The goal of this guide is to provide a step-by-step walk through of how-to setup Real Time Password Synchronization for user objects between your On-Premises Active Directory environments. Directory Sync will monitor source Active Directory password changes in real time and synchronize the changes to matched or newly created user objects in the target Active Directory.
To set up Directory Sync for Real Time Password Synchronization, source user objects must be matched to existing or newly created user objects in the target environment. To accomplish this, four (4) configurations must be completed prior to the first synchronization.
Set up Environments
Set up Local Agents
Set up Templates
Set up Workflows
The next section will provide the list of requirements needed to successfully Synchronization Password between two Active Directory environments.
In order to facilitate the Real Time Password Synchronization, the following is a list of minimum requirements to get set up using Directory Sync with your On-Premises Active Directory.
ADMIN$ must be accessible on the domain controller from the Directory Sync agent server.
Any third-party anti-virus program that prevents access the LSASS process may need to be updated with a whitelist entry for the Password Sync executable.
One (1) Local Administrator Account for each Microsoft Forest and/or Domain that has permissions to create, update or delete depending on the scope of your Directory Sync workflows.
The Password Sync functionality requires that either a domain admin role or built-in admin role be granted to the service account.
The next section will provide a step-by-step guide on how to set up Password Synchronization for Active Directory environments.