Dynamic Feedback at Password Change
With Dynamic Feedback at Password Change in Specops Client, users receive real-time feedback on password requirements when changing their passwords with Specops Password Policy or Specops uReset.
On Active Directory domain-joined computers, Specops Client displays this feedback during password changes through Ctrl+Alt+Del or the Windows Start menu. On Entra ID-joined computers, users access a browser-based password change flow through a shortcut, with or without Specops Client.
Note
Dynamic Feedback at Password Change is not supported when authenticating with RSA SecurID or if the Group Policy setting Interactive Logon: Do not display last username is set to Enabled.
Configuration for Active Directory-joined Computers
Dynamic Feedback at Password Change uses the computer’s credentials to resolve and read the applicable password policy. Ensure that affected computer accounts have read access to the following:
- The Default Domain Policy and, when using Specops Password Policy, the applicable Specops Password Policy.
- When Fine-Grained Password Policies are used, the user objects, the Password Settings Container and its policies (CN=Password Settings Container, CN=System, DC=acme, DC=org), and the
msDS-PSOAppliedandmsDS-ResultantPSOattributes on user objects.
Configuration for Entra ID-joined Computers
On Entra ID-joined computers, the Dynamic Feedback at Password Change add-on uses the Specops Authentication platform to provide feedback in a web browser.
Users verify their identity using a Trusted Network Location and a One-Time Password (OTP) sent via SMS or Corporate Email, followed by their password. They can then change their password with guidance from a traffic light system.
To use the add-on, you need a Gatekeeper and the required Admin and Change Password policy settings configured in Specops Authentication Web. You must also configure a policy in Intune for the Change Password options. Contact your account manager to enable the add-on.
To configure the Dynamic Feedback add-on:
- Make sure you have installed the Gatekeeper Administration Tool and configured the Gatekeeper, see Gatekeepers.
- Optionally, install Specops Client and deploy it using Intune, see Specops Client Installation.
- If using Specops Client, import the ADMX templates for Entra ID-joined computers into Intune, see ADMX templates.
-
Configure an Intune policy to disable the Windows Change password option in the Ctrl+Alt+Del menu. If using Specops Client, enable its Change password shortcut in the Start menu and configure the password change URL, see Configure Entra ID-joined Computers.
Note
The add-on can be used without the Specops Client by deploying a Change password shortcut directly to the desktop.