The information below will help you upgrade to the latest version of Specops Password Policy. For information on upgrading to the latest version of the Client, click here.

Supported upgrade environments

Supported upgrade environments

We strongly recommend that you keep Specops Password Policy installation updated to the latest version. When upgrading, all components should be upgraded. It is best practice to upgrade the components in the following order:

  1. Administration Tools
  2. Specops Password Policy Sentinel
  3. Specops Password Arbiter (if applicable)
  4. Specops Client (if applicable)

Planning an upgrade

Before upgrading, you should:

  1. Read the Specops Password Policy Release Notes. The Release Notes provide a summary of new features and changes since the last release. The Release Notes can help you evaluate whether an upgrade is necessary.
  2. Locate and read the Specops Password Policy Product Documentation.
  3. If you are upgrading to a new major version (for example, from version 5.xx to 6.xx), you will need a new license key before upgrading. Contact your sales representative for more information.


To upgrade to the latest version, your organization’s environment must meet the following system requirements:

Component Requirement
Administration Tools
  • Windows 10/11 or Windows Server 2016/2019/2022
  • .Net Framework 4.7.2 or later
  • Active Directory and Users and Computers snap-in
  • Group Policy Management Console (GPMC)
  • Windows Powershell 5.1
Specops Password Policy Sentinel
  • Windows Server 2016/2019/2022 (core or desktop experience)
  • .Net Framework 4.7.2 or later
  • Writable domain controller
Specops Authentication Client
  • Windows 10 x64, Windows 11 x64 or Windows Server 2016/2019/2022
  • .Net Framework 4.7.2 or later
  • For password resets with uReset 8 and Specops Password Reset, the Specops Cefsharp runtime MSI should be installed.
Specops Arbiter
  • Windows Server 2016/2019/2022 (core or desktop experience)
  • .Net Framework 4.7.2 or later

Upgrading Specops Password Policy

Upgrading Specops Password Policy requires domain administrator privileges.

The Setup Assistant will allow you to upgrade the required components. To start upgrading, follow the below tasks:

  1. Download the Setup Assistant.
  2. Save and Run the Setup Assistant locally to a machine where you administer Group Policy.
    By default the file is extracted to C:\temp\SpecopsPasswordPolicy_Setup_[VersionNumber]
  3. Double click SpecopsPasswordPolicy.Setup.exe to launch the Setup Assistant.
  4. To begin, click Start Installation in the Specops Setup Assistant dialog box.

Upgrading the Administration Tools

The Administration Tools are used to configure the central aspects of the solution and enable the creation of Specops Password Policy Settings in Group Policy Objects.

  1. From the Setup Assistant, select Administration Tools.
  2. Click Install.

The Domain Administration tool, Group Policy snap-in extension, and ADUC menu extensions will be updated.

Upgrading the Specops Password Policy Sentinel


To upgrade the Specops Password Policy Sentinel, it is required to upgrade the MSI on all writable domain controllers. After upgrading, each DC needs to be rebooted.

It is not necessary to apply the MSI to all DCs at once, but once the MSI is deployed to a DC, it should be rebooted after the upgrade without delay.

One strategy is to upgrade and reboot all DCs at once and reboot them.

However, in larger environments, it is unlikely that all DCs can be rebooted at the same time.

For such environments, upgrade a few DCs at a time; install and reboot so they eventually all have the latest Sentinel MSI.


Do NOT upgrade all DCs with the latest Sentinel MSI first, and wait with rebooting them. That could leave Specops Password Policy in a state where it is not functional.

New features in a policy should not be configured until all DCs have been upgraded and rebooted.

The Specops Sentinel ensures that password change requests comply with the Specops Password Policy assigned to the user object through Group Policy.

  1. From the Setup Assistant, select Domain Controller Sentinel to install the Sentinel.
  2. The grid will show all available domain controllers and the state for their Specops Password Policy Sentinel installation.
  3. Select one or more DCs that need upgrading (make sure to read the note and warning sections above first)
  4. Click Install.
  5. Reboot the upgraded DCs.

Upgrade the Specops Client

The Client displays the password policy rules when a user fails to meet the policy criteria when changing their password. The Client also notifies users when their passwords are about to expire.

You can automatically upgrade an existing Group Policy Object with Software Installation settings to deploy the Client in your domain.

  1. From the Setup Assistant, select Deploy Specops Password Client using GPSI.
  2. To select the Group Policy Object that will be used to deploy the Client, click Select GPO.
  3. Select an existing GPO from the list.
  4. Click Download… to download the installation files for the Client.
    1. In the dialog box, click Download Files.
    2. When the dialog box is complete, click OK.
  5. You can create a new share or select an existing share. To select an existing share you must copy the Client Side Extension msi-package into the appropriate share.
    The files can be copied from C:\temp\SpecopsPasswordPolicy_Setup[VersionNumber]\products\specopspasswordpolicy
  6. Click Select Share.
  7. Browse to the location of the network share, or enter the location of the share name.
    It is recommended that you use a Distributed File Share (DFS). If DFS is used with load balancing, verify that the setup files are copied to all servers before proceeding.
  8. To upgrade the packages for x86 and x64 deployments in the selected GPO, click Add Settings.
    The Client Side Extension MSI will be deployed through a computer software installation and may not take effect until the computers have been restarted.


If you are not deploying using GPSI, you can update the Client Side Extension using other deployment tools.

If you are upgrading to the latest version of the Client from version 6.3 or lower, and have previously made configuration changes using the ADMX/ADML template, such as configured the notification interval, you will need to manually migrate your settings. For more information, see Configuring the Client from the Administrative Template.


Congratulations! You have successfully upgraded all of the components. Please complete the following tasks once you have upgraded to the latest version of Specops Password Policy:

  1. Open the Specops Password Policy Domain Administration tool.
    1. Enter your new license key.
    2. Verify that the Password Policy Sentinel State on your domain controllers displays the new version of the Sentinel.
    3. Select Language files, and view the status of the files. The status should read OK. If there is a new version available, you will need to click Update Language Files.
  2. If you are using Specops Password Policy and the passphrase feature with Specops Password Reset, users using the mobile application will need to install the latest updates in order to use the passphrase feature.