Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ Both options achieve the same result: they disable Password Policy Enforcer Clie
After applying either option, the username and password fields will no longer appear on the Windows logon screen. Only the authentication method configured for RSA MFA will be available at logon.

### Option 1 — With Group Policy:
> **NOTE:** Install the Password Policy Client administrative template before these steps. For the ADMX template and installation steps, see [Configuring the password policy client](https://docs.netwrix.com/docs/passwordpolicyenforcer/11_2/admin/password-policy-client/configuring_the_password_policy_client).
> **NOTE:** Install the Password Policy Client administrative template before these steps. For the ADMX template and installation steps, see [Configuring the password policy client](https://docs.netwrix.com/docs/passwordpolicyenforcer/admin/password-policy-client/configuring_the_password_policy_client).

1. In Group Policy Management, edit the GPO linked to the affected machines.
2. Expand **Computer Configuration** > **Policies** > **Administrative Templates** > **Netwrix Password Policy Enforcer** > **Netwrix Password Policy Client**.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ The following steps occur in order when you change your password:
maximum age, minimum length, and complexity.
- If the password fails any Windows rule, LSASS rejects the change immediately. PPE does not see the password on the domain controller.
- If the password passes all Windows rules, LSASS sends it to PPE for additional checks.
3. **Password Policy Server** — On the domain controller, PPE evaluates the password against all its rules except [Similarity](pathname:///docs/passwordpolicyenforcer/11_2/admin/manage-policies/rules/similarity_rule), and accepts or rejects the password.
3. **Password Policy Server** — On the domain controller, PPE evaluates the password against all its rules except [Similarity](pathname:///docs/passwordpolicyenforcer/admin/manage-policies/rules/similarity_rule), and accepts or rejects the password.

### Effect on the Password Policy Client

Expand All @@ -71,11 +71,11 @@ PPE can only log rejection events if PPE rejects the password, either on the cli

To ensure PPE evaluates all passwords and can provide detailed rejection messages, disable the Windows password policy rules. You must then satisfy only the PPE rules.

See [Disable Windows Rules](pathname:///docs/passwordpolicyenforcer/11_2/installation/disable_windows_rules) for instructions.
See [Disable Windows Rules](pathname:///docs/passwordpolicyenforcer/installation/disable_windows_rules) for instructions.

> **NOTE:** If your organization requires both Windows and PPE rules, you must satisfy both. A password that passes all client-side PPE rules but fails a Windows rule will always produce a generic rejection message, and PPE logs no event for that rejection. This is expected behavior.

## Related Links

- [Similarity](pathname:///docs/passwordpolicyenforcer/11_2/admin/manage-policies/rules/similarity_rule)
- [Disable Windows Rules](pathname:///docs/passwordpolicyenforcer/11_2/installation/disable_windows_rules)
- [Similarity](pathname:///docs/passwordpolicyenforcer/admin/manage-policies/rules/similarity_rule)
- [Disable Windows Rules](pathname:///docs/passwordpolicyenforcer/installation/disable_windows_rules)
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ Password verification will be performed on the domain controller %DC_FQDN%.

## Resolutions

- Netwrix Password Policy Enforcer Mailer is required for Compromised Password Checker to operate. If it was not installed previously, refer to the following article for additional information on installation: Administration − Mailer ⸱ v10.2: https://docs.netwrix.com/docs/passwordpolicyenforcer/11_0
- Netwrix Password Policy Enforcer Mailer is required for Compromised Password Checker to operate. If it was not installed previously, refer to the following article for additional information on installation: Administration − Mailer: https://docs.netwrix.com/docs/passwordpolicyenforcer

- Review the FQDN of the domain controller the Netwrix Password Policy Enforcer Mailer was installed to:

Expand Down
10 changes: 0 additions & 10 deletions docs/passwordpolicyenforcer/10.2/administration/_category_.json

This file was deleted.

This file was deleted.

70 changes: 0 additions & 70 deletions docs/passwordpolicyenforcer/10.2/administration/connecting.md

This file was deleted.

This file was deleted.

Loading
Loading