IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  - Infomap - Change Password to Federated AD

    Posted Tue December 01, 2020 03:09 PM
    Hi everybody,
    we are using ISAM 9.0.7.2 with an LDAP and AD Federated (Basic Users).
    My question is: can we leverage the use of the UsernameLookupHelper/User classes to perform a change password operation on AD?

    If not, i believe the only way to achieve this would be to upgrade to ISVA 10 and use the new NativeLdap Helper class, or do you know if there is another way?




    Thanks.
    Regards,

    ------------------------------
    Ivan Gerardini
    ------------------------------


  • 2.  RE: - Infomap - Change Password to Federated AD

    Posted Wed December 02, 2020 05:42 AM
    Hi Ivan,

    I don't know for sure but I think that it should be possible to perform a change password operation using the UserLookup Helper as long as it is initialized to use the "ISAM Runtime" configuration.  This is done by:
     - Making sure your primary LDAP bind-dn and pw are included in ldap.conf (placeholders exist.  data is obfuscated on save)
     - Initializing the helper with .init(false)

    Perhaps someone else who has done this can confirm?

    Jon.

    ------------------------------
    Jon Harry
    Consulting IT Security Specialist
    IBM
    ------------------------------



  • 3.  RE: - Infomap - Change Password to Federated AD

    Posted Sun December 13, 2020 01:45 AM
    Hi Ivan,

    I have the same requirement to reset the AD password which is federated with ISAM by enabling the forgot password link over ISAM login page.

    Is that worked for you?
    If yes, Can you please let me know how to do it?




    ------------------------------
    Prashant Narkhede
    ------------------------------



  • 4.  RE: - Infomap - Change Password to Federated AD

    Posted Mon January 04, 2021 11:14 AM
    Did you solved that?


    ------------------------------
    Karol Soniecki
    ------------------------------



  • 5.  RE: - Infomap - Change Password to Federated AD

    Posted Mon January 04, 2021 10:43 PM
    Hi Karol,

    Yes, It worked for me without creating any custom InfoMap.

    The must thing you need to do is to configure the Federated AD with SSL and you should able to change the password for federated AD users via Policy Administration.

    Once the above works, you can configure the SCIM pointing to the federated AD and use the out of the box provided User Self Care InfoMaps for Forgot Password scenarios.

    Regards,
    Prashant Narkhede



    ------------------------------
    Prashant Narkhede
    ------------------------------



  • 6.  RE: - Infomap - Change Password to Federated AD

    Posted Mon December 30, 2024 10:20 AM

    Hello Prashant, 

    I have the same requirement to have a forgot password link on the ISVA login page and it is federated with multiple Azure AD as well on prem AD. Kindly need your help with how to achieve this. do you have any documents or any hints?

    vselvambal.c@tetco.sa



    ------------------------------
    VIJAYABASKAR BALASUBRAMANIAN
    ------------------------------



  • 7.  RE: - Infomap - Change Password to Federated AD

    Posted Thu March 20, 2025 09:13 AM
    Edited by Kamil Majchowski Sat March 22, 2025 09:53 AM

    Hello Prashant and everyone,

    I know it's been a few months since the last update, but I stumbled upon this thread while researching a similar issue. I'm currently working on implementing a "forgot password" functionality for an ISVA login page federated with multiple Azure AD and on-prem AD environments.

    Prashant, your suggestion about configuring Federated AD with SSL and using SCIM with out-of-the-box User Self Care InfoMaps sounds promising. Did you manage to document the process or encounter any specific challenges along the way? If anyone else has additional insights or resources to share, I'd greatly appreciate it!

    Thanks in advance for your help.



    ------------------------------
    Kamil Majchowski
    ------------------------------