Skip to content
IAM built for the AI-Era

Dynamic Feedback at Password Change

With Dynamic Feedback at Password Change in Specops Client, users receive real-time feedback on password requirements when changing their passwords with Specops Password Policy or Specops uReset.

On Active Directory domain-joined computers, Specops Client displays this feedback during password changes through Ctrl+Alt+Del or the Windows Start menu. On Entra ID-joined computers, users access a browser-based password change flow through a shortcut, with or without Specops Client.

Note

Dynamic Feedback at Password Change is not supported when authenticating with RSA SecurID or if the Group Policy setting Interactive Logon: Do not display last username is set to Enabled.

Configuration for Active Directory-joined Computers

Dynamic Feedback at Password Change uses the computer’s credentials to resolve and read the applicable password policy. Ensure that affected computer accounts have read access to the following:

  • The Default Domain Policy and, when using Specops Password Policy, the applicable Specops Password Policy.
  • When Fine-Grained Password Policies are used, the user objects, the Password Settings Container and its policies (CN=Password Settings Container, CN=System, DC=acme, DC=org), and the msDS-PSOApplied and msDS-ResultantPSO attributes on user objects.

Configuration for Entra ID-joined Computers

On Entra ID-joined computers, the Dynamic Feedback at Password Change add-on uses the Specops Authentication platform to provide feedback in a web browser.

Users verify their identity using a Trusted Network Location and a One-Time Password (OTP) sent via SMS or Corporate Email, followed by their password. They can then change their password with guidance from a traffic light system.

To use the add-on, you need a Gatekeeper and the required Admin and Change Password policy settings configured in Specops Authentication Web. You must also configure a policy in Intune for the Change Password options. Contact your account manager to enable the add-on.

To configure the Dynamic Feedback add-on:

  1. Make sure you have installed the Gatekeeper Administration Tool and configured the Gatekeeper, see Gatekeepers.
  2. Optionally, install Specops Client and deploy it using Intune, see Specops Client Installation.
  3. If using Specops Client, import the ADMX templates for Entra ID-joined computers into Intune, see ADMX templates.
  4. Configure an Intune policy to disable the Windows Change password option in the Ctrl+Alt+Del menu. If using Specops Client, enable its Change password shortcut in the Start menu and configure the password change URL, see Configure Entra ID-joined Computers.

    Note

    The add-on can be used without the Specops Client by deploying a Change password shortcut directly to the desktop.