11.1/administration/testbulk.webp) +![Password bulk test](/images/passwordpolicyenforcer/administration/testbulk.webp) **Step 3 –** Select a policy for the test. @@ -64,7 +64,7 @@ the file isn't on a shared drive. **Step 5 –** Click **Test passwords**. The **Statistics** are displayed. -![Test results](/images/passwordpolicyenforcer/11.1/administration/testbulkresult.webp) +![Test results](/images/passwordpolicyenforcer/administration/testbulkresult.webp) | Statistics of the Bulk Password Testing | | | --------------------------------------- | --------------------------------------------------------------------------------------- | @@ -77,7 +77,7 @@ the file isn't on a shared drive. Click **Show full report** to view the test details. -![Test Bulk Report](/images/passwordpolicyenforcer/11.1/administration/testbulkreport.webp) +![Test Bulk Report](/images/passwordpolicyenforcer/administration/testbulkreport.webp) You can use the **Report settings** to customize the report: diff --git a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/usersgroups.md b/docs/passwordpolicyenforcer/admin/manage-policies/usersgroups.md similarity index 91% rename from docs/passwordpolicyenforcer/11.2/admin/manage-policies/usersgroups.md rename to docs/passwordpolicyenforcer/admin/manage-policies/usersgroups.md index 9ec3de5ec5..251507ef7f 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/manage-policies/usersgroups.md +++ b/docs/passwordpolicyenforcer/admin/manage-policies/usersgroups.md @@ -18,12 +18,12 @@ Domain policy assignments for users and groups reference the object's Security I 2. Click the name of a policy in the policy list. 3. Select the **Users & Groups** tab. - ![Assign policies to Users and Groups](/images/passwordpolicyenforcer/11.2/administration/usersandgroups.webp) + ![Assign policies to Users and Groups](/images/passwordpolicyenforcer/administration/usersandgroups.webp) 4. Click the **+** beside **Users**, **Groups**, or **Containers/OUs** to add an assignment of that type. The Configuration Console displays a selection dialog box to help you select the users, groups, or OUs you want. 5. Click **OK** to add the assignment. The entry appears under the corresponding list. - ![Policy assignments](/images/passwordpolicyenforcer/11.2/administration/usersandgroups2.webp) + ![Policy assignments](/images/passwordpolicyenforcer/administration/usersandgroups2.webp) :::tip You can have different assignment types for a policy. For example, you may assign users to a policy by both OU and group at the same time. @@ -40,7 +40,7 @@ When you assign a policy to a group, PPE enforces the policy for all members of When you assign a policy to an OU, PPE enforces the policy for all users in the OU as well as any child OUs. For example, if the Helpdesk and Managers OUs are children of the Info Tech OU, then any policy assigned to the Info Tech OU also applies to the two child OUs. If you want to override the inherited policy, then assign a different policy to a child OU directly. -![managing_policies_3](/images/passwordpolicyenforcer/11.2/administration/managing_policies_3.webp) +![managing_policies_3](/images/passwordpolicyenforcer/administration/managing_policies_3.webp) ## Policy assignment conflicts @@ -64,10 +64,10 @@ If Password Policy Enforcer has only one policy, and that policy is also the def Use the [**Test Policy by User** feature](testpolicy.md#by-user) to check which policy PPE enforces for a user. Enter a username on the left, and the right pane shows the enforced policy. -![testviewlog](/images/passwordpolicyenforcer/11.2/administration/testviewlog.webp) +![testviewlog](/images/passwordpolicyenforcer/administration/testviewlog.webp) ## Policy selection flowchart This flowchart shows how Password Policy Enforcer determines which policy to enforce for a user. -![managing_policies](/images/passwordpolicyenforcer/11.2/administration/managing_policies.webp) +![managing_policies](/images/passwordpolicyenforcer/administration/managing_policies.webp) diff --git a/docs/passwordpolicyenforcer/11.2/admin/password-policy-client/_category_.json b/docs/passwordpolicyenforcer/admin/password-policy-client/_category_.json similarity index 100% rename from docs/passwordpolicyenforcer/11.2/admin/password-policy-client/_category_.json rename to docs/passwordpolicyenforcer/admin/password-policy-client/_category_.json diff --git a/docs/passwordpolicyenforcer/11.2/admin/password-policy-client/configuring_the_password_policy_client.md b/docs/passwordpolicyenforcer/admin/password-policy-client/configuring_the_password_policy_client.md similarity index 84% rename from docs/passwordpolicyenforcer/11.2/admin/password-policy-client/configuring_the_password_policy_client.md rename to docs/passwordpolicyenforcer/admin/password-policy-client/configuring_the_password_policy_client.md index 3f13758096..f1f5730989 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/password-policy-client/configuring_the_password_policy_client.md +++ b/docs/passwordpolicyenforcer/admin/password-policy-client/configuring_the_password_policy_client.md @@ -7,7 +7,7 @@ sidebar_position: 10 # Configuring the Password Policy Client The Password Policy Client is self-configuring and doesn't require manual configuration in most -cases. See the [Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.2/installation/installationclient.md) topic for +cases. See the [Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/installation/installationclient.md) topic for additional details. You may need to manually configure the Password Policy Client if: - You want to install it in a disabled state to be enabled later. @@ -29,17 +29,17 @@ have the group policy management console available. **Step 2 –** Go to Password Policy Enforcer install directory (C:\Program Files\Netwrix\Password Policy Enforcer) and copy the **PPEClt.adml** and **PPEClt.admx** files (highlighted in yellow): -![ppc_configuration](/images/passwordpolicyenforcer/11.2/administration/ppc_configuration.webp) +![ppc_configuration](/images/passwordpolicyenforcer/administration/ppc_configuration.webp) **Step 3 –** Go to C:\Windows\Policy Definitions and paste the .admx file in the root of this folder. -![ppc_configuration2](/images/passwordpolicyenforcer/11.2/administration/ppc_configuration2.webp) +![ppc_configuration2](/images/passwordpolicyenforcer/administration/ppc_configuration2.webp) **Step 4 –** Go to C:\Windows\Policy Definitions\en-US and paste the .adml file in the root of this folder. -![ppc_configuration1](/images/passwordpolicyenforcer/11.2/administration/ppc_configuration1.webp) +![ppc_configuration1](/images/passwordpolicyenforcer/administration/ppc_configuration1.webp) **Step 5 –** Open **Group Policy Management** console and check if you have a GPO created for Client. If not, see the topic's section for additional information. @@ -50,18 +50,18 @@ it here. After the GPO is configured, this view is available: -![ppc_configuration3](/images/passwordpolicyenforcer/11.2/administration/ppc_configuration3.webp) +![ppc_configuration3](/images/passwordpolicyenforcer/administration/ppc_configuration3.webp) **Step 7 –** Right-click the newly created GPO and select **Edit** from the pop-up menu. **Step 8 –** Expand **Computer Configuration** > **Policies** > **Administrative Templates** > **Netwrix Password Policy Enforcer** -![ppc_configuration4](/images/passwordpolicyenforcer/11.2/administration/ppc_configuration4.webp) +![ppc_configuration4](/images/passwordpolicyenforcer/administration/ppc_configuration4.webp) **Step 9 –** Click **Netwrix Password Policy Client** to open a list of modification settings. -![ppc_configuration5](/images/passwordpolicyenforcer/11.2/administration/ppc_configuration5.webp) +![ppc_configuration5](/images/passwordpolicyenforcer/administration/ppc_configuration5.webp) **Step 10 –** Select the one you need, then modify and save it. @@ -75,7 +75,7 @@ The Password Policy Client for Windows 10 and 11 maximizes the available screen non-essential user interface elements on small screens. It can also display the Password Policy message in a message box to draw attention to the password policy. -![the_password_policy_client_3](/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client_3.webp) +![the_password_policy_client_3](/images/passwordpolicyenforcer/administration/the_password_policy_client_3.webp) You can change the default display settings to control which user interface elements are hidden, and the point at which they are hidden. The display of the Password Policy message box is also diff --git a/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/password_policy_client.md b/docs/passwordpolicyenforcer/admin/password-policy-client/password_policy_client.md similarity index 69% rename from docs/passwordpolicyenforcer/11.1/admin/password-policy-client/password_policy_client.md rename to docs/passwordpolicyenforcer/admin/password-policy-client/password_policy_client.md index 226b272ca9..7dc1a9c41b 100644 --- a/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/password_policy_client.md +++ b/docs/passwordpolicyenforcer/admin/password-policy-client/password_policy_client.md @@ -10,13 +10,13 @@ The Password Policy Client helps users to choose a compliant password. Detailed provided if their new password is rejected. The Password Policy Client is optional. If it isn't installed, the -[Similarity Rule](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/similarity_rule.md) can't be enforced. Users only see the default Windows error +[Similarity Rule](/docs/passwordpolicyenforcer/admin/manage-policies/rules/similarity_rule.md) can't be enforced. Users only see the default Windows error message if their password is rejected, not the detailed help they receive from the Password Policy Client. -![the_password_policy_client](/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client.webp) +![the_password_policy_client](/images/passwordpolicyenforcer/administration/the_password_policy_client.webp) -![the_password_policy_client_1](/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client_1.webp) +![the_password_policy_client_1](/images/passwordpolicyenforcer/administration/the_password_policy_client_1.webp) The Password Policy Client displays the password policy during a password change so that users can see the policy while they choose their password. The Password Policy Client also displays a detailed diff --git a/docs/passwordpolicyenforcer/11.1/admin/ppe_tool.md b/docs/passwordpolicyenforcer/admin/ppe_tool.md similarity index 100% rename from docs/passwordpolicyenforcer/11.1/admin/ppe_tool.md rename to docs/passwordpolicyenforcer/admin/ppe_tool.md diff --git a/docs/passwordpolicyenforcer/11.2/admin/settings.md b/docs/passwordpolicyenforcer/admin/settings.md similarity index 95% rename from docs/passwordpolicyenforcer/11.2/admin/settings.md rename to docs/passwordpolicyenforcer/admin/settings.md index 070177d4a7..c23cd970e5 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/settings.md +++ b/docs/passwordpolicyenforcer/admin/settings.md @@ -10,7 +10,7 @@ Most Password Policy Enforcer (PPE) settings are policy-specific, but there are ## General -![General Settings PPE](/images/passwordpolicyenforcer/11.2/administration/settingsgeneral.webp) +![General Settings PPE](/images/passwordpolicyenforcer/administration/settingsgeneral.webp) **Default policy**. Select the policy to use as the default from the dropdown. Users must comply with the default password policy if you haven't assigned another policy to them. See [Set the default policy](manage-policies/manage_policies.md#set-the-default-policy) to learn how PPE uses the default policy and how to exempt specific users from it. @@ -49,7 +49,7 @@ The Password Policy Client and the Password Policy Server each enforce most PPE Password Policy Enforcer sends notification emails to users and administrators. Use the settings in the **Notifications** tab to configure your mail delivery settings. PPE can send email directly to a mail server or a pickup folder. -![Notifications Settings](/images/passwordpolicyenforcer/11.2/administration/settingsnotifications.webp) +![Notifications Settings](/images/passwordpolicyenforcer/administration/settingsnotifications.webp) **Send email reminders**. Select this option if you want PPE to send email notifications directly to a mail server. Select your mail server type, **SMTP Server**, **Google OAuth2**, or **O365 OAuth2**, then enter the requested information for the mail server. If you select **Google OAuth2**, click **Update credentials** to complete authorization in a web browser. Finally, click **Send test email** to ensure that the PPE Mailer can deliver email to your mail server. @@ -69,7 +69,7 @@ The default Google OAuth2 timeout is 60 seconds. You can change this by setting Install the Password Policy Enforcer Mailer Service on one server in the domain. Use the settings in the **Mail Service** tab to allow PPE to locate the mailer service. -![Mail Server Tab](/images/passwordpolicyenforcer/11.2/administration/settingsmailserver.webp) +![Mail Server Tab](/images/passwordpolicyenforcer/administration/settingsmailserver.webp) **Service**. Enter the hostname or IP address of the server that hosts the mailer service. @@ -80,7 +80,7 @@ Install the Password Policy Enforcer Mailer Service on one server in the domain. Use the **License** tab to view and update your license key. -![License Settings Tab](/images/passwordpolicyenforcer/11.2/administration/settingslicense.webp) +![License Settings Tab](/images/passwordpolicyenforcer/administration/settingslicense.webp) **Paste license from clipboard**. Copy your new license key to the clipboard, then click **Paste license from clipboard** to update the license key. diff --git a/docs/passwordpolicyenforcer/11.2/admin/systemaudit.md b/docs/passwordpolicyenforcer/admin/systemaudit.md similarity index 91% rename from docs/passwordpolicyenforcer/11.2/admin/systemaudit.md rename to docs/passwordpolicyenforcer/admin/systemaudit.md index 2441cae701..d9f8cf99f3 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/systemaudit.md +++ b/docs/passwordpolicyenforcer/admin/systemaudit.md @@ -21,7 +21,7 @@ configuration setting. System Audit and Support opens on the **Version Tracker** ## Version Tracker -![System Audit and Support Version Tracker tab](/images/passwordpolicyenforcer/11.2/administration/systemaudit.webp) +![System Audit and Support Version Tracker tab](/images/passwordpolicyenforcer/administration/systemaudit.webp) Click **Run test**. The audit reports the discovered domain controllers and versions. @@ -31,7 +31,7 @@ set up the firewall to allow Password Policy Enforcer to communicate. ::: -![System Audit results](/images/passwordpolicyenforcer/11.2/administration/systemauditversion.webp) +![System Audit results](/images/passwordpolicyenforcer/administration/systemauditversion.webp) You can click the export icon to download your results. The file name is **Audit\_\_**timestamp**\_.xlxs**, and it downloads to the default **Downloads** folder. For large @@ -49,7 +49,7 @@ the logs. Use the **Support Tools** tab to save a configuration report, export/import PPE settings, and open the property editor. -![System Audit Support Tools tab](/images/passwordpolicyenforcer/11.2/administration/systemaudittools.webp) +![System Audit Support Tools tab](/images/passwordpolicyenforcer/administration/systemaudittools.webp) - **Policies Configuration Report** saves the configuration as a text file. Browse to the folder where you want the report. The default filename is **PPEConfig.txt**. @@ -77,7 +77,7 @@ when Netwrix Support instructs you to. Access it from the Configuration Console: **System Audit and Support** > **Support Tools** > **Open editor** -![Property Editor](/images/passwordpolicyenforcer/11.2/administration/propertyeditor.webp) +![Property Editor](/images/passwordpolicyenforcer/administration/propertyeditor.webp) - **Policy**: select the policy to edit. - **Property**: select the property to change. diff --git a/docs/passwordpolicyenforcer/11.2/admin/troubleshooting.md b/docs/passwordpolicyenforcer/admin/troubleshooting.md similarity index 89% rename from docs/passwordpolicyenforcer/11.2/admin/troubleshooting.md rename to docs/passwordpolicyenforcer/admin/troubleshooting.md index 0d51e3e4ac..1af20d0ced 100644 --- a/docs/passwordpolicyenforcer/11.2/admin/troubleshooting.md +++ b/docs/passwordpolicyenforcer/admin/troubleshooting.md @@ -17,7 +17,7 @@ them. Select the first (blank) item in the dropdown list if you don't want a def Open the Programs and Features list in Control Panel on the computer you are changing the password from, and check if the Password Policy Client is in the list of installed programs. If it isn't, -then install the Password Policy Client. See the [Password Policy Client](/docs/passwordpolicyenforcer/11.2/admin/password-policy-client/password_policy_client.md) +then install the Password Policy Client. See the [Password Policy Client](/docs/passwordpolicyenforcer/admin/password-policy-client/password_policy_client.md) topic for additional information. If Password Policy Enforcer is enforcing a domain policy, then search the Windows Application Event @@ -38,7 +38,7 @@ password policy is assigned to the user. Ensure that the Password Policy Server is enabled. Ensure that the Password Policy Client is enabled. See -[Password Policy Client](/docs/passwordpolicyenforcer/11.2/admin/password-policy-client/password_policy_client.md) topic for additional information. +[Password Policy Client](/docs/passwordpolicyenforcer/admin/password-policy-client/password_policy_client.md) topic for additional information. #### Accepting passwords that don't comply with the policy @@ -52,7 +52,7 @@ local policies, search the Application Event Log on the local computer. Use the Test Policies page to test a password that Password Policy Enforcer is accepting. Examine the test results and event log to determine why Password Policy Enforcer accepted the password. If the Test Policies page rejects the password, you must configure the policy. See the -[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.2/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) topic for +[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) topic for additional information. If the **Enforce policy when password is reset** checkbox isn't selected in the PPS Properties @@ -66,7 +66,7 @@ Password screen. Use the Test Policies page to test a password that Password Policy Enforcer is rejecting. Examine the test results and event log to determine why Password Policy Enforcer rejected the password. If the Test Policies page rejects the password, you must configure the policy. See the -[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.2/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) topic for +[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) topic for additional information. Set **User must change password at next logon** for the user and repeat the password change test. If @@ -77,5 +77,5 @@ at next logon before every password change test to bypass the rule. #### Passwords that are accepted in the Test Policies page are rejected during a password change -See the [Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.2/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) +See the [Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) topic for additional information. diff --git a/docs/passwordpolicyenforcer/11.2/admin/writeback.md b/docs/passwordpolicyenforcer/admin/writeback.md similarity index 100% rename from docs/passwordpolicyenforcer/11.2/admin/writeback.md rename to docs/passwordpolicyenforcer/admin/writeback.md diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/_category_.json b/docs/passwordpolicyenforcer/evaluation/_category_.json similarity index 100% rename from docs/passwordpolicyenforcer/11.0/evaluation/_category_.json rename to docs/passwordpolicyenforcer/evaluation/_category_.json diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/conclusion.md b/docs/passwordpolicyenforcer/evaluation/conclusion.md similarity index 68% rename from docs/passwordpolicyenforcer/11.1/evaluation/conclusion.md rename to docs/passwordpolicyenforcer/evaluation/conclusion.md index b66b2c76a8..4a0f07b72e 100644 --- a/docs/passwordpolicyenforcer/11.1/evaluation/conclusion.md +++ b/docs/passwordpolicyenforcer/evaluation/conclusion.md @@ -10,8 +10,8 @@ You have successfully installed, configured, and tested Netwrix Password Policy Enforcer. This guide is an introduction to Password Policy Enforcer's capabilities. You can enforce almost any password policy imaginable with Password Policy Enforcer, customize the Password Policy Client messages, and even synchronize passwords with other networks and applications. The -[Administration](/docs/passwordpolicyenforcer/11.1/admin/administration_overview.md) topic contains more information to +[Administration](/docs/passwordpolicyenforcer/admin/administration_overview.md) topic contains more information to help you get the most out of Password Policy Enforcer. -The [Password Policy Enforcer Web](/docs/passwordpolicyenforcer/11.1/web-overview/web_overview.md) application lets users securely manage their passwords from a web browser, ensuring passwords comply with the password policy, and +The [Password Policy Enforcer Web](/docs/passwordpolicyenforcer/web-overview/web_overview.md) application lets users securely manage their passwords from a web browser, ensuring passwords comply with the password policy, and helping users choose compliant passwords. diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/configuring_policy_rules.md b/docs/passwordpolicyenforcer/evaluation/configuring_policy_rules.md similarity index 84% rename from docs/passwordpolicyenforcer/11.1/evaluation/configuring_policy_rules.md rename to docs/passwordpolicyenforcer/evaluation/configuring_policy_rules.md index 07e67428db..c85e1bc2d5 100644 --- a/docs/passwordpolicyenforcer/11.1/evaluation/configuring_policy_rules.md +++ b/docs/passwordpolicyenforcer/evaluation/configuring_policy_rules.md @@ -18,7 +18,7 @@ the policy to enforce these rules: When you create a policy, the policy settings are opened. You can open the settings for a policy at any time by clicking the policy name on the Configuration Console dashboard. -![New policy open for settings](/images/passwordpolicyenforcer/11.1/evaluation/newpolicysettings.webp) +![New policy open for settings](/images/passwordpolicyenforcer/evaluation/newpolicysettings.webp) Requirement: Password must contain at least seven characters. @@ -31,7 +31,7 @@ This condition is set with the **Length** rule. **Step 3 –** Select **7** for the **At least...** value. Depending on the template, this might be the default. -![Set the Length](/images/passwordpolicyenforcer/11.1/evaluation/evallength.webp) +![Set the Length](/images/passwordpolicyenforcer/evaluation/evallength.webp) Requirement: Password must contain at least one lowercase alpha character. @@ -47,7 +47,7 @@ This condition is set with the **Characters (Complexity)** rule. **Step 5 –** Select **Upper Alpha (A-Z)** for the next requirement while you are here. -![Set upper and lower case requirements](/images/passwordpolicyenforcer/11.1/evaluation/evalchars.webp) +![Set upper and lower case requirements](/images/passwordpolicyenforcer/evaluation/evalchars.webp) Password must contain at least one uppercase character. @@ -63,7 +63,7 @@ This condition is set with the **Characters (Granular)** rule. **Step 5 –** Select **Lower Alpha (a-z)** **Contain** **1** or more characters. -![set character granularity](/images/passwordpolicyenforcer/11.1/evaluation/evalcharsgran.webp) +![set character granularity](/images/passwordpolicyenforcer/evaluation/evalcharsgran.webp) Requirement: Password must not be similar to the user's logon name. @@ -75,7 +75,7 @@ This condition is set with the **Similarity** rule. **Step 3 –** Select **User logon name**. -![Set Similarity rule](/images/passwordpolicyenforcer/11.1/evaluation/evalsimilarity.webp) +![Set Similarity rule](/images/passwordpolicyenforcer/evaluation/evalsimilarity.webp) Requirement: Password must not exist in a dictionary of common passwords. @@ -89,6 +89,6 @@ This condition is set with the **Dictionary** rule. **Step 4 –** Navigate to **\Program Files\Password Policy Enforcer** folder and select**Dict.txt**. -![Enable the sample dictionary](/images/passwordpolicyenforcer/11.1/evaluation/evaldict.webp) +![Enable the sample dictionary](/images/passwordpolicyenforcer/evaluation/evaldict.webp) When you have added all the rules, click **Save** to save your new policy. diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/creating-a-password-policy/_category_.json b/docs/passwordpolicyenforcer/evaluation/creating-a-password-policy/_category_.json similarity index 100% rename from docs/passwordpolicyenforcer/11.0/evaluation/creating-a-password-policy/_category_.json rename to docs/passwordpolicyenforcer/evaluation/creating-a-password-policy/_category_.json diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/creating-a-password-policy/creating_a_password_policy.md b/docs/passwordpolicyenforcer/evaluation/creating-a-password-policy/creating_a_password_policy.md similarity index 78% rename from docs/passwordpolicyenforcer/11.2/evaluation/creating-a-password-policy/creating_a_password_policy.md rename to docs/passwordpolicyenforcer/evaluation/creating-a-password-policy/creating_a_password_policy.md index 337ced5786..89781e3091 100644 --- a/docs/passwordpolicyenforcer/11.2/evaluation/creating-a-password-policy/creating_a_password_policy.md +++ b/docs/passwordpolicyenforcer/evaluation/creating-a-password-policy/creating_a_password_policy.md @@ -17,7 +17,7 @@ Click **Start** > **Netwrix Password Policy Enforcer** > **PPE Configuration** or Double click the **PPE Configuration** desktop shortcut. -![Configuration Console Dashboard](/images/passwordpolicyenforcer/11.2/evaluation/ppedashboard.webp) +![Configuration Console Dashboard](/images/passwordpolicyenforcer/evaluation/ppedashboard.webp) The Configuration Console dashboard shows **No password policies have been set up** when you are getting started with Password Policy Enforcer. @@ -28,14 +28,14 @@ getting started with Password Policy Enforcer. example. **Step 4 –** Select a Policy template or **None** if you are creating your own. For a list of -policies see [Policy Templates ](/docs/passwordpolicyenforcer/11.2/evaluation/creating-a-password-policy/policy_templates.md). +policies see [Policy Templates ](/docs/passwordpolicyenforcer/evaluation/creating-a-password-policy/policy_templates.md). **Step 5 –** Click **Create policy**. Password Policy Enforcer creates the policy and opens the policy settings, showing the first item on the **Rules** tab. -![New policy open for settings](/images/passwordpolicyenforcer/11.2/evaluation/newpolicysettings.webp) +![New policy open for settings](/images/passwordpolicyenforcer/evaluation/newpolicysettings.webp) **Step 6 –** Click the context menu (beside the policy name and select **Make default**. -![Make the policy the default](/images/passwordpolicyenforcer/11.2/evaluation/evaldefault.webp) +![Make the policy the default](/images/passwordpolicyenforcer/evaluation/evaldefault.webp) diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/creating-a-password-policy/policy_templates.md b/docs/passwordpolicyenforcer/evaluation/creating-a-password-policy/policy_templates.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/evaluation/creating-a-password-policy/policy_templates.md rename to docs/passwordpolicyenforcer/evaluation/creating-a-password-policy/policy_templates.md diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/enforcing_multiple_policies.md b/docs/passwordpolicyenforcer/evaluation/enforcing_multiple_policies.md similarity index 80% rename from docs/passwordpolicyenforcer/11.2/evaluation/enforcing_multiple_policies.md rename to docs/passwordpolicyenforcer/evaluation/enforcing_multiple_policies.md index 6e4c43d1f7..c63f2d3370 100644 --- a/docs/passwordpolicyenforcer/11.2/evaluation/enforcing_multiple_policies.md +++ b/docs/passwordpolicyenforcer/evaluation/enforcing_multiple_policies.md @@ -15,7 +15,7 @@ containers (Organizational Units). If you are in the settings for your first policy, click the left arrow beside the policy name to return to the Configuration Console dashboard. -![Return to the dashboard](/images/passwordpolicyenforcer/11.2/evaluation/evaldashboard.webp) +![Return to the dashboard](/images/passwordpolicyenforcer/evaluation/evaldashboard.webp) Create an additional password policy. @@ -23,20 +23,20 @@ Create an additional password policy. **Step 2 –** Enter **Admins Policy** for the Policy duplication. -![Enter Admins Policy](/images/passwordpolicyenforcer/11.2/evaluation/evalcopypolicy2.webp) +![Enter Admins Policy](/images/passwordpolicyenforcer/evaluation/evalcopypolicy2.webp) **Step 3 –** Click **Make copy**. **Step 4 –** Open the **Users & Groups** tab. -![Open the Users & Groups tab](/images/passwordpolicyenforcer/11.2/evaluation/evalusergroups.webp) +![Open the Users & Groups tab](/images/passwordpolicyenforcer/evaluation/evalusergroups.webp) **Step 5 –** Click the **+** in the **Groups** list and enter **Domain Admins**. Specify a Domain or local **Location** depending on your evaluation set up. **Step 6 –** Click **OK**. Domain Admins appear in the **Groups** list. -![Domain Admins added](/images/passwordpolicyenforcer/11.2/evaluation/evaldomainadmins.webp) +![Domain Admins added](/images/passwordpolicyenforcer/evaluation/evaldomainadmins.webp) - Members of the Domain Admins group (or the PPETestAdmin user, if not using a domain controller) must now comply with the Administrators policy. All other users must comply with the Users policy. @@ -54,7 +54,7 @@ to nine characters. **Step 3 –** Select **9** from the **At Least** dropdown list. -![Set the length to 9](/images/passwordpolicyenforcer/11.2/evaluation/evallength9.webp) +![Set the length to 9](/images/passwordpolicyenforcer/evaluation/evallength9.webp) **Step 4 –** Click **Save**. @@ -62,7 +62,7 @@ to nine characters. **Step 6 –** Select the **PPETestAdmin** user. The results pane shows that the **Admins Policy** applies, and that the password must **contain at least 9 characters**. -![Admins policy is being tested](/images/passwordpolicyenforcer/11.2/evaluation/evaladmin.webp) +![Admins policy is being tested](/images/passwordpolicyenforcer/evaluation/evaladmin.webp) Use the Password Policy Enforcer configuration console, the Windows Change Password screen, the Active Directory Users and Computers console, or the Local Users and Groups console to test password @@ -70,7 +70,7 @@ changes and resets for the **PPETestUser** and **PPETestAdmin** accounts. Passwo should enforce the Eval policy for **PPETestUser**, and the Admins policy for **PPETestAdmin**. :::note -The [Set Priorities](/docs/passwordpolicyenforcer/11.2/admin/manage-policies/manage_policies.md#set-policy-priorities) topic contains +The [Set Priorities](/docs/passwordpolicyenforcer/admin/manage-policies/manage_policies.md#set-policy-priorities) topic contains more information about policy assignments, and how Password Policy Enforcer resolves policy assignment conflicts that occur when more than one policy is assigned to a user. diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/evaluation_overview.md b/docs/passwordpolicyenforcer/evaluation/evaluation_overview.md similarity index 92% rename from docs/passwordpolicyenforcer/11.1/evaluation/evaluation_overview.md rename to docs/passwordpolicyenforcer/evaluation/evaluation_overview.md index 0b47954c2d..08d3903ce6 100644 --- a/docs/passwordpolicyenforcer/11.1/evaluation/evaluation_overview.md +++ b/docs/passwordpolicyenforcer/evaluation/evaluation_overview.md @@ -12,7 +12,7 @@ Password Policy Enforcer helps secure your network by ensuring users set strong user enters a password that doesn't comply with the password policy, Password Policy Enforcer immediately rejects the password and details why the password was rejected. -![introduction_3](/images/passwordpolicyenforcer/11.1/evaluation/introduction_3.webp) +![introduction_3](/images/passwordpolicyenforcer/evaluation/introduction_3.webp) Unlike password cracking products that check passwords after they are accepted by the operating system, Password Policy Enforcer checks new passwords immediately to ensure that weak passwords do diff --git a/docs/passwordpolicyenforcer/11.0/evaluation/improving_the_password_policy.md b/docs/passwordpolicyenforcer/evaluation/improving_the_password_policy.md similarity index 95% rename from docs/passwordpolicyenforcer/11.0/evaluation/improving_the_password_policy.md rename to docs/passwordpolicyenforcer/evaluation/improving_the_password_policy.md index aafe82bc8f..59faedece4 100644 --- a/docs/passwordpolicyenforcer/11.0/evaluation/improving_the_password_policy.md +++ b/docs/passwordpolicyenforcer/evaluation/improving_the_password_policy.md @@ -23,7 +23,7 @@ Click your policy name on the Configuration Console dashboard if needed. **Step 1 –** Open the **Dictionary** rule. -![Open the Dictionary rule](/images/passwordpolicyenforcer/11.0/evaluation/evaldict.webp) +![Open the Dictionary rule](/images/passwordpolicyenforcer/evaluation/evaldict.webp) **Step 2 –** Select the **Detect character substitution** and **Detect words typed backwards** check boxes. diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/installforeval.md b/docs/passwordpolicyenforcer/evaluation/installforeval.md similarity index 75% rename from docs/passwordpolicyenforcer/11.1/evaluation/installforeval.md rename to docs/passwordpolicyenforcer/evaluation/installforeval.md index 085b2e1d0c..330facb1f8 100644 --- a/docs/passwordpolicyenforcer/11.1/evaluation/installforeval.md +++ b/docs/passwordpolicyenforcer/evaluation/installforeval.md @@ -10,16 +10,16 @@ The evaluation installation uses the standard installation packages: - Server Installation: install on each server and domain controller in the domain you are evaluating. You can install manually using the procedure in - [Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/11.1/installation/installationserver.md) or automatically - with [Install with Group Policy Management](/docs/passwordpolicyenforcer/11.1/installation/installationgpm.md) procedure. Installing + [Install Password Policy Enforcer on a Server](/docs/passwordpolicyenforcer/installation/installationserver.md) or automatically + with [Install with Group Policy Management](/docs/passwordpolicyenforcer/installation/installationgpm.md) procedure. Installing Password Policy Enforcer doesn't extend the Active Directory schema. Be sure and install the **Configuration Console** feature on at least one server. - Client Installation: install on each workstation you are evaluating. The Password Policy Client is an optional Password Policy Enforcer component to help users choose compliant passwords. Follow - the [Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/11.1/installation/installationclient.md) procedure, or - [Install with Group Policy Management](/docs/passwordpolicyenforcer/11.1/installation/installationgpm.md). + the [Install Password Policy Enforcer Client](/docs/passwordpolicyenforcer/installation/installationclient.md) procedure, or + [Install with Group Policy Management](/docs/passwordpolicyenforcer/installation/installationgpm.md). You may need to create a firewall port exception on the domain controllers if you are evaluating the Password Policy Client on a domain with client computers. See the -[Password Policy Client](/docs/passwordpolicyenforcer/11.1/admin/password-policy-client/password_policy_client.md) topic for additional +[Password Policy Client](/docs/passwordpolicyenforcer/admin/password-policy-client/password_policy_client.md) topic for additional information. diff --git a/docs/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer.md b/docs/passwordpolicyenforcer/evaluation/preparing_the_computer.md similarity index 91% rename from docs/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer.md rename to docs/passwordpolicyenforcer/evaluation/preparing_the_computer.md index ec68cc0670..986f9a0561 100644 --- a/docs/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer.md +++ b/docs/passwordpolicyenforcer/evaluation/preparing_the_computer.md @@ -48,7 +48,7 @@ policies. **Step 7 –** Close the **Group Policy Management Editor**. -![preparing_the_computer](/images/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer.webp) +![preparing_the_computer](/images/passwordpolicyenforcer/evaluation/preparing_the_computer.webp) **Step 8 –** Execute the `gpupdate/target:computer` command to refresh the Group Policy. @@ -56,7 +56,7 @@ policies. Create two user accounts for the evaluation: **PPETestUser** and **PPETestAdmin**. -![preparing_the_computer_1](/images/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer_1.webp) +![preparing_the_computer_1](/images/passwordpolicyenforcer/evaluation/preparing_the_computer_1.webp) Make **PPETestAdmin** a member of the Domain Admins group if you are evaluating Password Policy Enforcer on a domain controller. diff --git a/docs/passwordpolicyenforcer/11.1/evaluation/testing_the_password_policy.md b/docs/passwordpolicyenforcer/evaluation/testing_the_password_policy.md similarity index 94% rename from docs/passwordpolicyenforcer/11.1/evaluation/testing_the_password_policy.md rename to docs/passwordpolicyenforcer/evaluation/testing_the_password_policy.md index f077cab7f5..ac3a4694b1 100644 --- a/docs/passwordpolicyenforcer/11.1/evaluation/testing_the_password_policy.md +++ b/docs/passwordpolicyenforcer/evaluation/testing_the_password_policy.md @@ -20,7 +20,7 @@ option shows you the most information about the policy. **Step 2 –** Select the **PPETestUser** you created. The details pane displays the policy applied to the selected user. -![Enter user name for the test](/images/passwordpolicyenforcer/11.1/evaluation/evaltestuser.webp) +![Enter user name for the test](/images/passwordpolicyenforcer/evaluation/evaltestuser.webp) **Step 3 –** Enter a password to test. @@ -32,7 +32,7 @@ results pane. **mypassword** fails two requirements. You can hover over the requirements to view the associated rule. -![mypassword fails](/images/passwordpolicyenforcer/11.1/evaluation/evaltestuserfail.webp) +![mypassword fails](/images/passwordpolicyenforcer/evaluation/evaltestuserfail.webp) Click **View log** to expand Password Policy Enforcer's internal event log. The information in the event log can help you to understand why Password Policy Enforcer accepted or rejected a password. @@ -40,7 +40,7 @@ event log can help you to understand why Password Policy Enforcer accepted or re :::note Policy testing simulates a password change, but it may not always reflect what happens when a user changes their password. See the -[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/11.1/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) +[Policy Testing vs. Password Changes](/docs/passwordpolicyenforcer/admin/manage-policies/testpolicy.md#policy-testing-vs-password-changes) topic for additional information. ::: @@ -68,7 +68,7 @@ the Password Policy Client is installed. This helps users to choose a compliant Password Policy Client also changes the message that users see when their password is rejected. Both these messages are customizable. -![introduction_3](/images/passwordpolicyenforcer/11.1/evaluation/introduction_3.webp) +![introduction_3](/images/passwordpolicyenforcer/evaluation/introduction_3.webp) The Password Policy Client doesn't modify any Windows system files, and you don't have to install it to enforce a Password Policy Enforcer password policy. Web browser based versions of the Password diff --git a/docs/passwordpolicyenforcer/11.2/index.md b/docs/passwordpolicyenforcer/index.md similarity index 97% rename from docs/passwordpolicyenforcer/11.2/index.md rename to docs/passwordpolicyenforcer/index.md index f32029918b..8f87ec8670 100644 --- a/docs/passwordpolicyenforcer/11.2/index.md +++ b/docs/passwordpolicyenforcer/index.md @@ -1,10 +1,10 @@ --- -title: "Netwrix Password Policy Enforcer v11.2" +title: "Netwrix Password Policy Enforcer" description: "Netwrix Password Policy Enforcer Introduction" sidebar_position: 1 --- -# Netwrix Password Policy Enforcer v11.2 +# Netwrix Password Policy Enforcer Netwrix Password Policy Enforcer (PPE) helps you secure your network by ensuring users choose strong passwords. PPE rejects new passwords that don't comply with your password policy. If you install the optional Password Policy Client, users can also see which rules their password didn't comply with. A typical Windows network has both domain and local user accounts. Password Policy Enforcer can enforce password policies for both account types, but you will most likely use it for domain accounts in Active Directory. diff --git a/docs/passwordpolicyenforcer/11.0/installation/_category_.json b/docs/passwordpolicyenforcer/installation/_category_.json similarity index 100% rename from docs/passwordpolicyenforcer/11.0/installation/_category_.json rename to docs/passwordpolicyenforcer/installation/_category_.json diff --git a/docs/passwordpolicyenforcer/11.2/installation/disable_windows_rules.md b/docs/passwordpolicyenforcer/installation/disable_windows_rules.md similarity index 96% rename from docs/passwordpolicyenforcer/11.2/installation/disable_windows_rules.md rename to docs/passwordpolicyenforcer/installation/disable_windows_rules.md index 6226ef3879..4a9ba1f3a6 100644 --- a/docs/passwordpolicyenforcer/11.2/installation/disable_windows_rules.md +++ b/docs/passwordpolicyenforcer/installation/disable_windows_rules.md @@ -23,7 +23,7 @@ To disable the Windows password policy rules: 9. Select **Disabled**, then click **OK**. 10. Close the Group Policy Management Editor. -![installing_ppe_3](/images/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer.webp) +![installing_ppe_3](/images/passwordpolicyenforcer/evaluation/preparing_the_computer.webp) :::note Don't set the Windows policies to **Not Configured** as that leaves the previously enforced value in place and doesn't disable the rule. Instead, follow the preceding steps to explicitly set each numeric policy to **0** and set the complexity policy to **Disabled**. diff --git a/docs/passwordpolicyenforcer/11.2/installation/domain_and_local_policies.md b/docs/passwordpolicyenforcer/installation/domain_and_local_policies.md similarity index 96% rename from docs/passwordpolicyenforcer/11.2/installation/domain_and_local_policies.md rename to docs/passwordpolicyenforcer/installation/domain_and_local_policies.md index 5a534e9896..366cb292af 100644 --- a/docs/passwordpolicyenforcer/11.2/installation/domain_and_local_policies.md +++ b/docs/passwordpolicyenforcer/installation/domain_and_local_policies.md @@ -41,13 +41,13 @@ You can also use Group Policy to distribute a local configuration to many comput 4. Expand the **Computer Configuration**, **Preferences**, and **Windows Settings** items in the left pane. 5. Right-click the **Registry** item, then select **New** > **Registry Wizard**. - ![domain_and_local_policies](/images/passwordpolicyenforcer/11.2/administration/domain_and_local_policies.webp) + ![domain_and_local_policies](/images/passwordpolicyenforcer/administration/domain_and_local_policies.webp) 6. Select the computer that contains the Password Policy Enforcer local configuration you want to distribute, then click **Next**. 7. Expand the **HKEY_LOCAL_MACHINE**, **SOFTWARE**, and **ANIXIS** items. 8. Click the **Password Policy Enforcer 11.0** item, then select the checkboxes beside each item in the bottom pane of the window. - ![domain_and_local_policies_1](/images/passwordpolicyenforcer/11.2/administration/domain_and_local_policies_1.webp) + ![domain_and_local_policies_1](/images/passwordpolicyenforcer/administration/domain_and_local_policies_1.webp) 9. Click **Finish**. 10. Close the Group Policy Management Editor. diff --git a/docs/passwordpolicyenforcer/11.2/installation/installationclient.md b/docs/passwordpolicyenforcer/installation/installationclient.md similarity index 84% rename from docs/passwordpolicyenforcer/11.2/installation/installationclient.md rename to docs/passwordpolicyenforcer/installation/installationclient.md index bc43d995ad..8bb0408888 100644 --- a/docs/passwordpolicyenforcer/11.2/installation/installationclient.md +++ b/docs/passwordpolicyenforcer/installation/installationclient.md @@ -18,22 +18,22 @@ PPE only enforces the [Similarity rule](../admin/manage-policies/rules/similarit To manually install the Password Policy Client: -1. Run **Netwrix_PPE_Client_11.2.0.148_x64.msi** (64-bit) or **Netwrix_PPE_Client_11.2.0.148_x86.msi** (32-bit). The Setup wizard opens. +1. Run **Netwrix_PPE_Client_x64.msi** (64-bit) or **Netwrix_PPE_Client_x86.msi** (32-bit). The Setup wizard opens. - ![Client Setup](/images/passwordpolicyenforcer/11.2/install/clientsetup1.webp) + ![Client Setup](/images/passwordpolicyenforcer/install/clientsetup1.webp) 2. Click **Next**. - ![Client Setup](/images/passwordpolicyenforcer/11.2/install/clientsetup2.webp) + ![Client Setup](/images/passwordpolicyenforcer/install/clientsetup2.webp) 3. Review the End-User License Agreement, select the checkbox to accept the Agreement, then click **Next**. - ![Client Setup](/images/passwordpolicyenforcer/11.2/install/clientsetup3.webp) + ![Client Setup](/images/passwordpolicyenforcer/install/clientsetup3.webp) 4. Click **Install**. - ![Client Setup](/images/passwordpolicyenforcer/11.2/install/clientsetup4.webp) + ![Client Setup](/images/passwordpolicyenforcer/install/clientsetup4.webp) 5. Click **Finish** when installation is complete. You don't typically need to restart the computer. @@ -46,7 +46,7 @@ The Password Policy Client runs automatically during a password change. There is Use a software deployment tool or [Group Policy](installationgpm.md) to automate deployment across many computers. You can also run msiexec to install from the command line. For example, run this command with elevated permissions to silently install the 64-bit Password Policy Client: ```batch -msiexec /i Netwrix_PPE_Client_11.2.0.148_x64.msi /q +msiexec /i Netwrix_PPE_Client_x64.msi /q ``` :::tip @@ -65,5 +65,5 @@ Test the Password Policy Client by logging on to a computer, pressing **Ctrl+Alt You can uninstall the Password Policy Client from the **Installed apps** page in Windows Settings, or the **Uninstall or change a program** page in Control Panel. You can also run msiexec to uninstall from the command line. For example, run this command with elevated permissions to silently uninstall the 64-bit Password Policy Client: ```batch -msiexec /x Netwrix_PPE_Client_11.2.0.148_x64.msi /q +msiexec /x Netwrix_PPE_Client_x64.msi /q ``` diff --git a/docs/passwordpolicyenforcer/11.2/installation/installationgpm.md b/docs/passwordpolicyenforcer/installation/installationgpm.md similarity index 92% rename from docs/passwordpolicyenforcer/11.2/installation/installationgpm.md rename to docs/passwordpolicyenforcer/installation/installationgpm.md index 5894352226..e536f2e347 100644 --- a/docs/passwordpolicyenforcer/11.2/installation/installationgpm.md +++ b/docs/passwordpolicyenforcer/installation/installationgpm.md @@ -23,11 +23,11 @@ A distribution point can be a UNC path to a server share, or a Distributed File 2. Expand the **Forest** and **Domains** items, then expand your domain in the left pane. 3. Right-click the target OU in the left pane, then click **Create a GPO in this domain, and Link it here...**. Target the Domain Controllers OU to install a package only on the domain controllers (typical for the Password Policy Server). Target the OU containing your workstations to install a package on those computers (typical for the Password Policy Client), or target the domain root to deploy to all computers in the domain. - ![GPM installation](/images/passwordpolicyenforcer/11.2/install/gpm1.webp) + ![GPM installation](/images/passwordpolicyenforcer/install/gpm1.webp) 4. Enter a descriptive name for the GPO (for example, **Password Policy Enforcer**) in the name field, then press **Enter**. - ![GPM Install](/images/passwordpolicyenforcer/11.2/install/gpm2.webp) + ![GPM Install](/images/passwordpolicyenforcer/install/gpm2.webp) ## Edit the Group Policy Object @@ -42,7 +42,7 @@ A distribution point can be a UNC path to a server share, or a Distributed File 5. Click **Open**. - ![installing_ppe_2](/images/passwordpolicyenforcer/11.2/install/installing_ppe_2.webp) + ![installing_ppe_2](/images/passwordpolicyenforcer/install/installing_ppe_2.webp) 6. Select **Assigned** as the deployment method. 7. Click **OK**. diff --git a/docs/passwordpolicyenforcer/11.2/installation/installationserver.md b/docs/passwordpolicyenforcer/installation/installationserver.md similarity index 81% rename from docs/passwordpolicyenforcer/11.2/installation/installationserver.md rename to docs/passwordpolicyenforcer/installation/installationserver.md index 283329d6f2..cef9bedf8b 100644 --- a/docs/passwordpolicyenforcer/11.2/installation/installationserver.md +++ b/docs/passwordpolicyenforcer/installation/installationserver.md @@ -19,25 +19,25 @@ The [introduction](../index.md) has more information about these components, inc To manually install one or more server components: -1. Run **Netwrix_PPE_Server_11.2.0.148_x64.msi**. The Setup wizard opens. +1. Run **Netwrix_PPE_Server_x64.msi**. The Setup wizard opens. - ![Server Setup](/images/passwordpolicyenforcer/11.2/install/serversetup1.webp) + ![Server Setup](/images/passwordpolicyenforcer/install/serversetup1.webp) 2. Click **Next**. - ![Server Setup](/images/passwordpolicyenforcer/11.2/install/serversetup2.webp) + ![Server Setup](/images/passwordpolicyenforcer/install/serversetup2.webp) 3. Review the End-User License Agreement, select the checkbox to accept the Agreement, then click **Next**. - ![Server Setup](/images/passwordpolicyenforcer/11.2/install/serversetup3.webp) + ![Server Setup](/images/passwordpolicyenforcer/install/serversetup3.webp) 4. Select one or more components to install, then click **Next**. - ![Server Setup](/images/passwordpolicyenforcer/11.2/install/serversetup4.webp) + ![Server Setup](/images/passwordpolicyenforcer/install/serversetup4.webp) 5. Review your selections, then click **Install**. - ![Server Setup](/images/passwordpolicyenforcer/11.2/install/serversetup5.webp) + ![Server Setup](/images/passwordpolicyenforcer/install/serversetup5.webp) 6. Click **Finish** when installation is complete. If prompted to restart the computer, then restart before using the installed components. @@ -46,7 +46,7 @@ To manually install one or more server components: If you have many domain controllers, use a software deployment tool or [Group Policy](installationgpm.md) to automate the deployment. You can also run msiexec to install from the command line. For example, run this command with elevated permissions to silently install only the PPS component and immediately restart the computer: ```batch -msiexec /i Netwrix_PPE_Server_11.2.0.148_x64.msi ADDLOCAL=FeatureServerPPE /q +msiexec /i Netwrix_PPE_Server_x64.msi ADDLOCAL=FeatureServerPPE /q ``` The ADDLOCAL argument tells msiexec which components to install. `ADDLOCAL=FeatureServerPPE,FeatureConsole,FeaturePPEMailerServer` installs all the server components. @@ -60,6 +60,6 @@ Add an exclusion for `%ProgramFiles%\Netwrix\Password Policy Enforcer\PPE.DLL` t You can uninstall, repair, or change the installed server components from the **Installed apps** page in Windows Settings, or the **Uninstall or change a program** page in Control Panel. You can also run msiexec to uninstall from the command line. For example, run this command with elevated permissions to silently uninstall all the PPE server components without restarting the computer: ```batch -msiexec /x Netwrix_PPE_Server_11.2.0.148_x64.msi /q /norestart +msiexec /x Netwrix_PPE_Server_x64.msi /q /norestart ``` Use the REMOVE argument to remove individual components. For example, `REMOVE=FeaturePPEMailerServer` diff --git a/docs/passwordpolicyenforcer/11.2/installation/upgrading.md b/docs/passwordpolicyenforcer/installation/upgrading.md similarity index 87% rename from docs/passwordpolicyenforcer/11.2/installation/upgrading.md rename to docs/passwordpolicyenforcer/installation/upgrading.md index 877387934b..c657253542 100644 --- a/docs/passwordpolicyenforcer/11.2/installation/upgrading.md +++ b/docs/passwordpolicyenforcer/installation/upgrading.md @@ -12,7 +12,7 @@ You can upgrade PPE by running the installer manually, with [Group Policy](insta ## Upgrade the server components -The Password Policy Enforcer server installer detects existing installations and upgrades them to version 11.2. Follow the [Install the Server Components](installationserver.md) instructions to upgrade an existing installation. You don't need to uninstall the old version first. +The Password Policy Enforcer server installer detects existing installations and upgrades them to the latest version. Follow the [Install the Server Components](installationserver.md) instructions to upgrade an existing installation. You don't need to uninstall the old version first. :::warning If the upgrade is major, for example, from 10.x to 11.x, then you should immediately open the [PPE Configuration Console](../admin/configconsole.md) after upgrading the first domain controller in each domain. This automatically imports the configuration settings from the old version to the new one. @@ -26,7 +26,7 @@ Don't run multiple versions of the Password Policy Server in a domain for an ext ## Upgrade the Password Policy Client -The Password Policy Client installer detects existing installations and upgrades them to version 11.2. Follow the [Install the Password Policy Client](installationclient.md) instructions to upgrade an existing installation. You don't need to uninstall the old version first. +The Password Policy Client installer detects existing installations and upgrades them to the latest version. Follow the [Install the Password Policy Client](installationclient.md) instructions to upgrade an existing installation. You don't need to uninstall the old version first. :::warning Don't use any new features while running older Password Policy Enforcer components that may not fully support the new features. Netwrix develops and tests all PPE components together as a single version. For the best experience, use all the components from one version together. diff --git a/docs/passwordpolicyenforcer/11.0/web-overview/_category_.json b/docs/passwordpolicyenforcer/web-overview/_category_.json similarity index 100% rename from docs/passwordpolicyenforcer/11.0/web-overview/_category_.json rename to docs/passwordpolicyenforcer/web-overview/_category_.json diff --git a/docs/passwordpolicyenforcer/11.1/web-overview/configuration.md b/docs/passwordpolicyenforcer/web-overview/configuration.md similarity index 93% rename from docs/passwordpolicyenforcer/11.1/web-overview/configuration.md rename to docs/passwordpolicyenforcer/web-overview/configuration.md index 0cfaf001a6..b7968e14c0 100644 --- a/docs/passwordpolicyenforcer/11.1/web-overview/configuration.md +++ b/docs/passwordpolicyenforcer/web-overview/configuration.md @@ -14,7 +14,7 @@ Enforcer Web Configuration Console. Use the General tab to maintain the list of managed domains, and to configure Password Policy Enforcer integration. See the Password Policy Enforcer topic for additional information. -![configuring_ppe_web](/images/passwordpolicyenforcer/11.1/web/configuring_ppe_web.webp) +![configuring_ppe_web](/images/passwordpolicyenforcer/web/configuring_ppe_web.webp) ### Domain List @@ -55,7 +55,7 @@ Password Policy Enforcer is a configurable password filter that enforces granula with many advanced features. Password Policy Enforcer Web can integrate with Password Policy Enforcer to help users choose a compliant password. -![configuring_ppe_web_1](/images/passwordpolicyenforcer/11.1/web/configuring_ppe_web_1.webp) +![configuring_ppe_web_1](/images/passwordpolicyenforcer/web/configuring_ppe_web_1.webp) Password Policy Enforcer Web displays the Password Policy Enforcer password policy message when a user is prompted for their new password, and the Password Policy Enforcer rejection message if the diff --git a/docs/passwordpolicyenforcer/11.2/web-overview/editing_html_templates.md b/docs/passwordpolicyenforcer/web-overview/editing_html_templates.md similarity index 96% rename from docs/passwordpolicyenforcer/11.2/web-overview/editing_html_templates.md rename to docs/passwordpolicyenforcer/web-overview/editing_html_templates.md index 4cb2470275..833002f739 100644 --- a/docs/passwordpolicyenforcer/11.2/web-overview/editing_html_templates.md +++ b/docs/passwordpolicyenforcer/web-overview/editing_html_templates.md @@ -15,7 +15,7 @@ a language code. The files for the US English language are: | Filename | Content | | --------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -| en_default.htm | Static HTML for the Welcome page. See the [Launch Password Policy Enforcer Web](/docs/passwordpolicyenforcer/11.2/web-overview/using_web.md) topic for additional information. | +| en_default.htm | Static HTML for the Welcome page. See the [Launch Password Policy Enforcer Web](/docs/passwordpolicyenforcer/web-overview/using_web.md) topic for additional information. | | en_ppeweb.htm | Template for the Password Change page. See the [Change Password](using_web.md#change-password) topic for additional information. | | en_finished.htm | Template for the Finished page. | | en_error.htm | Template for the Password Critical Error page. See the [Error Messages](using_web.md#error-messages) topic for additional information. | @@ -116,7 +116,7 @@ or they may be displayed on the wrong page. Validation error messages are shown in a yellow box below the page instructions. Validation errors are normally caused by invalid user input. -![using_ppe_web_1](/images/passwordpolicyenforcer/11.2/web/using_ppe_web_1.webp) +![using_ppe_web_1](/images/passwordpolicyenforcer/web/using_ppe_web_1.webp) Validation error messages are defined in en_ppeweb.htm. The error messages are in the resource strings section near the end of the file. See the Resource Strings topic for additional information. @@ -133,7 +133,7 @@ All the critical error messages are defined in `en_error.htm`. The error message resource strings section near the end of the file. See the Resource Strings topic for additional information. -![using_ppe_web_2](/images/passwordpolicyenforcer/11.2/web/using_ppe_web_2.webp) +![using_ppe_web_2](/images/passwordpolicyenforcer/web/using_ppe_web_2.webp) You may see placeholders like %1 and %2 in some error messages. These are replaced with more information about the error. You should keep these as they provide important information about the @@ -161,7 +161,7 @@ If you want to display some text for all error messages, then insert your text a The finished message is shown after users successfully change their password. This message is defined in en_finished.htm. -![editing_the_html_templates_1](/images/passwordpolicyenforcer/11.2/web/editing_the_html_templates_1.webp) +![editing_the_html_templates_1](/images/passwordpolicyenforcer/web/editing_the_html_templates_1.webp) `

Finished

` diff --git a/docs/passwordpolicyenforcer/11.2/web-overview/installationweb.md b/docs/passwordpolicyenforcer/web-overview/installationweb.md similarity index 100% rename from docs/passwordpolicyenforcer/11.2/web-overview/installationweb.md rename to docs/passwordpolicyenforcer/web-overview/installationweb.md diff --git a/docs/passwordpolicyenforcer/11.0/web-overview/securing_web.md b/docs/passwordpolicyenforcer/web-overview/securing_web.md similarity index 100% rename from docs/passwordpolicyenforcer/11.0/web-overview/securing_web.md rename to docs/passwordpolicyenforcer/web-overview/securing_web.md diff --git a/docs/passwordpolicyenforcer/11.1/web-overview/using_web.md b/docs/passwordpolicyenforcer/web-overview/using_web.md similarity index 80% rename from docs/passwordpolicyenforcer/11.1/web-overview/using_web.md rename to docs/passwordpolicyenforcer/web-overview/using_web.md index 3d9b04f826..4f29e2f719 100644 --- a/docs/passwordpolicyenforcer/11.1/web-overview/using_web.md +++ b/docs/passwordpolicyenforcer/web-overview/using_web.md @@ -10,7 +10,7 @@ The default URL for Password Policy Enforcer Web is: `http://[server]/ppeweb/` Where [server] is the name or IP address of the server hosting Password Policy Enforcer Web. -![Web Welcome page](/images/passwordpolicyenforcer/11.1/web/webwelcome.webp) +![Web Welcome page](/images/passwordpolicyenforcer/web/webwelcome.webp) The default page is called the Welcome page. You can customize the information on this page by editing **en_default.htm**, or you can bypass this page and send users directly to the Password @@ -25,7 +25,7 @@ You can also include the username and/or domain in the URL: :::info Install the SSL Certificate the web server and use the HTTPS protocol if Password Policy Enforcer Web is used on an unencrypted network. See the -[Install an SSL Certificate](/docs/passwordpolicyenforcer/11.1/web-overview/securing_web.md) topic for additional +[Install an SSL Certificate](/docs/passwordpolicyenforcer/web-overview/securing_web.md) topic for additional information. ::: @@ -43,11 +43,11 @@ To change a password with Password Policy Enforcer Web: **Step 1 –** Click **Change Password** on the Welcome page. -![using_ppe_web](/images/passwordpolicyenforcer/11.1/web/using_ppe_web.webp) +![using_ppe_web](/images/passwordpolicyenforcer/web/using_ppe_web.webp) **Step 2 –** Enter a **Username** and **Domain**, then click **Next**. -![introduction_4](/images/passwordpolicyenforcer/11.1/web/introduction_4.webp) +![introduction_4](/images/passwordpolicyenforcer/web/introduction_4.webp) **Step 3 –** Enter the **Old Password**, **New Password**, and **Confirm Password**, then click **Next**. @@ -65,14 +65,14 @@ Validation errors are shown in a yellow box below the page instructions. Validat normally caused by invalid user input. They can often be overcome by changing the value of one or more input fields and resubmitting the form. -![using_ppe_web_1](/images/passwordpolicyenforcer/11.1/web/using_ppe_web_1.webp) +![using_ppe_web_1](/images/passwordpolicyenforcer/web/using_ppe_web_1.webp) Critical errors are shown on their own page. These errors are mostly a result of configuration or system errors. Users can sometimes overcome a critical error by following the instructions in the error message, but most critical errors are beyond the user's control. -![using_ppe_web_2](/images/passwordpolicyenforcer/11.1/web/using_ppe_web_2.webp) +![using_ppe_web_2](/images/passwordpolicyenforcer/web/using_ppe_web_2.webp) Validation and critical error messages are stored in the HTML templates. You can modify the default -messages by editing the templates. See the [Edit HTML Templates](/docs/passwordpolicyenforcer/11.1/web-overview/editing_html_templates.md) topic +messages by editing the templates. See the [Edit HTML Templates](/docs/passwordpolicyenforcer/web-overview/editing_html_templates.md) topic for additional information. diff --git a/docs/passwordpolicyenforcer/11.2/web-overview/web_overview.md b/docs/passwordpolicyenforcer/web-overview/web_overview.md similarity index 95% rename from docs/passwordpolicyenforcer/11.2/web-overview/web_overview.md rename to docs/passwordpolicyenforcer/web-overview/web_overview.md index 222368bf98..a1ca37938b 100644 --- a/docs/passwordpolicyenforcer/11.2/web-overview/web_overview.md +++ b/docs/passwordpolicyenforcer/web-overview/web_overview.md @@ -13,7 +13,7 @@ Download Password Policy Enforcer Web: [PasswordPolicyEnforcer-Web-10.3.0.1.msi](https://releases.netwrix.com/products/passwordpolicyenforcer/10.3/passwordpolicyenforcer-web-10.3.0.1.msi) -![introduction_4](/images/passwordpolicyenforcer/11.2/web/introduction_4.webp) +![introduction_4](/images/passwordpolicyenforcer/web/introduction_4.webp) Password Policy Enforcer Web communicates directly with the domain controllers, so it works best when both the web server and domain controllers are on the same network. If you need to put the web diff --git a/docs/passwordreset/3.23/administration/configuring_password_reset.md b/docs/passwordreset/3.23/administration/configuring_password_reset.md index f4c7fd1f50..15331fb85d 100644 --- a/docs/passwordreset/3.23/administration/configuring_password_reset.md +++ b/docs/passwordreset/3.23/administration/configuring_password_reset.md @@ -252,7 +252,7 @@ A warning icon is shown beside the language dropdown list if an e-mail template every language. Define an e-mail template for every language to ensure that users can understand their e-mail alerts. -![configuring_apr_5](/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_5.webp) +![configuring_apr_5](/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_5.webp) :::warning An attacker may choose a specific language to avoid detection. E-mail alerts are sent @@ -380,7 +380,7 @@ text box, and the path to the script file and other parameters in the **Paramete ::: -![configuring_apr_7](/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_7.webp) +![configuring_apr_7](/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_7.webp) ## Security Tab diff --git a/docs/passwordreset/3.23/administration/password_reset_client.md b/docs/passwordreset/3.23/administration/password_reset_client.md index 7976409133..606782536c 100644 --- a/docs/passwordreset/3.23/administration/password_reset_client.md +++ b/docs/passwordreset/3.23/administration/password_reset_client.md @@ -248,7 +248,7 @@ Editor. **Step 10 –** Click inside the **License key** text box, then paste the license key. -![the_password_reset_client_5](/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_5.webp) +![the_password_reset_client_5](/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_5.webp) **Step 11 –** Click **OK**. diff --git a/docs/passwordreset/3.23/administration/persuading_users_to_enroll.md b/docs/passwordreset/3.23/administration/persuading_users_to_enroll.md index 09f32f2c15..8679339f61 100644 --- a/docs/passwordreset/3.23/administration/persuading_users_to_enroll.md +++ b/docs/passwordreset/3.23/administration/persuading_users_to_enroll.md @@ -27,7 +27,7 @@ and **3.0** registry keys. **Step 3 –** Create a new **DWORD** value called **WebAPIState**, and set it to 1. -![persuading_users_to_enroll](/images/passwordpolicyenforcer/10.2/password_reset/administration/persuading_users_to_enroll.webp) +![persuading_users_to_enroll](/images/passwordpolicyenforcer/password_reset/administration/persuading_users_to_enroll.webp) ## Querying the API diff --git a/docs/passwordreset/3.23/administration/using_the_data_console.md b/docs/passwordreset/3.23/administration/using_the_data_console.md index b9f046e555..ea93e8023f 100644 --- a/docs/passwordreset/3.23/administration/using_the_data_console.md +++ b/docs/passwordreset/3.23/administration/using_the_data_console.md @@ -13,7 +13,7 @@ The Data Console has three tabs. The **Recent Activity** tab shows a chart of re chart is empty when Password Reset is first installed, but it populates as the system is used. -![using_the_data_console](/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console.webp) +![using_the_data_console](/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console.webp) The bars in the chart show how many successful enrollments, resets, unlocks, and changes occurred every day. You can click the bars to see a filtered view of the events for that day. For example, @@ -154,7 +154,7 @@ Use the Filter Editor to create complex filters, filters for hidden columns, or regularly used filters. Press **CTRL** + **F** to open the Filter Editor, or click the **Filter Editor** button in the lower right corner of the Data Console. -![using_the_data_console_9](/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_9.webp) +![using_the_data_console_9](/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_9.webp) A filter may contain several conditions. Conditions start with a column name, followed by an operator, and sometimes a value. Column names are shown in green, operators in maroon, and values in diff --git a/docs/passwordreset/3.3/administration/configuringpasswordreset/about_tab.md b/docs/passwordreset/3.3/administration/configuringpasswordreset/about_tab.md index a1518e5cf8..c8be2224ce 100644 --- a/docs/passwordreset/3.3/administration/configuringpasswordreset/about_tab.md +++ b/docs/passwordreset/3.3/administration/configuringpasswordreset/about_tab.md @@ -9,7 +9,7 @@ sidebar_position: 70 Use the **About** tab to check the version and license information, and to install a new license key. -![configuring_npr_10](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_10.webp) +![configuring_npr_10](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_10.webp) To install a new license key, copy the entire license e-mail to the clipboard, and then click Get license from clipboard. diff --git a/docs/passwordreset/3.3/administration/configuringpasswordreset/email_tab.md b/docs/passwordreset/3.3/administration/configuringpasswordreset/email_tab.md index 968a29c6ba..012fccdec0 100644 --- a/docs/passwordreset/3.3/administration/configuringpasswordreset/email_tab.md +++ b/docs/passwordreset/3.3/administration/configuringpasswordreset/email_tab.md @@ -34,7 +34,7 @@ sends an e-mail when the event occurs. Enabled triggers are underlined. Click the name of an enabled trigger to edit the trigger's e-mail template. -![configuring_npr_4](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_4.webp) +![configuring_npr_4](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_4.webp) Type the name and e-mail address you wish to appear in the e-mail's From field in the **From** text box. The correct format is "Display Name" `` @@ -82,7 +82,7 @@ A warning icon appears beside the language drop-down list if no e-mail template every language. You should define an e-mail template for every language to ensure that users can understand their e-mail alerts. -![configuring_npr_5](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_5.webp) +![configuring_npr_5](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_5.webp) :::warning An attacker may choose a specific language to avoid detection. Password Reset sends e-mail alerts diff --git a/docs/passwordreset/3.3/administration/configuringpasswordreset/enroll_tab.md b/docs/passwordreset/3.3/administration/configuringpasswordreset/enroll_tab.md index cb3737b459..06d4f0e047 100644 --- a/docs/passwordreset/3.3/administration/configuringpasswordreset/enroll_tab.md +++ b/docs/passwordreset/3.3/administration/configuringpasswordreset/enroll_tab.md @@ -8,7 +8,7 @@ sidebar_position: 20 Use the **Enroll** tab to maintain the list of enrollment questions and options. -![configuring_npr_2](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_2.webp) +![configuring_npr_2](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_2.webp) ### Question List diff --git a/docs/passwordreset/3.3/administration/configuringpasswordreset/general_tab.md b/docs/passwordreset/3.3/administration/configuringpasswordreset/general_tab.md index e2c3982e73..4e5eaa8f9d 100644 --- a/docs/passwordreset/3.3/administration/configuringpasswordreset/general_tab.md +++ b/docs/passwordreset/3.3/administration/configuringpasswordreset/general_tab.md @@ -82,7 +82,7 @@ Password Reset is a configurable password filter that enforces granular password advanced features. Password Reset can integrate with Password Policy Enforcer to help users choose a compliant password. -![configuring_npr_1](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_1.webp) +![configuring_npr_1](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_1.webp) Password Reset displays the Password Policy Enforcer policy message when users are prompted for their new password, and the Password Policy Enforcer rejection message if the new password does not @@ -117,7 +117,7 @@ server configuration, and enable "Only accept encrypted client request". ::: -![using_ppe_with_npr](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_ppe_with_npr.webp) +![using_ppe_with_npr](/images/passwordpolicyenforcer/passwordreset/administration/using_ppe_with_npr.webp) Do not enable this option if you are using Netwrix Password Reset v3.3 with Netwrix Password Policy Enforcer v8.x or earlier versions, or with Netwrix Password Policy Enforcer/Web. If you are diff --git a/docs/passwordreset/3.3/administration/configuringpasswordreset/permissions_tab.md b/docs/passwordreset/3.3/administration/configuringpasswordreset/permissions_tab.md index ede74205ca..2dfa5e41c5 100644 --- a/docs/passwordreset/3.3/administration/configuringpasswordreset/permissions_tab.md +++ b/docs/passwordreset/3.3/administration/configuringpasswordreset/permissions_tab.md @@ -8,7 +8,7 @@ sidebar_position: 60 Use the **Permissions** tab to control which users can use Password Reset. -![configuring_npr_9](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_9.webp) +![configuring_npr_9](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_9.webp) ### Enroll diff --git a/docs/passwordreset/3.3/administration/configuringpasswordreset/security_tab.md b/docs/passwordreset/3.3/administration/configuringpasswordreset/security_tab.md index d698ef9eb8..dca8a7aa0c 100644 --- a/docs/passwordreset/3.3/administration/configuringpasswordreset/security_tab.md +++ b/docs/passwordreset/3.3/administration/configuringpasswordreset/security_tab.md @@ -9,7 +9,7 @@ sidebar_position: 50 Use the **Security** tab to configure the inactivity timeout, password reset policies, and the lockout threshold. -![configuring_npr_8](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_8.webp) +![configuring_npr_8](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_8.webp) ### Inactivity Timeout diff --git a/docs/passwordreset/3.3/administration/configuringpasswordreset/verification_tab.md b/docs/passwordreset/3.3/administration/configuringpasswordreset/verification_tab.md index 4ecbd0ce77..638a5f9f6a 100644 --- a/docs/passwordreset/3.3/administration/configuringpasswordreset/verification_tab.md +++ b/docs/passwordreset/3.3/administration/configuringpasswordreset/verification_tab.md @@ -11,7 +11,7 @@ provide two-factor authentication and authenticate users that have not manually verification code to the user's mobile phone by e-mail and/or SMS, and the user enters the verification code to continue. -![configuring_npr_6](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_6.webp)7 +![configuring_npr_6](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_6.webp)7 #### Verification Codes @@ -58,7 +58,7 @@ hide parts of the e-mail address and phone number when requesting a verification especially important if automatic enrollment is enabled, as it stops an attacker from discovering information about the user. -![configuring_npr_0](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_0.webp) +![configuring_npr_0](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_0.webp) Verification codes are of a specified length, and may contain both alpha and numeric characters. Select the desired options from the **Create verification codes with...** drop-down lists. Longer, @@ -119,4 +119,4 @@ text box, and the path to the script file and other parameters in the **Paramete ::: -![configuring_npr_7](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_7.webp) +![configuring_npr_7](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_7.webp) diff --git a/docs/passwordreset/3.3/administration/editing_the_html_templates.md b/docs/passwordreset/3.3/administration/editing_the_html_templates.md index 52d5c57327..fb332c248c 100644 --- a/docs/passwordreset/3.3/administration/editing_the_html_templates.md +++ b/docs/passwordreset/3.3/administration/editing_the_html_templates.md @@ -138,7 +138,7 @@ text_short classes are used in page instructions to tailor content to the screen Validation error messages are shown in a red box below the page instructions. Validation errors are normally caused by invalid user input. -![using_npr_12](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_12.webp) +![using_npr_12](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_12.webp) Validation error messages are defined in the relevant template (en_enroll.htm, en_reset.htm, en_unlock.htm, or en_change.htm). The error messages are in the resource strings section near the @@ -159,7 +159,7 @@ information about the error. You should keep these, but you can delete them if y All the critical error messages are defined in en_error.htm. The messages are in the resource strings section near the end of the file. See the [Resource Strings](#resource-strings) topic for details on editing message text. -![using_npr_13](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_13.webp) +![using_npr_13](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_13.webp) You may see placeholders like %1 and %2 in some error messages. These are replaced with more information about the error. You should keep these, but you can delete them if you don't want them. @@ -184,7 +184,7 @@ Finished messages are shown after users successfully complete an enroll, reset, These messages are defined in the Resource Strings section near the end of `en_finished.htm`. See the [Resource Strings](#resource-strings) topic for details on editing message text. -![using_npr_9](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_9.webp) +![using_npr_9](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_9.webp) `en_finished.htm` has two resource strings for password changes (RES_FINISHED_CHANGE and RES_FINISHED_CHANGE_INVITE). The first is shown when a user who has enrolled into NPR changes their diff --git a/docs/passwordreset/3.3/administration/installation.md b/docs/passwordreset/3.3/administration/installation.md index 094b495ba2..54cef99889 100644 --- a/docs/passwordreset/3.3/administration/installation.md +++ b/docs/passwordreset/3.3/administration/installation.md @@ -221,7 +221,7 @@ Reset**, and **3.0** registry keys. **Step 12 –** Set the **ServerIP** registry value to the IP address of the computer that you installed the Password Reset Server onto. -![installing_npr_1](/images/passwordpolicyenforcer/11.0/passwordreset/administration/installing_npr_1.webp) +![installing_npr_1](/images/passwordpolicyenforcer/passwordreset/administration/installing_npr_1.webp) The Password Reset Setup wizard only installs one Web Interface on each server, but you can copy the files to another directory and publish several Web Interfaces from one server. Each directory can diff --git a/docs/passwordreset/3.3/administration/password_reset_client.md b/docs/passwordreset/3.3/administration/password_reset_client.md index bcaf131a30..2863bc6cde 100644 --- a/docs/passwordreset/3.3/administration/password_reset_client.md +++ b/docs/passwordreset/3.3/administration/password_reset_client.md @@ -140,7 +140,7 @@ installation folder. (`\Program Files\Netwrix Password Reset\` by default). **Step 7 –** Select **NPRClt.adm**, and then click **Open**. -![the_password_reset_client_2](/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_2.webp) +![the_password_reset_client_2](/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_2.webp) **Step 8 –** Click **Close**. @@ -157,12 +157,12 @@ domain level. Templates**, **Classic Administrative Templates (ADM)**, **Netwrix Password Reset**, and **Password Reset Client** items. -![the_password_reset_client_3](/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_3.webp) +![the_password_reset_client_3](/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_3.webp) **Step 4 –** Double-click the **Browser settings** item in the right pane of the Group Policy Management Editor. -![the_password_reset_client_4](/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_4.webp) +![the_password_reset_client_4](/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_4.webp) **Step 5 –** Select the **Enabled**option. @@ -263,7 +263,7 @@ Editor. **Step 10 –** Click inside the **License key** text box, then paste the license key. -![the_password_reset_client_5](/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_5.webp) +![the_password_reset_client_5](/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_5.webp) **Step 11 –** Click **OK**. diff --git a/docs/passwordreset/3.3/administration/using_password_reset.md b/docs/passwordreset/3.3/administration/using_password_reset.md index ee33ac72b1..04ebcba287 100644 --- a/docs/passwordreset/3.3/administration/using_password_reset.md +++ b/docs/passwordreset/3.3/administration/using_password_reset.md @@ -80,16 +80,16 @@ Follow the steps below to reset an account password. **Step 3 –** Type the **Answer** to the first question, and then click **Next**. Repeat until all questions are answered correctly. -![using_npr_3](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_3.webp) +![using_npr_3](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_3.webp) **Step 4 –** Password Reset may ask you to enter a verification code. The verification code is sent to your phone by e-mail or SMS. Type the **Code**, and then click **Next**. -![using_npr_5](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_5.webp) +![using_npr_5](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_5.webp) **Step 5 –** Type the new **Password** into both text boxes, and then click **Next**. -![using_npr_6](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_6.webp) +![using_npr_6](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_6.webp) **Step 6 –** Click **OK** to return to the menu. @@ -102,7 +102,7 @@ Follow the steps below to unlock an account. **Step 1 –** Click the **Unlock** item in the menu. -![using_npr_7](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_7.webp) +![using_npr_7](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_7.webp) **Step 2 –** Type a **Username** and **Domain**, and then click **Next**. @@ -111,12 +111,12 @@ Follow the steps below to unlock an account. **Step 3 –** Type the **Answer** to the first question, and then click **Next**. Repeat until all questions are answered correctly. -![using_npr_8](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_8.webp) +![using_npr_8](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_8.webp) **Step 4 –** Password Reset may ask you to enter a verification code. The verification code is sent to your phone by e-mail or SMS. Type the **Code**, and then click **Next**. -![using_npr_9](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_9.webp) +![using_npr_9](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_9.webp) **Step 5 –** Click **OK** to return to the menu. @@ -159,7 +159,7 @@ Validation errors appear in a red box below the page instructions. Validation er caused by invalid user input. You can often resolve them by changing the value of one or more input fields and resubmitting the form. -![using_npr_12](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_12.webp) +![using_npr_12](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_12.webp) Critical errors appear on their own page. These errors are mostly a result of configuration or system errors. Password Reset may write an event to the Windows Application event log on the Password Reset @@ -167,7 +167,7 @@ Server computer when a critical error occurs. Users can sometimes overcome a cri following the instructions in the error message, but most critical errors are beyond the user's control. -![using_npr_13](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_13.webp) +![using_npr_13](/images/passwordpolicyenforcer/passwordreset/administration/using_npr_13.webp) Validation and critical error messages are stored in the HTML templates. You can modify the default messages by editing the templates. See diff --git a/docs/passwordreset/3.3/administration/usingthedataconsole/filter_editor.md b/docs/passwordreset/3.3/administration/usingthedataconsole/filter_editor.md index f144b1a6e8..e293998b6b 100644 --- a/docs/passwordreset/3.3/administration/usingthedataconsole/filter_editor.md +++ b/docs/passwordreset/3.3/administration/usingthedataconsole/filter_editor.md @@ -10,7 +10,7 @@ Use the Filter Editor to create complex filters, filters for hidden columns, or regularly used filters. Press **CTRL** + **F** to open the Filter Editor, or click the **Filter Editor** button in the lower right corner of the Data Console. -![using_the_data_console_9](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_9.webp) +![using_the_data_console_9](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_9.webp) A filter may contain several conditions. Conditions start with a column name, followed by an operator, and sometimes a value. The Filter Editor shows column names in green, operators in maroon, and values in @@ -36,4 +36,4 @@ Some columns are hidden in the Data Console. You can use the Filter Editor to cr these columns. For example, the filter in the image below shows all users with an NPR v1 enrollment record. -![using_the_data_console_10](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_10.webp) +![using_the_data_console_10](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_10.webp) diff --git a/docs/passwordreset/3.3/administration/usingthedataconsole/filtering_data.md b/docs/passwordreset/3.3/administration/usingthedataconsole/filtering_data.md index 11f3445024..8ae2b17fe8 100644 --- a/docs/passwordreset/3.3/administration/usingthedataconsole/filtering_data.md +++ b/docs/passwordreset/3.3/administration/usingthedataconsole/filtering_data.md @@ -18,7 +18,7 @@ from Filtering by Column Values. Create more complex filters with the Custom Fil The top row in the **Audit Log** and **Users** tabs is called the Filter Row. You can type filter values directly into this row. -![using_the_data_console_3](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_3.webp) +![using_the_data_console_3](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_3.webp) The Filter Row is empty when you first open the Data Console. To create a filter, click the **Filter Row** in the column you want to filter. A cursor appears. Type a value, and then press **ENTER** @@ -28,7 +28,7 @@ Click the button to show an editor or selector that helps you enter a value. Val wildcard characters. Use a ? to match any single character, or a \* to match more than one character. -![using_the_data_console_4](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_4.webp) +![using_the_data_console_4](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_4.webp) The image shows a filter on the Date, Source, and Source IP columns. Only password reset events on 2/5/2015 originating from IP addresses starting with 192.168.115 appear. The small blue @@ -44,19 +44,19 @@ or the filter editor windows for a logical OR filter. You can also create a filter by selecting values from a list in the column headers. -![using_the_data_console_5](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_5.webp) +![using_the_data_console_5](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_5.webp) Hover the mouse pointer over a column header until a small button appears on the right side of the header. -![using_the_data_console_6](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_6.webp) +![using_the_data_console_6](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_6.webp) Click the button to show a list of values in the column. Select one or more values from the list. Rows that do not match one of the selected values are hidden. -![using_the_data_console_7](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_7.webp) +![using_the_data_console_7](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_7.webp) The list of values for date and date/time columns also includes date ranges such as **Last 7 days**, **Today**, **Yesterday**, etc. @@ -69,7 +69,7 @@ filter. Use custom filters to search for partial matches, find a range of values, or to create more complex filters. Click **(Custom...)** in a column header's value list to create a custom filter. -![using_the_data_console_8](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_8.webp) +![using_the_data_console_8](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_8.webp) Custom filters can contain one or two conditions for each column. Select an operator for the first condition from the drop-down list below the column name. The list shows only relevant operators for each @@ -99,16 +99,16 @@ The Status Bar appears at the very bottom of the Data Console. It shows the numb records and the total record count. The Filter Bar appears above the Status Bar, and it shows the active filter. The button on the right side of the Filter Bar opens the Filter Editor. -![using_the_data_console_11](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_11.webp) +![using_the_data_console_11](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_11.webp) A button and a check box appear on the left side of the Filter Bar when a filter is active. Click the button to clear the filter. Toggle the check box to disable or enable the filter. -![using_the_data_console_12](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_12.webp) +![using_the_data_console_12](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_12.webp) A drop-down button appears to the right of the filter. Click it to select a recently used filter. -![using_the_data_console_13](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_13.webp) +![using_the_data_console_13](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_13.webp) ## Exporting Data diff --git a/docs/passwordreset/3.3/administration/usingthedataconsole/using_the_data_console.md b/docs/passwordreset/3.3/administration/usingthedataconsole/using_the_data_console.md index fbb8dc7a84..773823e1c5 100644 --- a/docs/passwordreset/3.3/administration/usingthedataconsole/using_the_data_console.md +++ b/docs/passwordreset/3.3/administration/usingthedataconsole/using_the_data_console.md @@ -12,7 +12,7 @@ The Data Console allows you to view and export data collected by Password Reset. The Data Console has three tabs. The **Recent Activity** tab shows a chart of recent requests. The chart is empty when Password Reset is first installed, but populates as the system is used. -![using_the_data_console](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console.webp) +![using_the_data_console](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console.webp) The bars in the chart show how many successful enrollments, resets, unlocks, and changes occurred every day. You can click the bars to see a filtered view of the events for that day. For example, diff --git a/docs/passwordreset/3.3/administration/workingwiththedatabase/moving_to_sql_server.md b/docs/passwordreset/3.3/administration/workingwiththedatabase/moving_to_sql_server.md index 9f7b2c0bf5..60bb74157b 100644 --- a/docs/passwordreset/3.3/administration/workingwiththedatabase/moving_to_sql_server.md +++ b/docs/passwordreset/3.3/administration/workingwiththedatabase/moving_to_sql_server.md @@ -23,7 +23,7 @@ Windows authentication. To identify the service account, open services.msc, doub Password Reset service, and then click the Log On tab. Password Reset logs on to SQL Server with this account. -![working_with_the_database](/images/passwordpolicyenforcer/11.0/passwordreset/administration/working_with_the_database.webp) +![working_with_the_database](/images/passwordpolicyenforcer/passwordreset/administration/working_with_the_database.webp) **Step 3 –** Create an SQL Server user, and map it to the service account login. @@ -68,7 +68,7 @@ information, and **Trust server certificate** must be selected if SQL Server is certificate. SQL Server uses a self-signed certificate if a trusted certificate is not installed. The SQL Server Native Client must be installed if **Trust server certificate** is selected. -![working_with_the_database_1](/images/passwordpolicyenforcer/11.0/passwordreset/administration/working_with_the_database_1.webp) +![working_with_the_database_1](/images/passwordpolicyenforcer/passwordreset/administration/working_with_the_database_1.webp) **Step 8 –** Click **Next**. diff --git a/docs/passwordreset/3.3/evaluation/configuring_password_reset.md b/docs/passwordreset/3.3/evaluation/configuring_password_reset.md index dc6feed127..461e819659 100644 --- a/docs/passwordreset/3.3/evaluation/configuring_password_reset.md +++ b/docs/passwordreset/3.3/evaluation/configuring_password_reset.md @@ -10,7 +10,7 @@ In the previous section, you used Password Reset with a default configuration. Y Configuration Console to edit the configuration settings. Click Start > Netwrix Password Reset > NPR Configuration Console to open the console. -![configuring_npr_1](/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr.webp) +![configuring_npr_1](/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr.webp) The Configuration Console has a tabbed layout. Click the tabs along the top to see the various settings. Most of the settings are self-explanatory. Press **F1** on any of the tabs to see the help diff --git a/docs/passwordreset/3.3/evaluation/data_console.md b/docs/passwordreset/3.3/evaluation/data_console.md index 1775d07a94..dd4083e93c 100644 --- a/docs/passwordreset/3.3/evaluation/data_console.md +++ b/docs/passwordreset/3.3/evaluation/data_console.md @@ -19,7 +19,7 @@ every day. You can click the bars to see a filtered view of the events for that The Audit Log tab contains all the events recorded by Password Reset. You can create filters to show only some of the events. Filters are flexible. -![the_data_console_1](/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_9.webp) +![the_data_console_1](/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_9.webp) The Users tab contains information about each user. You can export the data in the Audit Log and Users tabs from the File menu. diff --git a/docs/passwordreset/3.3/evaluation/evaluation_overview.md b/docs/passwordreset/3.3/evaluation/evaluation_overview.md index 7b53b76b7b..13f4a7d594 100644 --- a/docs/passwordreset/3.3/evaluation/evaluation_overview.md +++ b/docs/passwordreset/3.3/evaluation/evaluation_overview.md @@ -17,7 +17,7 @@ the first time. [Contact Netwrix support](mailto:support@netwrix.com) if you have any questions or if you encounter any problems during your evaluation. -![introduction_1_1](/images/passwordpolicyenforcer/11.0/passwordreset/evaluation/introduction_1_1.webp) +![introduction_1_1](/images/passwordpolicyenforcer/passwordreset/evaluation/introduction_1_1.webp) The Password Reset Administrator's Guide contains additional installation and configuration information. Refer to the Administrator's Guide for more detailed coverage of the topics discussed diff --git a/docs/passwordreset/CLAUDE.md b/docs/passwordreset/CLAUDE.md index f0958a616c..8541107a75 100644 --- a/docs/passwordreset/CLAUDE.md +++ b/docs/passwordreset/CLAUDE.md @@ -30,8 +30,8 @@ Both versions share the same top-level sections: `administration/`, `evaluation/ All images live under `static/images/` at the repo root. In markdown, paths start with `/images/...` (Docusaurus serves `static/` at the root). Many passwordreset images are stored under `static/images/passwordpolicyenforcer/`, not `static/images/passwordreset/`. This is by design — the products were historically bundled together. -- **3.3 docs** → files on disk at `static/images/passwordpolicyenforcer/11.0/passwordreset/`, referenced in markdown as `/images/passwordpolicyenforcer/11.0/passwordreset/...` -- **3.23 docs** → files on disk at `static/images/passwordpolicyenforcer/10.2/password_reset/`, referenced in markdown as `/images/passwordpolicyenforcer/10.2/password_reset/...` (note the underscore) +- **3.3 docs** → files on disk at `static/images/passwordpolicyenforcer/passwordreset/`, referenced in markdown as `/images/passwordpolicyenforcer/passwordreset/...` +- **3.23 docs** → files on disk at `static/images/passwordpolicyenforcer/password_reset/`, referenced in markdown as `/images/passwordpolicyenforcer/password_reset/...` (note the underscore) - Some images are under `static/images/passwordreset/3.3/` and `static/images/passwordreset/3.23/` as expected When adding or updating images, check existing references in the file to determine which image directory path convention to follow. diff --git a/sidebars/passwordpolicyenforcer/10.2.js b/sidebars/passwordpolicyenforcer.js similarity index 100% rename from sidebars/passwordpolicyenforcer/10.2.js rename to sidebars/passwordpolicyenforcer.js diff --git a/sidebars/passwordpolicyenforcer/11.0.js b/sidebars/passwordpolicyenforcer/11.0.js deleted file mode 100644 index f4e8941a40..0000000000 --- a/sidebars/passwordpolicyenforcer/11.0.js +++ /dev/null @@ -1,8 +0,0 @@ -module.exports = { - sidebar: [ - { - type: 'autogenerated', - dirName: '.', - }, - ], -}; diff --git a/sidebars/passwordpolicyenforcer/11.1.js b/sidebars/passwordpolicyenforcer/11.1.js deleted file mode 100644 index f4e8941a40..0000000000 --- a/sidebars/passwordpolicyenforcer/11.1.js +++ /dev/null @@ -1,8 +0,0 @@ -module.exports = { - sidebar: [ - { - type: 'autogenerated', - dirName: '.', - }, - ], -}; diff --git a/sidebars/passwordpolicyenforcer/11.2.js b/sidebars/passwordpolicyenforcer/11.2.js deleted file mode 100644 index f4e8941a40..0000000000 --- a/sidebars/passwordpolicyenforcer/11.2.js +++ /dev/null @@ -1,8 +0,0 @@ -module.exports = { - sidebar: [ - { - type: 'autogenerated', - dirName: '.', - }, - ], -}; diff --git a/src/config/products.js b/src/config/products.js index a169ded97f..41db9ba671 100644 --- a/src/config/products.js +++ b/src/config/products.js @@ -344,34 +344,13 @@ export const PRODUCTS = [ icon: '', versions: [ { - version: '11.2', - label: '11.2', + version: 'current', + label: 'Current', isLatest: true, - sidebarFile: './sidebars/passwordpolicyenforcer/11.2.js', - }, - { - version: '11.1', - label: '11.1', - isLatest: false, - hidden: true, - sidebarFile: './sidebars/passwordpolicyenforcer/11.1.js', - }, - { - version: '11.0', - label: '11.0', - isLatest: false, - hidden: true, - sidebarFile: './sidebars/passwordpolicyenforcer/11.0.js', - }, - { - version: '10.2', - label: '10.2', - isLatest: false, - hidden: true, - sidebarFile: './sidebars/passwordpolicyenforcer/10.2.js', + sidebarFile: './sidebars/passwordpolicyenforcer.js', }, ], - defaultVersion: '11.2', + defaultVersion: 'current', }, { id: 'passwordreset', diff --git a/static/images/passwordpolicyenforcer/10.2/administration/bulkpasswordtest.webp b/static/images/passwordpolicyenforcer/10.2/administration/bulkpasswordtest.webp deleted file mode 100644 index faea0baa22..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/bulkpasswordtest.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_0.webp b/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_0.webp deleted file mode 100644 index dae4f78bc5..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_0.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_1.webp b/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_1.webp deleted file mode 100644 index 096281bc9e..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_2.webp b/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_2.webp deleted file mode 100644 index c8c7cda514..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_3.webp b/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_3.webp deleted file mode 100644 index 338c769f96..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_4.webp b/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_4.webp deleted file mode 100644 index 572979667f..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_5.webp b/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_5.webp deleted file mode 100644 index 6a74d4ece5..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_6.webp b/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_6.webp deleted file mode 100644 index 66883e563c..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_6.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_7.webp b/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_7.webp deleted file mode 100644 index 44753686b2..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/configuring_ppe_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/cpcgeneral.webp b/static/images/passwordpolicyenforcer/10.2/administration/cpcgeneral.webp deleted file mode 100644 index 7320e4ebf8..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/cpcgeneral.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/cpcreportrecipient.webp b/static/images/passwordpolicyenforcer/10.2/administration/cpcreportrecipient.webp deleted file mode 100644 index a0a3e49538..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/cpcreportrecipient.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/cpcusernotification.webp b/static/images/passwordpolicyenforcer/10.2/administration/cpcusernotification.webp deleted file mode 100644 index c5e5a712ca..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/cpcusernotification.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_1.webp b/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_1.webp deleted file mode 100644 index afdabba05a..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_2.webp b/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_2.webp deleted file mode 100644 index c6626568eb..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_3.webp b/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_3.webp deleted file mode 100644 index 40d5d6fd41..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_4.webp b/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_4.webp deleted file mode 100644 index 665baa37b7..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_5.webp b/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_5.webp deleted file mode 100644 index 91d9c46152..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/customizing_message_templates_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_1.webp b/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_1.webp deleted file mode 100644 index c4edbd152c..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_2.webp b/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_2.webp deleted file mode 100644 index 9b302d96a4..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_3.webp b/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_3.webp deleted file mode 100644 index 3727f32df3..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_4.webp b/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_4.webp deleted file mode 100644 index 13ae58946e..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_5.webp b/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_5.webp deleted file mode 100644 index 5c38fb74ab..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/customizing_rule_inserts_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.webp b/static/images/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.webp deleted file mode 100644 index 31ce99de79..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/domain_and_local_policies.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/domain_and_local_policies_1.webp b/static/images/passwordpolicyenforcer/10.2/administration/domain_and_local_policies_1.webp deleted file mode 100644 index b1b82fd46d..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/domain_and_local_policies_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/editschedule.webp b/static/images/passwordpolicyenforcer/10.2/administration/editschedule.webp deleted file mode 100644 index 2145fc412d..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/editschedule.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/emailtab.webp b/static/images/passwordpolicyenforcer/10.2/administration/emailtab.webp deleted file mode 100644 index 1dd28c0818..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/emailtab.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/hibpfolder.webp b/static/images/passwordpolicyenforcer/10.2/administration/hibpfolder.webp deleted file mode 100644 index ca9d6ccc96..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/hibpfolder.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe.webp b/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe.webp deleted file mode 100644 index be8835f4b1..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_1.webp b/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_1.webp deleted file mode 100644 index 48254c3410..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_2.webp b/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_2.webp deleted file mode 100644 index 6b438abf55..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_4.webp b/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_4.webp deleted file mode 100644 index aa49160eac..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_7.webp b/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_7.webp deleted file mode 100644 index dbde8e984a..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/installing_ppe_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/keboardlayoutwindow.webp b/static/images/passwordpolicyenforcer/10.2/administration/keboardlayoutwindow.webp deleted file mode 100644 index 646de03445..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/keboardlayoutwindow.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/licensegenerator.webp b/static/images/passwordpolicyenforcer/10.2/administration/licensegenerator.webp deleted file mode 100644 index 7091bc22ae..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/licensegenerator.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/licensetab.webp b/static/images/passwordpolicyenforcer/10.2/administration/licensetab.webp deleted file mode 100644 index b511bd9a61..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/licensetab.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/livepolicymessageexample.webp b/static/images/passwordpolicyenforcer/10.2/administration/livepolicymessageexample.webp deleted file mode 100644 index a0f512a35b..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/livepolicymessageexample.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_1.webp b/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_1.webp deleted file mode 100644 index 263d671bac..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_12.webp b/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_12.webp deleted file mode 100644 index 84ba4f4b5c..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_12.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_3.webp b/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_3.webp deleted file mode 100644 index 662c9a6d45..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_4.webp b/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_4.webp deleted file mode 100644 index 165233ef73..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_5.webp b/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_5.webp deleted file mode 100644 index 793d84867e..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_6_363x434.webp b/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_6_363x434.webp deleted file mode 100644 index 33d39db213..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_6_363x434.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_7.webp b/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_7.webp deleted file mode 100644 index 5c37e33c09..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/passwordhashdatabase.webp b/static/images/passwordpolicyenforcer/10.2/administration/passwordhashdatabase.webp deleted file mode 100644 index 8fe907539b..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/passwordhashdatabase.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/passwordtest.webp b/static/images/passwordpolicyenforcer/10.2/administration/passwordtest.webp deleted file mode 100644 index 2fb604481b..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/passwordtest.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/policypropertieswindow.webp b/static/images/passwordpolicyenforcer/10.2/administration/policypropertieswindow.webp deleted file mode 100644 index c4f146e3cb..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/policypropertieswindow.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration.webp deleted file mode 100644 index 865dd46889..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration1.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration1.webp deleted file mode 100644 index 7d593617fa..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration2.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration2.webp deleted file mode 100644 index 31f5ca5f00..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration3.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration3.webp deleted file mode 100644 index 69dd5a8c6e..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration4.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration4.webp deleted file mode 100644 index da7e144c17..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration5.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration5.webp deleted file mode 100644 index 84b86a0732..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppc_configuration5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe1.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe1.webp deleted file mode 100644 index 85d6d660ef..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe2.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe2.webp deleted file mode 100644 index 068bc37273..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe7configurationimport.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe7configurationimport.webp deleted file mode 100644 index 1de1815620..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe7configurationimport.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules.webp deleted file mode 100644 index c3ef7bca56..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_10.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_10.webp deleted file mode 100644 index fd101b64de..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_10.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_11.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_11.webp deleted file mode 100644 index c0da9dc212..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_11.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_12.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_12.webp deleted file mode 100644 index 1d74ced85f..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_12.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_13.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_13.webp deleted file mode 100644 index 358e824ef3..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_13.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_14.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_14.webp deleted file mode 100644 index 9070fab92e..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_14.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_15.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_15.webp deleted file mode 100644 index cf90932182..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_15.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_16.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_16.webp deleted file mode 100644 index 603c2003dd..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_16.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_17.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_17.webp deleted file mode 100644 index 6af863efdf..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_17.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_19.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_19.webp deleted file mode 100644 index 4d5b421653..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_19.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_2.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_2.webp deleted file mode 100644 index 610b0c9ade..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_21.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_21.webp deleted file mode 100644 index 87edd702f0..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_21.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_22.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_22.webp deleted file mode 100644 index a0f6fe9081..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_22.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_3.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_3.webp deleted file mode 100644 index 39ad7653ab..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_4.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_4.webp deleted file mode 100644 index c787d10985..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_5.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_5.webp deleted file mode 100644 index 165130e5c4..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_6_337x406.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_6_337x406.webp deleted file mode 100644 index 98157f625f..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_6_337x406.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_7.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_7.webp deleted file mode 100644 index 3f35ff0f7b..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_8.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_8.webp deleted file mode 100644 index 127abd4489..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_8.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_9.webp b/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_9.webp deleted file mode 100644 index 2a51269f56..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/ppe_rules_9.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/schedulelist.webp b/static/images/passwordpolicyenforcer/10.2/administration/schedulelist.webp deleted file mode 100644 index 04dfe98f43..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/schedulelist.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindow.webp b/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindow.webp deleted file mode 100644 index d24b17e4e2..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindow.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerschedule.webp b/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerschedule.webp deleted file mode 100644 index 4334322c22..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerschedule.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerschedulemonthly.webp b/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerschedulemonthly.webp deleted file mode 100644 index 5ccbb17e81..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerschedulemonthly.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerscheduleweekly.webp b/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerscheduleweekly.webp deleted file mode 100644 index 2edd00b2be..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpasswordcheckerscheduleweekly.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpropertyeditor.webp b/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpropertyeditor.webp deleted file mode 100644 index e2f7546af4..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/supporttoolswindowpropertyeditor.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_2.webp b/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_2.webp deleted file mode 100644 index 1c101cddfa..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_4.webp b/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_4.webp deleted file mode 100644 index 3eef3238d6..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_5.webp b/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_5.webp deleted file mode 100644 index 54eef53845..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_6.webp b/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_6.webp deleted file mode 100644 index 80e43a9bca..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_6.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_7.webp b/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_7.webp deleted file mode 100644 index 913dcd94ea..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/the_ppe_mailer.webp b/static/images/passwordpolicyenforcer/10.2/administration/the_ppe_mailer.webp deleted file mode 100644 index 94a0f3b6c1..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/the_ppe_mailer.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/the_ppe_mailer_1.webp b/static/images/passwordpolicyenforcer/10.2/administration/the_ppe_mailer_1.webp deleted file mode 100644 index e9f36d31a6..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/the_ppe_mailer_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/vieweventlogs.webp b/static/images/passwordpolicyenforcer/10.2/administration/vieweventlogs.webp deleted file mode 100644 index 2dad177147..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/vieweventlogs.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/administration/vieweventlogslogproperties.webp b/static/images/passwordpolicyenforcer/10.2/administration/vieweventlogslogproperties.webp deleted file mode 100644 index 6e6ad49923..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/administration/vieweventlogslogproperties.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/conclusion_1.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/conclusion_1.webp deleted file mode 100644 index 41bb7ecbb1..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/conclusion_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/configuring_policy_rules.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/configuring_policy_rules.webp deleted file mode 100644 index acdbabf60f..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/configuring_policy_rules.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/creating_a_password_policy_2.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/creating_a_password_policy_2.webp deleted file mode 100644 index 7ec1f671dc..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/creating_a_password_policy_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies_1.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies_1.webp deleted file mode 100644 index 23c2305141..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies_2.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies_2.webp deleted file mode 100644 index f893916471..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/enforcing_multiple_policies_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/managing_policies.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/managing_policies.webp deleted file mode 100644 index e3e332bbb8..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/managing_policies.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/netwrix_password_reset_and_ppe_1105x808.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/netwrix_password_reset_and_ppe_1105x808.webp deleted file mode 100644 index 0452480b13..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/netwrix_password_reset_and_ppe_1105x808.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer.webp deleted file mode 100644 index 75375533a9..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer_1.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer_1.webp deleted file mode 100644 index 6df7c47791..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/preparing_the_computer_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy.webp deleted file mode 100644 index 7f00d82cdc..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_1.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_1.webp deleted file mode 100644 index 1a9611f79b..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_2.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_2.webp deleted file mode 100644 index a9b853b75e..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_3.webp b/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_3.webp deleted file mode 100644 index 95a74160b6..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/evaluation/testing_the_password_policy_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/configuring_ppe_web.webp b/static/images/passwordpolicyenforcer/10.2/web/configuring_ppe_web.webp deleted file mode 100644 index 49c98a5176..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/configuring_ppe_web.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/configuring_ppe_web_1.webp b/static/images/passwordpolicyenforcer/10.2/web/configuring_ppe_web_1.webp deleted file mode 100644 index f4fb11682c..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/configuring_ppe_web_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/editing_the_html_templates_1.webp b/static/images/passwordpolicyenforcer/10.2/web/editing_the_html_templates_1.webp deleted file mode 100644 index 82a199fdf5..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/editing_the_html_templates_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web.webp b/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web.webp deleted file mode 100644 index 0f694885c1..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_1.webp b/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_1.webp deleted file mode 100644 index 0bc0615ec1..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_2.webp b/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_2.webp deleted file mode 100644 index 3b2d941695..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_3.webp b/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_3.webp deleted file mode 100644 index 7f27e00677..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_4.webp b/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_4.webp deleted file mode 100644 index 9606b26f95..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_5.webp b/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_5.webp deleted file mode 100644 index 6842033d8d..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/installing_ppe_web_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/introduction_4.webp b/static/images/passwordpolicyenforcer/10.2/web/introduction_4.webp deleted file mode 100644 index 4226ae9e2a..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/introduction_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/using_ppe_web.webp b/static/images/passwordpolicyenforcer/10.2/web/using_ppe_web.webp deleted file mode 100644 index 359cd3f17d..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/using_ppe_web.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/using_ppe_web_1.webp b/static/images/passwordpolicyenforcer/10.2/web/using_ppe_web_1.webp deleted file mode 100644 index 9747dc8829..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/using_ppe_web_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/10.2/web/using_ppe_web_2.webp b/static/images/passwordpolicyenforcer/10.2/web/using_ppe_web_2.webp deleted file mode 100644 index d8cc4e92e9..0000000000 Binary files a/static/images/passwordpolicyenforcer/10.2/web/using_ppe_web_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/agemax.webp b/static/images/passwordpolicyenforcer/11.0/administration/agemax.webp deleted file mode 100644 index 4c2c6704aa..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/agemax.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/charcomplexity.webp b/static/images/passwordpolicyenforcer/11.0/administration/charcomplexity.webp deleted file mode 100644 index 160b13d0e8..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/charcomplexity.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict.webp b/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict.webp deleted file mode 100644 index 76001100d0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict2.webp b/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict2.webp deleted file mode 100644 index a5e17d4e24..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict3.webp b/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict3.webp deleted file mode 100644 index 8133221e52..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict4.webp b/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict4.webp deleted file mode 100644 index 25d57993aa..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/chargranularrestrict4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/compromisedpasswords.webp b/static/images/passwordpolicyenforcer/11.0/administration/compromisedpasswords.webp deleted file mode 100644 index eadcbee2fa..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/compromisedpasswords.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/connecttodomain.webp b/static/images/passwordpolicyenforcer/11.0/administration/connecttodomain.webp deleted file mode 100644 index 1c387b7499..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/connecttodomain.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/disable.webp b/static/images/passwordpolicyenforcer/11.0/administration/disable.webp deleted file mode 100644 index 681abfab11..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/disable.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/disabled.webp b/static/images/passwordpolicyenforcer/11.0/administration/disabled.webp deleted file mode 100644 index cb3428d8d9..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/disabled.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/managing_policies.webp b/static/images/passwordpolicyenforcer/11.0/administration/managing_policies.webp deleted file mode 100644 index 43d4b9261a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/managing_policies.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/mesages2.webp b/static/images/passwordpolicyenforcer/11.0/administration/mesages2.webp deleted file mode 100644 index 1377d8d6b1..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/mesages2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/messages.webp b/static/images/passwordpolicyenforcer/11.0/administration/messages.webp deleted file mode 100644 index 79bb2b2567..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/messages.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/messagesmacros.webp b/static/images/passwordpolicyenforcer/11.0/administration/messagesmacros.webp deleted file mode 100644 index 97e120fe85..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/messagesmacros.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/passphrase.webp b/static/images/passwordpolicyenforcer/11.0/administration/passphrase.webp deleted file mode 100644 index 30f1420b37..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/passphrase.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration4.webp b/static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration4.webp deleted file mode 100644 index afe2ee0587..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration5.webp b/static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration5.webp deleted file mode 100644 index c90a500ac5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/ppe_rules_8.webp b/static/images/passwordpolicyenforcer/11.0/administration/ppe_rules_8.webp deleted file mode 100644 index 1b21ece800..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/ppe_rules_8.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/settingsgeneral.webp b/static/images/passwordpolicyenforcer/11.0/administration/settingsgeneral.webp deleted file mode 100644 index f02bffdebf..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/settingsgeneral.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/settingslicense.webp b/static/images/passwordpolicyenforcer/11.0/administration/settingslicense.webp deleted file mode 100644 index 8b402a00e4..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/settingslicense.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/settingsnotifications.webp b/static/images/passwordpolicyenforcer/11.0/administration/settingsnotifications.webp deleted file mode 100644 index 55d1fd9f16..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/settingsnotifications.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/testviewlog.webp b/static/images/passwordpolicyenforcer/11.0/administration/testviewlog.webp deleted file mode 100644 index e13a2720d8..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/testviewlog.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client.webp b/static/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client.webp deleted file mode 100644 index 65b7f38112..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client_1.webp b/static/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client_1.webp deleted file mode 100644 index 9966d06034..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client_3.webp b/static/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client_3.webp deleted file mode 100644 index c97165b643..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/the_password_policy_client_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/vieweventlogs.webp b/static/images/passwordpolicyenforcer/11.0/administration/vieweventlogs.webp deleted file mode 100644 index 8f95050d7f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/vieweventlogs.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/administration/vieweventlogslogproperties.webp b/static/images/passwordpolicyenforcer/11.0/administration/vieweventlogslogproperties.webp deleted file mode 100644 index c4d071407c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/administration/vieweventlogslogproperties.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/introduction_3.webp b/static/images/passwordpolicyenforcer/11.0/evaluation/introduction_3.webp deleted file mode 100644 index 21611fe210..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/evaluation/introduction_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/clientsetup1.webp b/static/images/passwordpolicyenforcer/11.0/install/clientsetup1.webp deleted file mode 100644 index 8dcfb29685..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/clientsetup1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/clientsetup2.webp b/static/images/passwordpolicyenforcer/11.0/install/clientsetup2.webp deleted file mode 100644 index 33663e151a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/clientsetup2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/clientsetup3.webp b/static/images/passwordpolicyenforcer/11.0/install/clientsetup3.webp deleted file mode 100644 index e61bc1e356..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/clientsetup3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/clientsetup4.webp b/static/images/passwordpolicyenforcer/11.0/install/clientsetup4.webp deleted file mode 100644 index 8a08e63fa1..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/clientsetup4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/serversetup1.webp b/static/images/passwordpolicyenforcer/11.0/install/serversetup1.webp deleted file mode 100644 index b76dc7ecff..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/serversetup1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/serversetup2.webp b/static/images/passwordpolicyenforcer/11.0/install/serversetup2.webp deleted file mode 100644 index 584cfabd24..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/serversetup2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/serversetup3.webp b/static/images/passwordpolicyenforcer/11.0/install/serversetup3.webp deleted file mode 100644 index 488d4f970b..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/serversetup3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/serversetup4.webp b/static/images/passwordpolicyenforcer/11.0/install/serversetup4.webp deleted file mode 100644 index 02c8cef904..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/serversetup4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/serversetup5.webp b/static/images/passwordpolicyenforcer/11.0/install/serversetup5.webp deleted file mode 100644 index 972ec0e940..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/serversetup5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_3.webp b/static/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_3.webp deleted file mode 100644 index 0a9f8b7fce..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_4.webp b/static/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_4.webp deleted file mode 100644 index 688a5338f5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_5.webp b/static/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_5.webp deleted file mode 100644 index c9c02b4ac0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.0/install/the_password_policy_client_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/agemax.webp b/static/images/passwordpolicyenforcer/11.1/administration/agemax.webp deleted file mode 100644 index 4c2c6704aa..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/agemax.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/agemin.webp b/static/images/passwordpolicyenforcer/11.1/administration/agemin.webp deleted file mode 100644 index e737f50a78..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/agemin.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/charcomplexity.webp b/static/images/passwordpolicyenforcer/11.1/administration/charcomplexity.webp deleted file mode 100644 index 160b13d0e8..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/charcomplexity.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/chargranular.webp b/static/images/passwordpolicyenforcer/11.1/administration/chargranular.webp deleted file mode 100644 index b78127ec48..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/chargranular.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict.webp b/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict.webp deleted file mode 100644 index 76001100d0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict2.webp b/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict2.webp deleted file mode 100644 index a5e17d4e24..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict3.webp b/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict3.webp deleted file mode 100644 index 8133221e52..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict4.webp b/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict4.webp deleted file mode 100644 index 25d57993aa..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/chargranularrestrict4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/chargranularvowel.webp b/static/images/passwordpolicyenforcer/11.1/administration/chargranularvowel.webp deleted file mode 100644 index f9ee5e5ba0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/chargranularvowel.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/cmdletconnect.webp b/static/images/passwordpolicyenforcer/11.1/administration/cmdletconnect.webp deleted file mode 100644 index 41d1a17914..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/cmdletconnect.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/cmdletgetppebulkpasswordtest.webp b/static/images/passwordpolicyenforcer/11.1/administration/cmdletgetppebulkpasswordtest.webp deleted file mode 100644 index f20e18afe4..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/cmdletgetppebulkpasswordtest.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/cmdletgetppeconfigreport.webp b/static/images/passwordpolicyenforcer/11.1/administration/cmdletgetppeconfigreport.webp deleted file mode 100644 index 6edda3963d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/cmdletgetppeconfigreport.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/cmdletstartppehibpupdater.webp b/static/images/passwordpolicyenforcer/11.1/administration/cmdletstartppehibpupdater.webp deleted file mode 100644 index aa449ec8ce..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/cmdletstartppehibpupdater.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/compromised.webp b/static/images/passwordpolicyenforcer/11.1/administration/compromised.webp deleted file mode 100644 index 1e1c862fd6..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/compromised.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/compromisedpasswordsschedule.webp b/static/images/passwordpolicyenforcer/11.1/administration/compromisedpasswordsschedule.webp deleted file mode 100644 index b52637bd9a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/compromisedpasswordsschedule.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/connecttodomain.webp b/static/images/passwordpolicyenforcer/11.1/administration/connecttodomain.webp deleted file mode 100644 index 1c387b7499..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/connecttodomain.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/connecttolocal.webp b/static/images/passwordpolicyenforcer/11.1/administration/connecttolocal.webp deleted file mode 100644 index a2be10578d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/connecttolocal.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/dictionary.webp b/static/images/passwordpolicyenforcer/11.1/administration/dictionary.webp deleted file mode 100644 index b616feb3bf..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/dictionary.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/disable.webp b/static/images/passwordpolicyenforcer/11.1/administration/disable.webp deleted file mode 100644 index 681abfab11..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/disable.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/disabled.webp b/static/images/passwordpolicyenforcer/11.1/administration/disabled.webp deleted file mode 100644 index cb3428d8d9..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/disabled.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/domain_and_local_policies.webp b/static/images/passwordpolicyenforcer/11.1/administration/domain_and_local_policies.webp deleted file mode 100644 index 1af12832a8..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/domain_and_local_policies.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/domain_and_local_policies_1.webp b/static/images/passwordpolicyenforcer/11.1/administration/domain_and_local_policies_1.webp deleted file mode 100644 index 140ffa98db..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/domain_and_local_policies_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/editschedule.webp b/static/images/passwordpolicyenforcer/11.1/administration/editschedule.webp deleted file mode 100644 index d03b989904..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/editschedule.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/emailusernotification.webp b/static/images/passwordpolicyenforcer/11.1/administration/emailusernotification.webp deleted file mode 100644 index 0cd7bdcf15..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/emailusernotification.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/enabledisableppeconsole.webp b/static/images/passwordpolicyenforcer/11.1/administration/enabledisableppeconsole.webp deleted file mode 100644 index 37de10d442..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/enabledisableppeconsole.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/enabledrules.webp b/static/images/passwordpolicyenforcer/11.1/administration/enabledrules.webp deleted file mode 100644 index 59e0d7acd5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/enabledrules.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/hibpfolder.webp b/static/images/passwordpolicyenforcer/11.1/administration/hibpfolder.webp deleted file mode 100644 index 8bb56ba37d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/hibpfolder.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/hibpupdater.webp b/static/images/passwordpolicyenforcer/11.1/administration/hibpupdater.webp deleted file mode 100644 index 5dcfcd6b23..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/hibpupdater.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/history.webp b/static/images/passwordpolicyenforcer/11.1/administration/history.webp deleted file mode 100644 index b1b8326e4c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/history.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/length.webp b/static/images/passwordpolicyenforcer/11.1/administration/length.webp deleted file mode 100644 index 6a24c0c0ae..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/length.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/managing_policies.webp b/static/images/passwordpolicyenforcer/11.1/administration/managing_policies.webp deleted file mode 100644 index 43d4b9261a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/managing_policies.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/managing_policies_3.webp b/static/images/passwordpolicyenforcer/11.1/administration/managing_policies_3.webp deleted file mode 100644 index 66e6432a57..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/managing_policies_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/messages.webp b/static/images/passwordpolicyenforcer/11.1/administration/messages.webp deleted file mode 100644 index 79bb2b2567..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/messages.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/messagesmacros.webp b/static/images/passwordpolicyenforcer/11.1/administration/messagesmacros.webp deleted file mode 100644 index 97e120fe85..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/messagesmacros.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/passphrase.webp b/static/images/passwordpolicyenforcer/11.1/administration/passphrase.webp deleted file mode 100644 index 30f1420b37..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/passphrase.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/patterns.webp b/static/images/passwordpolicyenforcer/11.1/administration/patterns.webp deleted file mode 100644 index 6c0f3caf60..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/patterns.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/policypriority.webp b/static/images/passwordpolicyenforcer/11.1/administration/policypriority.webp deleted file mode 100644 index f08f43a067..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/policypriority.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration.webp b/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration.webp deleted file mode 100644 index ac4789b81d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration1.webp b/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration1.webp deleted file mode 100644 index fc0591436e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration2.webp b/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration2.webp deleted file mode 100644 index 02839c99ed..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration3.webp b/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration3.webp deleted file mode 100644 index e4a3ec6c31..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/ppe1.webp b/static/images/passwordpolicyenforcer/11.1/administration/ppe1.webp deleted file mode 100644 index a33dab12b2..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/ppe1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/ppe_rules_8.webp b/static/images/passwordpolicyenforcer/11.1/administration/ppe_rules_8.webp deleted file mode 100644 index 1b21ece800..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/ppe_rules_8.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/ppedashboardpolicies.webp b/static/images/passwordpolicyenforcer/11.1/administration/ppedashboardpolicies.webp deleted file mode 100644 index 88f4de2cc5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/ppedashboardpolicies.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/properties.webp b/static/images/passwordpolicyenforcer/11.1/administration/properties.webp deleted file mode 100644 index 5e64dc7624..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/properties.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/propertyeditor.webp b/static/images/passwordpolicyenforcer/11.1/administration/propertyeditor.webp deleted file mode 100644 index ab2f8ef765..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/propertyeditor.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/repetition.webp b/static/images/passwordpolicyenforcer/11.1/administration/repetition.webp deleted file mode 100644 index 455e4fdbda..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/repetition.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/schedulelist.webp b/static/images/passwordpolicyenforcer/11.1/administration/schedulelist.webp deleted file mode 100644 index c44c1b3278..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/schedulelist.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications2.webp b/static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications2.webp deleted file mode 100644 index 19ba5a2875..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications3.webp b/static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications3.webp deleted file mode 100644 index 181c40d170..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications4.webp b/static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications4.webp deleted file mode 100644 index ade4b3e2cd..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/similarity.webp b/static/images/passwordpolicyenforcer/11.1/administration/similarity.webp deleted file mode 100644 index 82530f37de..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/similarity.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/systemaudit.webp b/static/images/passwordpolicyenforcer/11.1/administration/systemaudit.webp deleted file mode 100644 index 247d9594ce..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/systemaudit.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/systemaudittools.webp b/static/images/passwordpolicyenforcer/11.1/administration/systemaudittools.webp deleted file mode 100644 index 9effa4a369..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/systemaudittools.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/systemauditversion.webp b/static/images/passwordpolicyenforcer/11.1/administration/systemauditversion.webp deleted file mode 100644 index fb4ebe06ce..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/systemauditversion.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/testbulk.webp b/static/images/passwordpolicyenforcer/11.1/administration/testbulk.webp deleted file mode 100644 index 7d5654c61e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/testbulk.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/testbulkreport.webp b/static/images/passwordpolicyenforcer/11.1/administration/testbulkreport.webp deleted file mode 100644 index 6cff411a48..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/testbulkreport.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/testbulkresult.webp b/static/images/passwordpolicyenforcer/11.1/administration/testbulkresult.webp deleted file mode 100644 index 9962e0c021..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/testbulkresult.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/testuser.webp b/static/images/passwordpolicyenforcer/11.1/administration/testuser.webp deleted file mode 100644 index 6b087ab24a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/testuser.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/testuserfail.webp b/static/images/passwordpolicyenforcer/11.1/administration/testuserfail.webp deleted file mode 100644 index 1680753c30..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/testuserfail.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/testuserpass.webp b/static/images/passwordpolicyenforcer/11.1/administration/testuserpass.webp deleted file mode 100644 index 7eda782066..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/testuserpass.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/testuserverbose.webp b/static/images/passwordpolicyenforcer/11.1/administration/testuserverbose.webp deleted file mode 100644 index 52ef8c1e96..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/testuserverbose.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/testviewlog.webp b/static/images/passwordpolicyenforcer/11.1/administration/testviewlog.webp deleted file mode 100644 index e13a2720d8..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/testviewlog.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client.webp b/static/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client.webp deleted file mode 100644 index 65b7f38112..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client_1.webp b/static/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client_1.webp deleted file mode 100644 index 9966d06034..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client_3.webp b/static/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client_3.webp deleted file mode 100644 index c97165b643..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/the_password_policy_client_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/unique.webp b/static/images/passwordpolicyenforcer/11.1/administration/unique.webp deleted file mode 100644 index 916efa6469..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/unique.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/usersandgroups.webp b/static/images/passwordpolicyenforcer/11.1/administration/usersandgroups.webp deleted file mode 100644 index 7b48f5f5eb..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/usersandgroups.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/usersandgroups2.webp b/static/images/passwordpolicyenforcer/11.1/administration/usersandgroups2.webp deleted file mode 100644 index ec9a459f0a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/usersandgroups2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/vieweventlogs.webp b/static/images/passwordpolicyenforcer/11.1/administration/vieweventlogs.webp deleted file mode 100644 index 8f95050d7f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/vieweventlogs.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/administration/vieweventlogslogproperties.webp b/static/images/passwordpolicyenforcer/11.1/administration/vieweventlogslogproperties.webp deleted file mode 100644 index c4d071407c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/administration/vieweventlogslogproperties.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evaladmin.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evaladmin.webp deleted file mode 100644 index 4af0a1a56c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evaladmin.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evalchars.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evalchars.webp deleted file mode 100644 index 49b7a98d0e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evalchars.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evalcharsgran.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evalcharsgran.webp deleted file mode 100644 index 7609a8e637..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evalcharsgran.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evalcopypolicy2.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evalcopypolicy2.webp deleted file mode 100644 index a97cbade5e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evalcopypolicy2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evaldashboard.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evaldashboard.webp deleted file mode 100644 index e82d849df1..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evaldashboard.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evaldefault.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evaldefault.webp deleted file mode 100644 index 1d013ba75d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evaldefault.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evaldict.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evaldict.webp deleted file mode 100644 index bdf1034791..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evaldict.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evaldomainadmins.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evaldomainadmins.webp deleted file mode 100644 index e5de0a43c2..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evaldomainadmins.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evallength.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evallength.webp deleted file mode 100644 index ffb226ac2c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evallength.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evallength9.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evallength9.webp deleted file mode 100644 index 7abd5d9aa2..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evallength9.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evalsimilarity.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evalsimilarity.webp deleted file mode 100644 index 82528c85d3..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evalsimilarity.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evaltestuser.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evaltestuser.webp deleted file mode 100644 index d5651df3bf..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evaltestuser.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evaltestuserfail.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evaltestuserfail.webp deleted file mode 100644 index 568bd0c594..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evaltestuserfail.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/evalusergroups.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/evalusergroups.webp deleted file mode 100644 index 37b5c512eb..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/evalusergroups.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/introduction_3.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/introduction_3.webp deleted file mode 100644 index 21611fe210..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/introduction_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/newpolicysettings.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/newpolicysettings.webp deleted file mode 100644 index c5530da377..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/newpolicysettings.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/ppedashboard.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/ppedashboard.webp deleted file mode 100644 index 87b7f03aac..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/ppedashboard.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer.webp deleted file mode 100644 index 9b72e9ea10..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer_1.webp b/static/images/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer_1.webp deleted file mode 100644 index 4c426892e0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/evaluation/preparing_the_computer_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/install/gpm1.webp b/static/images/passwordpolicyenforcer/11.1/install/gpm1.webp deleted file mode 100644 index d8a96a6d03..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/install/gpm1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/install/gpm2.webp b/static/images/passwordpolicyenforcer/11.1/install/gpm2.webp deleted file mode 100644 index 2a0f3b8fd0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/install/gpm2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/install/installing_ppe_2.webp b/static/images/passwordpolicyenforcer/11.1/install/installing_ppe_2.webp deleted file mode 100644 index 6ef6db21ca..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/install/installing_ppe_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_3.webp b/static/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_3.webp deleted file mode 100644 index 0a9f8b7fce..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_4.webp b/static/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_4.webp deleted file mode 100644 index 688a5338f5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_5.webp b/static/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_5.webp deleted file mode 100644 index c9c02b4ac0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/install/the_password_policy_client_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr.webp deleted file mode 100644 index 66592471d0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_0.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_0.webp deleted file mode 100644 index a94bdaeab1..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_0.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_1.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_1.webp deleted file mode 100644 index 6ca0f46a48..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_10.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_10.webp deleted file mode 100644 index f7e6accce0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_10.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_2.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_2.webp deleted file mode 100644 index 24a6a69be5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_3_709x772.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_3_709x772.webp deleted file mode 100644 index f0c5c09c7c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_3_709x772.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_4.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_4.webp deleted file mode 100644 index 590339e5ac..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_5.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_5.webp deleted file mode 100644 index e7f3acc03f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_6.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_6.webp deleted file mode 100644 index 0e9a72c722..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_6.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_7.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_7.webp deleted file mode 100644 index 1d1812ec33..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_8.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_8.webp deleted file mode 100644 index 764546b0e3..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_8.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_9.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_9.webp deleted file mode 100644 index 51082b59d8..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/configuring_npr_9.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/installing_npr_1.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/installing_npr_1.webp deleted file mode 100644 index c753368e8c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/installing_npr_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/installing_npr_624x193.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/installing_npr_624x193.webp deleted file mode 100644 index 37e76fcc1c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/installing_npr_624x193.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/persuading_users_to_enroll.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/persuading_users_to_enroll.webp deleted file mode 100644 index cedcffc37b..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/persuading_users_to_enroll.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_1_895x652.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_1_895x652.webp deleted file mode 100644 index 6d81b3e2f6..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_1_895x652.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_2.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_2.webp deleted file mode 100644 index 85e205b911..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_3.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_3.webp deleted file mode 100644 index e700ba7976..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_4.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_4.webp deleted file mode 100644 index 6f0c3f24bd..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_5.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_5.webp deleted file mode 100644 index 9e63c4e63f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_905x750.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_905x750.webp deleted file mode 100644 index 338d4dba9f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/the_password_reset_client_905x750.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_0_765x963.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_0_765x963.webp deleted file mode 100644 index 79ab24e742..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_0_765x963.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_10_771x440.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_10_771x440.webp deleted file mode 100644 index c12f7b3c85..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_10_771x440.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_11_773x593.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_11_773x593.webp deleted file mode 100644 index fb6acc5604..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_11_773x593.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_12.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_12.webp deleted file mode 100644 index 511c6f17f6..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_12.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_13.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_13.webp deleted file mode 100644 index 913a93af9b..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_13.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_1_824x469.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_1_824x469.webp deleted file mode 100644 index 83a29189bd..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_1_824x469.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_2_809x640.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_2_809x640.webp deleted file mode 100644 index a209f92167..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_2_809x640.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_3.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_3.webp deleted file mode 100644 index 514bd0dba9..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_4_842x816.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_4_842x816.webp deleted file mode 100644 index c30249f740..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_4_842x816.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_5.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_5.webp deleted file mode 100644 index 5f951d58f4..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_6.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_6.webp deleted file mode 100644 index fa7778ba85..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_6.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_7.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_7.webp deleted file mode 100644 index 54c1e6b528..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_8.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_8.webp deleted file mode 100644 index 5188cce1a7..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_8.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_866x634.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_866x634.webp deleted file mode 100644 index 3e7d337f75..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_866x634.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_9.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_9.webp deleted file mode 100644 index 3475c7b8a4..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_9.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_9_789x276.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_9_789x276.webp deleted file mode 100644 index 4cda2e3d74..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_npr_9_789x276.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_ppe_with_npr.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_ppe_with_npr.webp deleted file mode 100644 index dbf7bcac05..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_ppe_with_npr.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console.webp deleted file mode 100644 index 594c25880a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_10.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_10.webp deleted file mode 100644 index 4f8f574d7f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_10.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_11.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_11.webp deleted file mode 100644 index aeb6bbdfc4..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_11.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_12.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_12.webp deleted file mode 100644 index 96c6a9620c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_12.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_13.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_13.webp deleted file mode 100644 index 10b703fdc3..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_13.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_1_1393x772.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_1_1393x772.webp deleted file mode 100644 index 2934a1e86d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_1_1393x772.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_2_1317x725.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_2_1317x725.webp deleted file mode 100644 index 41fee0ff30..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_2_1317x725.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_3.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_3.webp deleted file mode 100644 index 65ea7ade3a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_4.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_4.webp deleted file mode 100644 index 9a793cca1f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_5.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_5.webp deleted file mode 100644 index cbbc18d5c2..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_6.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_6.webp deleted file mode 100644 index 5255843ffa..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_6.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_7.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_7.webp deleted file mode 100644 index fcc5beba5d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_8.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_8.webp deleted file mode 100644 index 09dc99a135..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_8.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_9.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_9.webp deleted file mode 100644 index 82dc5c5fe5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/using_the_data_console_9.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/working_with_the_database.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/working_with_the_database.webp deleted file mode 100644 index adac686f03..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/working_with_the_database.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/working_with_the_database_1.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/working_with_the_database_1.webp deleted file mode 100644 index 94139764f1..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/administration/working_with_the_database_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/passwordreset/evaluation/introduction_1_1.webp b/static/images/passwordpolicyenforcer/11.1/passwordreset/evaluation/introduction_1_1.webp deleted file mode 100644 index 514bd0dba9..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/passwordreset/evaluation/introduction_1_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/web/configuring_ppe_web.webp b/static/images/passwordpolicyenforcer/11.1/web/configuring_ppe_web.webp deleted file mode 100644 index 4a41202633..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/web/configuring_ppe_web.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/web/configuring_ppe_web_1.webp b/static/images/passwordpolicyenforcer/11.1/web/configuring_ppe_web_1.webp deleted file mode 100644 index 7d4a4c8fb7..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/web/configuring_ppe_web_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/web/editing_the_html_templates_1.webp b/static/images/passwordpolicyenforcer/11.1/web/editing_the_html_templates_1.webp deleted file mode 100644 index 797e4b93e2..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/web/editing_the_html_templates_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/web/introduction_4.webp b/static/images/passwordpolicyenforcer/11.1/web/introduction_4.webp deleted file mode 100644 index 47c5c80ac8..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/web/introduction_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/web/using_ppe_web.webp b/static/images/passwordpolicyenforcer/11.1/web/using_ppe_web.webp deleted file mode 100644 index fa7f3e1000..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/web/using_ppe_web.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/web/using_ppe_web_1.webp b/static/images/passwordpolicyenforcer/11.1/web/using_ppe_web_1.webp deleted file mode 100644 index dd1f253e45..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/web/using_ppe_web_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/web/using_ppe_web_2.webp b/static/images/passwordpolicyenforcer/11.1/web/using_ppe_web_2.webp deleted file mode 100644 index 2c269adb73..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/web/using_ppe_web_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.1/web/webwelcome.webp b/static/images/passwordpolicyenforcer/11.1/web/webwelcome.webp deleted file mode 100644 index 51efb6513e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.1/web/webwelcome.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/agemin.webp b/static/images/passwordpolicyenforcer/11.2/administration/agemin.webp deleted file mode 100644 index e737f50a78..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/agemin.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/chargranular.webp b/static/images/passwordpolicyenforcer/11.2/administration/chargranular.webp deleted file mode 100644 index b78127ec48..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/chargranular.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/chargranularvowel.webp b/static/images/passwordpolicyenforcer/11.2/administration/chargranularvowel.webp deleted file mode 100644 index f9ee5e5ba0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/chargranularvowel.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/cmdletconnect.webp b/static/images/passwordpolicyenforcer/11.2/administration/cmdletconnect.webp deleted file mode 100644 index 41d1a17914..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/cmdletconnect.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/cmdletgetppebulkpasswordtest.webp b/static/images/passwordpolicyenforcer/11.2/administration/cmdletgetppebulkpasswordtest.webp deleted file mode 100644 index f20e18afe4..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/cmdletgetppebulkpasswordtest.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/cmdletgetppeconfigreport.webp b/static/images/passwordpolicyenforcer/11.2/administration/cmdletgetppeconfigreport.webp deleted file mode 100644 index 6edda3963d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/cmdletgetppeconfigreport.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/cmdletstartppehibpupdater.webp b/static/images/passwordpolicyenforcer/11.2/administration/cmdletstartppehibpupdater.webp deleted file mode 100644 index aa449ec8ce..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/cmdletstartppehibpupdater.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/compromised.webp b/static/images/passwordpolicyenforcer/11.2/administration/compromised.webp deleted file mode 100644 index 1e1c862fd6..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/compromised.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/compromisedpasswords.webp b/static/images/passwordpolicyenforcer/11.2/administration/compromisedpasswords.webp deleted file mode 100644 index 0152ff8686..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/compromisedpasswords.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/compromisedpasswordsschedule.webp b/static/images/passwordpolicyenforcer/11.2/administration/compromisedpasswordsschedule.webp deleted file mode 100644 index b52637bd9a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/compromisedpasswordsschedule.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/dictionary.webp b/static/images/passwordpolicyenforcer/11.2/administration/dictionary.webp deleted file mode 100644 index b616feb3bf..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/dictionary.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/domain_and_local_policies.webp b/static/images/passwordpolicyenforcer/11.2/administration/domain_and_local_policies.webp deleted file mode 100644 index 1af12832a8..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/domain_and_local_policies.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/domain_and_local_policies_1.webp b/static/images/passwordpolicyenforcer/11.2/administration/domain_and_local_policies_1.webp deleted file mode 100644 index 140ffa98db..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/domain_and_local_policies_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/editschedule.webp b/static/images/passwordpolicyenforcer/11.2/administration/editschedule.webp deleted file mode 100644 index d03b989904..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/editschedule.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/emailusernotification.webp b/static/images/passwordpolicyenforcer/11.2/administration/emailusernotification.webp deleted file mode 100644 index 0cd7bdcf15..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/emailusernotification.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/enabledisableppeconsole.webp b/static/images/passwordpolicyenforcer/11.2/administration/enabledisableppeconsole.webp deleted file mode 100644 index 37de10d442..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/enabledisableppeconsole.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/enabledrules.webp b/static/images/passwordpolicyenforcer/11.2/administration/enabledrules.webp deleted file mode 100644 index 59e0d7acd5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/enabledrules.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/hibpfolder.webp b/static/images/passwordpolicyenforcer/11.2/administration/hibpfolder.webp deleted file mode 100644 index 8bb56ba37d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/hibpfolder.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/hibpupdater.webp b/static/images/passwordpolicyenforcer/11.2/administration/hibpupdater.webp deleted file mode 100644 index 5dcfcd6b23..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/hibpupdater.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/history.webp b/static/images/passwordpolicyenforcer/11.2/administration/history.webp deleted file mode 100644 index b1b8326e4c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/history.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/length.webp b/static/images/passwordpolicyenforcer/11.2/administration/length.webp deleted file mode 100644 index 6a24c0c0ae..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/length.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/managing_policies.webp b/static/images/passwordpolicyenforcer/11.2/administration/managing_policies.webp deleted file mode 100644 index 43d4b9261a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/managing_policies.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/managing_policies_3.webp b/static/images/passwordpolicyenforcer/11.2/administration/managing_policies_3.webp deleted file mode 100644 index 66e6432a57..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/managing_policies_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/mesages2.webp b/static/images/passwordpolicyenforcer/11.2/administration/mesages2.webp deleted file mode 100644 index 9702fd4416..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/mesages2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/patterns.webp b/static/images/passwordpolicyenforcer/11.2/administration/patterns.webp deleted file mode 100644 index 6c0f3caf60..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/patterns.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/policypriority.webp b/static/images/passwordpolicyenforcer/11.2/administration/policypriority.webp deleted file mode 100644 index f08f43a067..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/policypriority.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration.webp b/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration.webp deleted file mode 100644 index ac4789b81d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration1.webp b/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration1.webp deleted file mode 100644 index fc0591436e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration2.webp b/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration2.webp deleted file mode 100644 index 02839c99ed..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration3.webp b/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration3.webp deleted file mode 100644 index e4a3ec6c31..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration4.webp b/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration4.webp deleted file mode 100644 index 51cfce3bd0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration5.webp b/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration5.webp deleted file mode 100644 index 273c0f1b96..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/ppc_configuration5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/ppe1.webp b/static/images/passwordpolicyenforcer/11.2/administration/ppe1.webp deleted file mode 100644 index a33dab12b2..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/ppe1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/ppedashboardpolicies.webp b/static/images/passwordpolicyenforcer/11.2/administration/ppedashboardpolicies.webp deleted file mode 100644 index 88f4de2cc5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/ppedashboardpolicies.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/properties.webp b/static/images/passwordpolicyenforcer/11.2/administration/properties.webp deleted file mode 100644 index 5e64dc7624..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/properties.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/propertyeditor.webp b/static/images/passwordpolicyenforcer/11.2/administration/propertyeditor.webp deleted file mode 100644 index ab2f8ef765..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/propertyeditor.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/repetition.webp b/static/images/passwordpolicyenforcer/11.2/administration/repetition.webp deleted file mode 100644 index 455e4fdbda..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/repetition.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/schedulelist.webp b/static/images/passwordpolicyenforcer/11.2/administration/schedulelist.webp deleted file mode 100644 index c44c1b3278..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/schedulelist.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/settingsgeneral.webp b/static/images/passwordpolicyenforcer/11.2/administration/settingsgeneral.webp deleted file mode 100644 index 024e24c338..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/settingsgeneral.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/settingslicense.webp b/static/images/passwordpolicyenforcer/11.2/administration/settingslicense.webp deleted file mode 100644 index 44eafebd8e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/settingslicense.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/settingsmailserver.webp b/static/images/passwordpolicyenforcer/11.2/administration/settingsmailserver.webp deleted file mode 100644 index 1b0e1c3dfb..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/settingsmailserver.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/settingsnotifications.webp b/static/images/passwordpolicyenforcer/11.2/administration/settingsnotifications.webp deleted file mode 100644 index 9544712bd7..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/settingsnotifications.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/similarity.webp b/static/images/passwordpolicyenforcer/11.2/administration/similarity.webp deleted file mode 100644 index 82530f37de..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/similarity.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/systemaudit.webp b/static/images/passwordpolicyenforcer/11.2/administration/systemaudit.webp deleted file mode 100644 index 247d9594ce..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/systemaudit.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/systemaudittools.webp b/static/images/passwordpolicyenforcer/11.2/administration/systemaudittools.webp deleted file mode 100644 index 9effa4a369..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/systemaudittools.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/systemauditversion.webp b/static/images/passwordpolicyenforcer/11.2/administration/systemauditversion.webp deleted file mode 100644 index fb4ebe06ce..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/systemauditversion.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/testbulk.webp b/static/images/passwordpolicyenforcer/11.2/administration/testbulk.webp deleted file mode 100644 index 7d5654c61e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/testbulk.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/testbulkreport.webp b/static/images/passwordpolicyenforcer/11.2/administration/testbulkreport.webp deleted file mode 100644 index 6cff411a48..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/testbulkreport.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/testbulkresult.webp b/static/images/passwordpolicyenforcer/11.2/administration/testbulkresult.webp deleted file mode 100644 index 9962e0c021..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/testbulkresult.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/testuser.webp b/static/images/passwordpolicyenforcer/11.2/administration/testuser.webp deleted file mode 100644 index 6b087ab24a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/testuser.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/testuserfail.webp b/static/images/passwordpolicyenforcer/11.2/administration/testuserfail.webp deleted file mode 100644 index 1680753c30..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/testuserfail.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/testuserpass.webp b/static/images/passwordpolicyenforcer/11.2/administration/testuserpass.webp deleted file mode 100644 index 7eda782066..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/testuserpass.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/testuserverbose.webp b/static/images/passwordpolicyenforcer/11.2/administration/testuserverbose.webp deleted file mode 100644 index 52ef8c1e96..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/testuserverbose.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client.webp b/static/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client.webp deleted file mode 100644 index 65b7f38112..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client_1.webp b/static/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client_1.webp deleted file mode 100644 index 9966d06034..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client_3.webp b/static/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client_3.webp deleted file mode 100644 index c97165b643..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/the_password_policy_client_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/unique.webp b/static/images/passwordpolicyenforcer/11.2/administration/unique.webp deleted file mode 100644 index 916efa6469..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/unique.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/usersandgroups.webp b/static/images/passwordpolicyenforcer/11.2/administration/usersandgroups.webp deleted file mode 100644 index 7b48f5f5eb..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/usersandgroups.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/usersandgroups2.webp b/static/images/passwordpolicyenforcer/11.2/administration/usersandgroups2.webp deleted file mode 100644 index ec9a459f0a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/administration/usersandgroups2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evaladmin.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evaladmin.webp deleted file mode 100644 index 4af0a1a56c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evaladmin.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evalchars.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evalchars.webp deleted file mode 100644 index 49b7a98d0e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evalchars.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evalcharsgran.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evalcharsgran.webp deleted file mode 100644 index 7609a8e637..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evalcharsgran.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evalcopypolicy2.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evalcopypolicy2.webp deleted file mode 100644 index a97cbade5e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evalcopypolicy2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evaldashboard.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evaldashboard.webp deleted file mode 100644 index e82d849df1..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evaldashboard.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evaldefault.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evaldefault.webp deleted file mode 100644 index 1d013ba75d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evaldefault.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evaldict.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evaldict.webp deleted file mode 100644 index bdf1034791..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evaldict.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evaldomainadmins.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evaldomainadmins.webp deleted file mode 100644 index e5de0a43c2..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evaldomainadmins.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evallength.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evallength.webp deleted file mode 100644 index ffb226ac2c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evallength.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evallength9.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evallength9.webp deleted file mode 100644 index 7abd5d9aa2..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evallength9.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evalsimilarity.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evalsimilarity.webp deleted file mode 100644 index 82528c85d3..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evalsimilarity.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evaltestuser.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evaltestuser.webp deleted file mode 100644 index d5651df3bf..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evaltestuser.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evaltestuserfail.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evaltestuserfail.webp deleted file mode 100644 index 568bd0c594..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evaltestuserfail.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/evalusergroups.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/evalusergroups.webp deleted file mode 100644 index 37b5c512eb..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/evalusergroups.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/introduction_3.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/introduction_3.webp deleted file mode 100644 index 21611fe210..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/introduction_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/newpolicysettings.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/newpolicysettings.webp deleted file mode 100644 index c5530da377..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/newpolicysettings.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/ppedashboard.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/ppedashboard.webp deleted file mode 100644 index 87b7f03aac..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/ppedashboard.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer.webp deleted file mode 100644 index 9b72e9ea10..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer_1.webp b/static/images/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer_1.webp deleted file mode 100644 index 4c426892e0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/evaluation/preparing_the_computer_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/clientsetup1.webp b/static/images/passwordpolicyenforcer/11.2/install/clientsetup1.webp deleted file mode 100644 index 11effdf2cf..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/clientsetup1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/clientsetup2.webp b/static/images/passwordpolicyenforcer/11.2/install/clientsetup2.webp deleted file mode 100644 index 269fa64c9f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/clientsetup2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/clientsetup3.webp b/static/images/passwordpolicyenforcer/11.2/install/clientsetup3.webp deleted file mode 100644 index ad6f7ecd9b..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/clientsetup3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/clientsetup4.webp b/static/images/passwordpolicyenforcer/11.2/install/clientsetup4.webp deleted file mode 100644 index 79e590b99a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/clientsetup4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/gpm1.webp b/static/images/passwordpolicyenforcer/11.2/install/gpm1.webp deleted file mode 100644 index d8a96a6d03..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/gpm1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/gpm2.webp b/static/images/passwordpolicyenforcer/11.2/install/gpm2.webp deleted file mode 100644 index 2a0f3b8fd0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/gpm2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/installing_ppe_2.webp b/static/images/passwordpolicyenforcer/11.2/install/installing_ppe_2.webp deleted file mode 100644 index 6ef6db21ca..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/installing_ppe_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/serversetup1.webp b/static/images/passwordpolicyenforcer/11.2/install/serversetup1.webp deleted file mode 100644 index 8f4be42122..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/serversetup1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/serversetup2.webp b/static/images/passwordpolicyenforcer/11.2/install/serversetup2.webp deleted file mode 100644 index 9edd19d505..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/serversetup2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/serversetup3.webp b/static/images/passwordpolicyenforcer/11.2/install/serversetup3.webp deleted file mode 100644 index f3a1918817..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/serversetup3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/serversetup4.webp b/static/images/passwordpolicyenforcer/11.2/install/serversetup4.webp deleted file mode 100644 index 5b2419a77d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/serversetup4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/install/serversetup5.webp b/static/images/passwordpolicyenforcer/11.2/install/serversetup5.webp deleted file mode 100644 index c3e6c7e8ff..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/install/serversetup5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr.webp deleted file mode 100644 index 66592471d0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_0.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_0.webp deleted file mode 100644 index a94bdaeab1..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_0.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_1.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_1.webp deleted file mode 100644 index 6ca0f46a48..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_10.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_10.webp deleted file mode 100644 index f7e6accce0..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_10.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_2.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_2.webp deleted file mode 100644 index 24a6a69be5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_3_709x772.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_3_709x772.webp deleted file mode 100644 index f0c5c09c7c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_3_709x772.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_4.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_4.webp deleted file mode 100644 index 590339e5ac..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_5.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_5.webp deleted file mode 100644 index e7f3acc03f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_6.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_6.webp deleted file mode 100644 index 0e9a72c722..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_6.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_7.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_7.webp deleted file mode 100644 index 1d1812ec33..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_8.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_8.webp deleted file mode 100644 index 764546b0e3..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_8.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_9.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_9.webp deleted file mode 100644 index 51082b59d8..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/configuring_npr_9.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/installing_npr_1.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/installing_npr_1.webp deleted file mode 100644 index c753368e8c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/installing_npr_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/installing_npr_624x193.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/installing_npr_624x193.webp deleted file mode 100644 index 37e76fcc1c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/installing_npr_624x193.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/persuading_users_to_enroll.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/persuading_users_to_enroll.webp deleted file mode 100644 index cedcffc37b..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/persuading_users_to_enroll.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_1_895x652.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_1_895x652.webp deleted file mode 100644 index 6d81b3e2f6..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_1_895x652.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_2.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_2.webp deleted file mode 100644 index 85e205b911..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_3.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_3.webp deleted file mode 100644 index e700ba7976..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_4.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_4.webp deleted file mode 100644 index 6f0c3f24bd..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_5.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_5.webp deleted file mode 100644 index 9e63c4e63f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_905x750.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_905x750.webp deleted file mode 100644 index 338d4dba9f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/the_password_reset_client_905x750.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_0_765x963.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_0_765x963.webp deleted file mode 100644 index 79ab24e742..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_0_765x963.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_10_771x440.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_10_771x440.webp deleted file mode 100644 index c12f7b3c85..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_10_771x440.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_11_773x593.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_11_773x593.webp deleted file mode 100644 index fb6acc5604..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_11_773x593.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_12.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_12.webp deleted file mode 100644 index 511c6f17f6..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_12.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_13.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_13.webp deleted file mode 100644 index 913a93af9b..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_13.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_1_824x469.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_1_824x469.webp deleted file mode 100644 index 83a29189bd..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_1_824x469.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_2_809x640.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_2_809x640.webp deleted file mode 100644 index a209f92167..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_2_809x640.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_3.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_3.webp deleted file mode 100644 index 514bd0dba9..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_4_842x816.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_4_842x816.webp deleted file mode 100644 index c30249f740..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_4_842x816.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_5.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_5.webp deleted file mode 100644 index 5f951d58f4..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_6.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_6.webp deleted file mode 100644 index fa7778ba85..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_6.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_7.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_7.webp deleted file mode 100644 index 54c1e6b528..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_8.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_8.webp deleted file mode 100644 index 5188cce1a7..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_8.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_866x634.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_866x634.webp deleted file mode 100644 index 3e7d337f75..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_866x634.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_9.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_9.webp deleted file mode 100644 index 3475c7b8a4..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_9.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_9_789x276.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_9_789x276.webp deleted file mode 100644 index 4cda2e3d74..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_npr_9_789x276.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_ppe_with_npr.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_ppe_with_npr.webp deleted file mode 100644 index dbf7bcac05..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_ppe_with_npr.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console.webp deleted file mode 100644 index 594c25880a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_10.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_10.webp deleted file mode 100644 index 4f8f574d7f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_10.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_11.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_11.webp deleted file mode 100644 index aeb6bbdfc4..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_11.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_12.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_12.webp deleted file mode 100644 index 96c6a9620c..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_12.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_13.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_13.webp deleted file mode 100644 index 10b703fdc3..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_13.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_1_1393x772.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_1_1393x772.webp deleted file mode 100644 index 2934a1e86d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_1_1393x772.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_2_1317x725.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_2_1317x725.webp deleted file mode 100644 index 41fee0ff30..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_2_1317x725.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_3.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_3.webp deleted file mode 100644 index 65ea7ade3a..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_3.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_4.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_4.webp deleted file mode 100644 index 9a793cca1f..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_5.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_5.webp deleted file mode 100644 index cbbc18d5c2..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_5.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_6.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_6.webp deleted file mode 100644 index 5255843ffa..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_6.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_7.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_7.webp deleted file mode 100644 index fcc5beba5d..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_7.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_8.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_8.webp deleted file mode 100644 index 09dc99a135..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_8.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_9.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_9.webp deleted file mode 100644 index 82dc5c5fe5..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/using_the_data_console_9.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/working_with_the_database.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/working_with_the_database.webp deleted file mode 100644 index adac686f03..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/working_with_the_database.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/working_with_the_database_1.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/working_with_the_database_1.webp deleted file mode 100644 index 94139764f1..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/administration/working_with_the_database_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/passwordreset/evaluation/introduction_1_1.webp b/static/images/passwordpolicyenforcer/11.2/passwordreset/evaluation/introduction_1_1.webp deleted file mode 100644 index 514bd0dba9..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/passwordreset/evaluation/introduction_1_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/web/configuring_ppe_web.webp b/static/images/passwordpolicyenforcer/11.2/web/configuring_ppe_web.webp deleted file mode 100644 index 4a41202633..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/web/configuring_ppe_web.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/web/configuring_ppe_web_1.webp b/static/images/passwordpolicyenforcer/11.2/web/configuring_ppe_web_1.webp deleted file mode 100644 index 7d4a4c8fb7..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/web/configuring_ppe_web_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/web/editing_the_html_templates_1.webp b/static/images/passwordpolicyenforcer/11.2/web/editing_the_html_templates_1.webp deleted file mode 100644 index 797e4b93e2..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/web/editing_the_html_templates_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/web/introduction_4.webp b/static/images/passwordpolicyenforcer/11.2/web/introduction_4.webp deleted file mode 100644 index 47c5c80ac8..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/web/introduction_4.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/web/using_ppe_web.webp b/static/images/passwordpolicyenforcer/11.2/web/using_ppe_web.webp deleted file mode 100644 index fa7f3e1000..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/web/using_ppe_web.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/web/using_ppe_web_1.webp b/static/images/passwordpolicyenforcer/11.2/web/using_ppe_web_1.webp deleted file mode 100644 index dd1f253e45..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/web/using_ppe_web_1.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/web/using_ppe_web_2.webp b/static/images/passwordpolicyenforcer/11.2/web/using_ppe_web_2.webp deleted file mode 100644 index 2c269adb73..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/web/using_ppe_web_2.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/web/webwelcome.webp b/static/images/passwordpolicyenforcer/11.2/web/webwelcome.webp deleted file mode 100644 index 51efb6513e..0000000000 Binary files a/static/images/passwordpolicyenforcer/11.2/web/webwelcome.webp and /dev/null differ diff --git a/static/images/passwordpolicyenforcer/11.2/administration/agemax.webp b/static/images/passwordpolicyenforcer/administration/agemax.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/agemax.webp rename to static/images/passwordpolicyenforcer/administration/agemax.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/agemin.webp b/static/images/passwordpolicyenforcer/administration/agemin.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/agemin.webp rename to static/images/passwordpolicyenforcer/administration/agemin.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/character_patterns.webp b/static/images/passwordpolicyenforcer/administration/character_patterns.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/character_patterns.webp rename to static/images/passwordpolicyenforcer/administration/character_patterns.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/characters_granular_must_contain_two_special.webp b/static/images/passwordpolicyenforcer/administration/characters_granular_must_contain_two_special.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/characters_granular_must_contain_two_special.webp rename to static/images/passwordpolicyenforcer/administration/characters_granular_must_contain_two_special.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/charcomplexity.webp b/static/images/passwordpolicyenforcer/administration/charcomplexity.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/charcomplexity.webp rename to static/images/passwordpolicyenforcer/administration/charcomplexity.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/chargranular.webp b/static/images/passwordpolicyenforcer/administration/chargranular.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/chargranular.webp rename to static/images/passwordpolicyenforcer/administration/chargranular.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/chargranularrestrict.webp b/static/images/passwordpolicyenforcer/administration/chargranularrestrict.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/chargranularrestrict.webp rename to static/images/passwordpolicyenforcer/administration/chargranularrestrict.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/chargranularvowel.webp b/static/images/passwordpolicyenforcer/administration/chargranularvowel.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/chargranularvowel.webp rename to static/images/passwordpolicyenforcer/administration/chargranularvowel.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/cmdletconnect.webp b/static/images/passwordpolicyenforcer/administration/cmdletconnect.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/cmdletconnect.webp rename to static/images/passwordpolicyenforcer/administration/cmdletconnect.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/cmdletgetppebulkpasswordtest.webp b/static/images/passwordpolicyenforcer/administration/cmdletgetppebulkpasswordtest.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/cmdletgetppebulkpasswordtest.webp rename to static/images/passwordpolicyenforcer/administration/cmdletgetppebulkpasswordtest.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/cmdletgetppeconfigreport.webp b/static/images/passwordpolicyenforcer/administration/cmdletgetppeconfigreport.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/cmdletgetppeconfigreport.webp rename to static/images/passwordpolicyenforcer/administration/cmdletgetppeconfigreport.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/cmdletstartppehibpupdater.webp b/static/images/passwordpolicyenforcer/administration/cmdletstartppehibpupdater.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/cmdletstartppehibpupdater.webp rename to static/images/passwordpolicyenforcer/administration/cmdletstartppehibpupdater.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/compromised.webp b/static/images/passwordpolicyenforcer/administration/compromised.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/compromised.webp rename to static/images/passwordpolicyenforcer/administration/compromised.webp diff --git a/static/images/passwordpolicyenforcer/11.1/administration/compromisedpasswords.webp b/static/images/passwordpolicyenforcer/administration/compromisedpasswords.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/administration/compromisedpasswords.webp rename to static/images/passwordpolicyenforcer/administration/compromisedpasswords.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/compromisedpasswordsschedule.webp b/static/images/passwordpolicyenforcer/administration/compromisedpasswordsschedule.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/compromisedpasswordsschedule.webp rename to static/images/passwordpolicyenforcer/administration/compromisedpasswordsschedule.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/dictionary.webp b/static/images/passwordpolicyenforcer/administration/dictionary.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/dictionary.webp rename to static/images/passwordpolicyenforcer/administration/dictionary.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/domain_and_local_policies.webp b/static/images/passwordpolicyenforcer/administration/domain_and_local_policies.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/domain_and_local_policies.webp rename to static/images/passwordpolicyenforcer/administration/domain_and_local_policies.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/domain_and_local_policies_1.webp b/static/images/passwordpolicyenforcer/administration/domain_and_local_policies_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/domain_and_local_policies_1.webp rename to static/images/passwordpolicyenforcer/administration/domain_and_local_policies_1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/editschedule.webp b/static/images/passwordpolicyenforcer/administration/editschedule.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/editschedule.webp rename to static/images/passwordpolicyenforcer/administration/editschedule.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/email_template_editor.webp b/static/images/passwordpolicyenforcer/administration/email_template_editor.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/email_template_editor.webp rename to static/images/passwordpolicyenforcer/administration/email_template_editor.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/emailusernotification.webp b/static/images/passwordpolicyenforcer/administration/emailusernotification.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/emailusernotification.webp rename to static/images/passwordpolicyenforcer/administration/emailusernotification.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/enabledisableppeconsole.webp b/static/images/passwordpolicyenforcer/administration/enabledisableppeconsole.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/enabledisableppeconsole.webp rename to static/images/passwordpolicyenforcer/administration/enabledisableppeconsole.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/enabledrules.webp b/static/images/passwordpolicyenforcer/administration/enabledrules.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/enabledrules.webp rename to static/images/passwordpolicyenforcer/administration/enabledrules.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/hibpfolder.webp b/static/images/passwordpolicyenforcer/administration/hibpfolder.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/hibpfolder.webp rename to static/images/passwordpolicyenforcer/administration/hibpfolder.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/hibpupdater.webp b/static/images/passwordpolicyenforcer/administration/hibpupdater.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/hibpupdater.webp rename to static/images/passwordpolicyenforcer/administration/hibpupdater.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/history.webp b/static/images/passwordpolicyenforcer/administration/history.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/history.webp rename to static/images/passwordpolicyenforcer/administration/history.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/keyboard_layouts.webp b/static/images/passwordpolicyenforcer/administration/keyboard_layouts.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/keyboard_layouts.webp rename to static/images/passwordpolicyenforcer/administration/keyboard_layouts.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/last_character_rule.webp b/static/images/passwordpolicyenforcer/administration/last_character_rule.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/last_character_rule.webp rename to static/images/passwordpolicyenforcer/administration/last_character_rule.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/length.webp b/static/images/passwordpolicyenforcer/administration/length.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/length.webp rename to static/images/passwordpolicyenforcer/administration/length.webp diff --git a/static/images/passwordpolicyenforcer/10.2/administration/managing_policies.webp b/static/images/passwordpolicyenforcer/administration/managing_policies.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/administration/managing_policies.webp rename to static/images/passwordpolicyenforcer/administration/managing_policies.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/managing_policies_3.webp b/static/images/passwordpolicyenforcer/administration/managing_policies_3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/managing_policies_3.webp rename to static/images/passwordpolicyenforcer/administration/managing_policies_3.webp diff --git a/static/images/passwordpolicyenforcer/11.1/administration/mesages2.webp b/static/images/passwordpolicyenforcer/administration/mesages2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/administration/mesages2.webp rename to static/images/passwordpolicyenforcer/administration/mesages2.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/message_generic_rejection_template.webp b/static/images/passwordpolicyenforcer/administration/message_generic_rejection_template.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/message_generic_rejection_template.webp rename to static/images/passwordpolicyenforcer/administration/message_generic_rejection_template.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/message_live_policy_macro.webp b/static/images/passwordpolicyenforcer/administration/message_live_policy_macro.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/message_live_policy_macro.webp rename to static/images/passwordpolicyenforcer/administration/message_live_policy_macro.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/message_rejection_reason_template.webp b/static/images/passwordpolicyenforcer/administration/message_rejection_reason_template.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/message_rejection_reason_template.webp rename to static/images/passwordpolicyenforcer/administration/message_rejection_reason_template.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/message_template.webp b/static/images/passwordpolicyenforcer/administration/message_template.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/message_template.webp rename to static/images/passwordpolicyenforcer/administration/message_template.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/messages.webp b/static/images/passwordpolicyenforcer/administration/messages.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/messages.webp rename to static/images/passwordpolicyenforcer/administration/messages.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/passphrase.webp b/static/images/passwordpolicyenforcer/administration/passphrase.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/passphrase.webp rename to static/images/passwordpolicyenforcer/administration/passphrase.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/patterns.webp b/static/images/passwordpolicyenforcer/administration/patterns.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/patterns.webp rename to static/images/passwordpolicyenforcer/administration/patterns.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/policy_options_menu.webp b/static/images/passwordpolicyenforcer/administration/policy_options_menu.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/policy_options_menu.webp rename to static/images/passwordpolicyenforcer/administration/policy_options_menu.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/policypriority.webp b/static/images/passwordpolicyenforcer/administration/policypriority.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/policypriority.webp rename to static/images/passwordpolicyenforcer/administration/policypriority.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration.webp b/static/images/passwordpolicyenforcer/administration/ppc_configuration.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration.webp rename to static/images/passwordpolicyenforcer/administration/ppc_configuration.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration1.webp b/static/images/passwordpolicyenforcer/administration/ppc_configuration1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration1.webp rename to static/images/passwordpolicyenforcer/administration/ppc_configuration1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration2.webp b/static/images/passwordpolicyenforcer/administration/ppc_configuration2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration2.webp rename to static/images/passwordpolicyenforcer/administration/ppc_configuration2.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration3.webp b/static/images/passwordpolicyenforcer/administration/ppc_configuration3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/ppc_configuration3.webp rename to static/images/passwordpolicyenforcer/administration/ppc_configuration3.webp diff --git a/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration4.webp b/static/images/passwordpolicyenforcer/administration/ppc_configuration4.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration4.webp rename to static/images/passwordpolicyenforcer/administration/ppc_configuration4.webp diff --git a/static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration5.webp b/static/images/passwordpolicyenforcer/administration/ppc_configuration5.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/administration/ppc_configuration5.webp rename to static/images/passwordpolicyenforcer/administration/ppc_configuration5.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/ppe1.webp b/static/images/passwordpolicyenforcer/administration/ppe1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/ppe1.webp rename to static/images/passwordpolicyenforcer/administration/ppe1.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/ppe_rules_8.webp b/static/images/passwordpolicyenforcer/administration/ppe_rules_8.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/ppe_rules_8.webp rename to static/images/passwordpolicyenforcer/administration/ppe_rules_8.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/ppedashboardpolicies.webp b/static/images/passwordpolicyenforcer/administration/ppedashboardpolicies.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/ppedashboardpolicies.webp rename to static/images/passwordpolicyenforcer/administration/ppedashboardpolicies.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/properties.webp b/static/images/passwordpolicyenforcer/administration/properties.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/properties.webp rename to static/images/passwordpolicyenforcer/administration/properties.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/propertyeditor.webp b/static/images/passwordpolicyenforcer/administration/propertyeditor.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/propertyeditor.webp rename to static/images/passwordpolicyenforcer/administration/propertyeditor.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/repetition.webp b/static/images/passwordpolicyenforcer/administration/repetition.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/repetition.webp rename to static/images/passwordpolicyenforcer/administration/repetition.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/schedulelist.webp b/static/images/passwordpolicyenforcer/administration/schedulelist.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/schedulelist.webp rename to static/images/passwordpolicyenforcer/administration/schedulelist.webp diff --git a/static/images/passwordpolicyenforcer/11.1/administration/settingsgeneral.webp b/static/images/passwordpolicyenforcer/administration/settingsgeneral.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/administration/settingsgeneral.webp rename to static/images/passwordpolicyenforcer/administration/settingsgeneral.webp diff --git a/static/images/passwordpolicyenforcer/11.1/administration/settingslicense.webp b/static/images/passwordpolicyenforcer/administration/settingslicense.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/administration/settingslicense.webp rename to static/images/passwordpolicyenforcer/administration/settingslicense.webp diff --git a/static/images/passwordpolicyenforcer/11.1/administration/settingsmailserver.webp b/static/images/passwordpolicyenforcer/administration/settingsmailserver.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/administration/settingsmailserver.webp rename to static/images/passwordpolicyenforcer/administration/settingsmailserver.webp diff --git a/static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications.webp b/static/images/passwordpolicyenforcer/administration/settingsnotifications.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/administration/settingsnotifications.webp rename to static/images/passwordpolicyenforcer/administration/settingsnotifications.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/similarity.webp b/static/images/passwordpolicyenforcer/administration/similarity.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/similarity.webp rename to static/images/passwordpolicyenforcer/administration/similarity.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/systemaudit.webp b/static/images/passwordpolicyenforcer/administration/systemaudit.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/systemaudit.webp rename to static/images/passwordpolicyenforcer/administration/systemaudit.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/systemaudittools.webp b/static/images/passwordpolicyenforcer/administration/systemaudittools.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/systemaudittools.webp rename to static/images/passwordpolicyenforcer/administration/systemaudittools.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/systemauditversion.webp b/static/images/passwordpolicyenforcer/administration/systemauditversion.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/systemauditversion.webp rename to static/images/passwordpolicyenforcer/administration/systemauditversion.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/testbulk.webp b/static/images/passwordpolicyenforcer/administration/testbulk.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/testbulk.webp rename to static/images/passwordpolicyenforcer/administration/testbulk.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/testbulkreport.webp b/static/images/passwordpolicyenforcer/administration/testbulkreport.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/testbulkreport.webp rename to static/images/passwordpolicyenforcer/administration/testbulkreport.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/testbulkresult.webp b/static/images/passwordpolicyenforcer/administration/testbulkresult.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/testbulkresult.webp rename to static/images/passwordpolicyenforcer/administration/testbulkresult.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/testuser.webp b/static/images/passwordpolicyenforcer/administration/testuser.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/testuser.webp rename to static/images/passwordpolicyenforcer/administration/testuser.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/testuserfail.webp b/static/images/passwordpolicyenforcer/administration/testuserfail.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/testuserfail.webp rename to static/images/passwordpolicyenforcer/administration/testuserfail.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/testuserpass.webp b/static/images/passwordpolicyenforcer/administration/testuserpass.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/testuserpass.webp rename to static/images/passwordpolicyenforcer/administration/testuserpass.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/testuserverbose.webp b/static/images/passwordpolicyenforcer/administration/testuserverbose.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/testuserverbose.webp rename to static/images/passwordpolicyenforcer/administration/testuserverbose.webp diff --git a/static/images/passwordpolicyenforcer/11.2/administration/testviewlog.webp b/static/images/passwordpolicyenforcer/administration/testviewlog.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.2/administration/testviewlog.webp rename to static/images/passwordpolicyenforcer/administration/testviewlog.webp diff --git a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client.webp b/static/images/passwordpolicyenforcer/administration/the_password_policy_client.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client.webp rename to static/images/passwordpolicyenforcer/administration/the_password_policy_client.webp diff --git a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_1.webp b/static/images/passwordpolicyenforcer/administration/the_password_policy_client_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_1.webp rename to static/images/passwordpolicyenforcer/administration/the_password_policy_client_1.webp diff --git a/static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_3.webp b/static/images/passwordpolicyenforcer/administration/the_password_policy_client_3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/administration/the_password_policy_client_3.webp rename to static/images/passwordpolicyenforcer/administration/the_password_policy_client_3.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/unique.webp b/static/images/passwordpolicyenforcer/administration/unique.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/unique.webp rename to static/images/passwordpolicyenforcer/administration/unique.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/usersandgroups.webp b/static/images/passwordpolicyenforcer/administration/usersandgroups.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/usersandgroups.webp rename to static/images/passwordpolicyenforcer/administration/usersandgroups.webp diff --git a/static/images/passwordpolicyenforcer/11.0/administration/usersandgroups2.webp b/static/images/passwordpolicyenforcer/administration/usersandgroups2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/administration/usersandgroups2.webp rename to static/images/passwordpolicyenforcer/administration/usersandgroups2.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evaladmin.webp b/static/images/passwordpolicyenforcer/evaluation/evaladmin.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evaladmin.webp rename to static/images/passwordpolicyenforcer/evaluation/evaladmin.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evalchars.webp b/static/images/passwordpolicyenforcer/evaluation/evalchars.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evalchars.webp rename to static/images/passwordpolicyenforcer/evaluation/evalchars.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evalcharsgran.webp b/static/images/passwordpolicyenforcer/evaluation/evalcharsgran.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evalcharsgran.webp rename to static/images/passwordpolicyenforcer/evaluation/evalcharsgran.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evalcopypolicy2.webp b/static/images/passwordpolicyenforcer/evaluation/evalcopypolicy2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evalcopypolicy2.webp rename to static/images/passwordpolicyenforcer/evaluation/evalcopypolicy2.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evaldashboard.webp b/static/images/passwordpolicyenforcer/evaluation/evaldashboard.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evaldashboard.webp rename to static/images/passwordpolicyenforcer/evaluation/evaldashboard.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evaldefault.webp b/static/images/passwordpolicyenforcer/evaluation/evaldefault.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evaldefault.webp rename to static/images/passwordpolicyenforcer/evaluation/evaldefault.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evaldict.webp b/static/images/passwordpolicyenforcer/evaluation/evaldict.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evaldict.webp rename to static/images/passwordpolicyenforcer/evaluation/evaldict.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evaldomainadmins.webp b/static/images/passwordpolicyenforcer/evaluation/evaldomainadmins.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evaldomainadmins.webp rename to static/images/passwordpolicyenforcer/evaluation/evaldomainadmins.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evallength.webp b/static/images/passwordpolicyenforcer/evaluation/evallength.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evallength.webp rename to static/images/passwordpolicyenforcer/evaluation/evallength.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evallength9.webp b/static/images/passwordpolicyenforcer/evaluation/evallength9.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evallength9.webp rename to static/images/passwordpolicyenforcer/evaluation/evallength9.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evalsimilarity.webp b/static/images/passwordpolicyenforcer/evaluation/evalsimilarity.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evalsimilarity.webp rename to static/images/passwordpolicyenforcer/evaluation/evalsimilarity.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evaltestuser.webp b/static/images/passwordpolicyenforcer/evaluation/evaltestuser.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evaltestuser.webp rename to static/images/passwordpolicyenforcer/evaluation/evaltestuser.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evaltestuserfail.webp b/static/images/passwordpolicyenforcer/evaluation/evaltestuserfail.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evaltestuserfail.webp rename to static/images/passwordpolicyenforcer/evaluation/evaltestuserfail.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/evalusergroups.webp b/static/images/passwordpolicyenforcer/evaluation/evalusergroups.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/evalusergroups.webp rename to static/images/passwordpolicyenforcer/evaluation/evalusergroups.webp diff --git a/static/images/passwordpolicyenforcer/10.2/evaluation/introduction_3.webp b/static/images/passwordpolicyenforcer/evaluation/introduction_3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/evaluation/introduction_3.webp rename to static/images/passwordpolicyenforcer/evaluation/introduction_3.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/newpolicysettings.webp b/static/images/passwordpolicyenforcer/evaluation/newpolicysettings.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/newpolicysettings.webp rename to static/images/passwordpolicyenforcer/evaluation/newpolicysettings.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/ppedashboard.webp b/static/images/passwordpolicyenforcer/evaluation/ppedashboard.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/ppedashboard.webp rename to static/images/passwordpolicyenforcer/evaluation/ppedashboard.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/preparing_the_computer.webp b/static/images/passwordpolicyenforcer/evaluation/preparing_the_computer.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/preparing_the_computer.webp rename to static/images/passwordpolicyenforcer/evaluation/preparing_the_computer.webp diff --git a/static/images/passwordpolicyenforcer/11.0/evaluation/preparing_the_computer_1.webp b/static/images/passwordpolicyenforcer/evaluation/preparing_the_computer_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/evaluation/preparing_the_computer_1.webp rename to static/images/passwordpolicyenforcer/evaluation/preparing_the_computer_1.webp diff --git a/static/images/passwordpolicyenforcer/11.1/install/clientsetup1.webp b/static/images/passwordpolicyenforcer/install/clientsetup1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/install/clientsetup1.webp rename to static/images/passwordpolicyenforcer/install/clientsetup1.webp diff --git a/static/images/passwordpolicyenforcer/11.1/install/clientsetup2.webp b/static/images/passwordpolicyenforcer/install/clientsetup2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/install/clientsetup2.webp rename to static/images/passwordpolicyenforcer/install/clientsetup2.webp diff --git a/static/images/passwordpolicyenforcer/11.1/install/clientsetup3.webp b/static/images/passwordpolicyenforcer/install/clientsetup3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/install/clientsetup3.webp rename to static/images/passwordpolicyenforcer/install/clientsetup3.webp diff --git a/static/images/passwordpolicyenforcer/11.1/install/clientsetup4.webp b/static/images/passwordpolicyenforcer/install/clientsetup4.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/install/clientsetup4.webp rename to static/images/passwordpolicyenforcer/install/clientsetup4.webp diff --git a/static/images/passwordpolicyenforcer/11.0/install/gpm1.webp b/static/images/passwordpolicyenforcer/install/gpm1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/install/gpm1.webp rename to static/images/passwordpolicyenforcer/install/gpm1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/install/gpm2.webp b/static/images/passwordpolicyenforcer/install/gpm2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/install/gpm2.webp rename to static/images/passwordpolicyenforcer/install/gpm2.webp diff --git a/static/images/passwordpolicyenforcer/11.0/install/installing_ppe_2.webp b/static/images/passwordpolicyenforcer/install/installing_ppe_2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/install/installing_ppe_2.webp rename to static/images/passwordpolicyenforcer/install/installing_ppe_2.webp diff --git a/static/images/passwordpolicyenforcer/11.1/install/serversetup1.webp b/static/images/passwordpolicyenforcer/install/serversetup1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/install/serversetup1.webp rename to static/images/passwordpolicyenforcer/install/serversetup1.webp diff --git a/static/images/passwordpolicyenforcer/11.1/install/serversetup2.webp b/static/images/passwordpolicyenforcer/install/serversetup2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/install/serversetup2.webp rename to static/images/passwordpolicyenforcer/install/serversetup2.webp diff --git a/static/images/passwordpolicyenforcer/11.1/install/serversetup3.webp b/static/images/passwordpolicyenforcer/install/serversetup3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/install/serversetup3.webp rename to static/images/passwordpolicyenforcer/install/serversetup3.webp diff --git a/static/images/passwordpolicyenforcer/11.1/install/serversetup4.webp b/static/images/passwordpolicyenforcer/install/serversetup4.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/install/serversetup4.webp rename to static/images/passwordpolicyenforcer/install/serversetup4.webp diff --git a/static/images/passwordpolicyenforcer/11.1/install/serversetup5.webp b/static/images/passwordpolicyenforcer/install/serversetup5.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.1/install/serversetup5.webp rename to static/images/passwordpolicyenforcer/install/serversetup5.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_0.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_0.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_0.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_0.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_1.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_1.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_1.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_10.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_10.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_10.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_10.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_2.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_2.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_2.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_3_709x772.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_3_709x772.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_3_709x772.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_3_709x772.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_4.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_4.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_4.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_4.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_5.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_5.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_5.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_5.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_6.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_6.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_6.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_6.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_7.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_7.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_7.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_7.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_8.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_8.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_8.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_8.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_9.webp b/static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_9.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/configuring_npr_9.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/configuring_npr_9.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/installing_npr_1.webp b/static/images/passwordpolicyenforcer/password_reset/administration/installing_npr_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/installing_npr_1.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/installing_npr_1.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/installing_npr_624x193.webp b/static/images/passwordpolicyenforcer/password_reset/administration/installing_npr_624x193.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/installing_npr_624x193.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/installing_npr_624x193.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/persuading_users_to_enroll.webp b/static/images/passwordpolicyenforcer/password_reset/administration/persuading_users_to_enroll.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/persuading_users_to_enroll.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/persuading_users_to_enroll.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_1_895x652.webp b/static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_1_895x652.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_1_895x652.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_1_895x652.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_2.webp b/static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_2.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_2.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_3.webp b/static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_3.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_3.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_4.webp b/static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_4.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_4.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_4.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_5.webp b/static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_5.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_5.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_5.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_905x750.webp b/static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_905x750.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/the_password_reset_client_905x750.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/the_password_reset_client_905x750.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_0_765x963.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_0_765x963.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_0_765x963.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_0_765x963.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_10_771x440.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_10_771x440.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_10_771x440.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_10_771x440.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_11_773x593.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_11_773x593.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_11_773x593.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_11_773x593.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_12.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_12.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_12.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_12.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_13.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_13.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_13.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_13.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_1_824x469.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_1_824x469.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_1_824x469.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_1_824x469.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_2_809x640.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_2_809x640.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_2_809x640.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_2_809x640.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_3.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_3.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_3.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_4_842x816.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_4_842x816.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_4_842x816.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_4_842x816.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_5.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_5.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_5.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_5.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_6.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_6.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_6.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_6.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_7.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_7.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_7.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_7.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_8.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_8.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_8.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_8.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_866x634.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_866x634.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_866x634.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_866x634.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_9.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_9.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_9.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_9.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_9_789x276.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_npr_9_789x276.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_npr_9_789x276.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_npr_9_789x276.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_ppe_with_npr.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_ppe_with_npr.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_ppe_with_npr.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_ppe_with_npr.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_10.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_10.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_10.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_10.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_11.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_11.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_11.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_11.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_12.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_12.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_12.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_12.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_13.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_13.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_13.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_13.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_1_1393x772.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_1_1393x772.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_1_1393x772.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_1_1393x772.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_2_1317x725.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_2_1317x725.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_2_1317x725.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_2_1317x725.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_3.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_3.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_3.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_4.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_4.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_4.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_4.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_5.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_5.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_5.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_5.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_6.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_6.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_6.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_6.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_7.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_7.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_7.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_7.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_8.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_8.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_8.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_8.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_9.webp b/static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_9.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/using_the_data_console_9.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/using_the_data_console_9.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/working_with_the_database.webp b/static/images/passwordpolicyenforcer/password_reset/administration/working_with_the_database.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/working_with_the_database.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/working_with_the_database.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/administration/working_with_the_database_1.webp b/static/images/passwordpolicyenforcer/password_reset/administration/working_with_the_database_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/administration/working_with_the_database_1.webp rename to static/images/passwordpolicyenforcer/password_reset/administration/working_with_the_database_1.webp diff --git a/static/images/passwordpolicyenforcer/10.2/password_reset/evaluation/introduction_1_1.webp b/static/images/passwordpolicyenforcer/password_reset/evaluation/introduction_1_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/10.2/password_reset/evaluation/introduction_1_1.webp rename to static/images/passwordpolicyenforcer/password_reset/evaluation/introduction_1_1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_0.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_0.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_0.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_0.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_1.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_1.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_10.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_10.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_10.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_10.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_2.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_2.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_2.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_3_709x772.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_3_709x772.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_3_709x772.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_3_709x772.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_4.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_4.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_4.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_4.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_5.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_5.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_5.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_5.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_6.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_6.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_6.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_6.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_7.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_7.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_7.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_7.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_8.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_8.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_8.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_8.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_9.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_9.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_9.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/configuring_npr_9.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/installing_npr_1.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/installing_npr_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/installing_npr_1.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/installing_npr_1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/installing_npr_624x193.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/installing_npr_624x193.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/installing_npr_624x193.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/installing_npr_624x193.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/persuading_users_to_enroll.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/persuading_users_to_enroll.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/persuading_users_to_enroll.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/persuading_users_to_enroll.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_1_895x652.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_1_895x652.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_1_895x652.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_1_895x652.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_2.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_2.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_2.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_3.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_3.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_3.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_4.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_4.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_4.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_4.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_5.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_5.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_5.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_5.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_905x750.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_905x750.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/the_password_reset_client_905x750.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/the_password_reset_client_905x750.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_0_765x963.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_0_765x963.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_0_765x963.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_0_765x963.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_10_771x440.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_10_771x440.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_10_771x440.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_10_771x440.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_11_773x593.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_11_773x593.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_11_773x593.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_11_773x593.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_12.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_12.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_12.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_12.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_13.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_13.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_13.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_13.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_1_824x469.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_1_824x469.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_1_824x469.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_1_824x469.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_2_809x640.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_2_809x640.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_2_809x640.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_2_809x640.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_3.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_3.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_3.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_4_842x816.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_4_842x816.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_4_842x816.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_4_842x816.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_5.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_5.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_5.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_5.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_6.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_6.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_6.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_6.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_7.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_7.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_7.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_7.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_8.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_8.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_8.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_8.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_866x634.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_866x634.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_866x634.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_866x634.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_9.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_9.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_9.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_9.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_9_789x276.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_9_789x276.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_npr_9_789x276.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_npr_9_789x276.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_ppe_with_npr.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_ppe_with_npr.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_ppe_with_npr.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_ppe_with_npr.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_10.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_10.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_10.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_10.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_11.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_11.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_11.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_11.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_12.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_12.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_12.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_12.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_13.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_13.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_13.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_13.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_1_1393x772.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_1_1393x772.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_1_1393x772.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_1_1393x772.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_2_1317x725.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_2_1317x725.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_2_1317x725.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_2_1317x725.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_3.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_3.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_3.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_3.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_4.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_4.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_4.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_4.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_5.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_5.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_5.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_5.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_6.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_6.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_6.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_6.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_7.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_7.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_7.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_7.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_8.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_8.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_8.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_8.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_9.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_9.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/using_the_data_console_9.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/using_the_data_console_9.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/working_with_the_database.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/working_with_the_database.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/working_with_the_database.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/working_with_the_database.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/administration/working_with_the_database_1.webp b/static/images/passwordpolicyenforcer/passwordreset/administration/working_with_the_database_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/administration/working_with_the_database_1.webp rename to static/images/passwordpolicyenforcer/passwordreset/administration/working_with_the_database_1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/passwordreset/evaluation/introduction_1_1.webp b/static/images/passwordpolicyenforcer/passwordreset/evaluation/introduction_1_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/passwordreset/evaluation/introduction_1_1.webp rename to static/images/passwordpolicyenforcer/passwordreset/evaluation/introduction_1_1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/web/configuring_ppe_web.webp b/static/images/passwordpolicyenforcer/web/configuring_ppe_web.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/web/configuring_ppe_web.webp rename to static/images/passwordpolicyenforcer/web/configuring_ppe_web.webp diff --git a/static/images/passwordpolicyenforcer/11.0/web/configuring_ppe_web_1.webp b/static/images/passwordpolicyenforcer/web/configuring_ppe_web_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/web/configuring_ppe_web_1.webp rename to static/images/passwordpolicyenforcer/web/configuring_ppe_web_1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/web/editing_the_html_templates_1.webp b/static/images/passwordpolicyenforcer/web/editing_the_html_templates_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/web/editing_the_html_templates_1.webp rename to static/images/passwordpolicyenforcer/web/editing_the_html_templates_1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/web/introduction_4.webp b/static/images/passwordpolicyenforcer/web/introduction_4.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/web/introduction_4.webp rename to static/images/passwordpolicyenforcer/web/introduction_4.webp diff --git a/static/images/passwordpolicyenforcer/11.0/web/using_ppe_web.webp b/static/images/passwordpolicyenforcer/web/using_ppe_web.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/web/using_ppe_web.webp rename to static/images/passwordpolicyenforcer/web/using_ppe_web.webp diff --git a/static/images/passwordpolicyenforcer/11.0/web/using_ppe_web_1.webp b/static/images/passwordpolicyenforcer/web/using_ppe_web_1.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/web/using_ppe_web_1.webp rename to static/images/passwordpolicyenforcer/web/using_ppe_web_1.webp diff --git a/static/images/passwordpolicyenforcer/11.0/web/using_ppe_web_2.webp b/static/images/passwordpolicyenforcer/web/using_ppe_web_2.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/web/using_ppe_web_2.webp rename to static/images/passwordpolicyenforcer/web/using_ppe_web_2.webp diff --git a/static/images/passwordpolicyenforcer/11.0/web/webwelcome.webp b/static/images/passwordpolicyenforcer/web/webwelcome.webp similarity index 100% rename from static/images/passwordpolicyenforcer/11.0/web/webwelcome.webp rename to static/images/passwordpolicyenforcer/web/webwelcome.webp