Planehazza Posted June 19, 2023 Posted June 19, 2023 Has anyone implemented Password Sync to sync AD password changes to Google Workspace? I've got it in, but having problems. If I reset the password on a DC via a domain admin account, it changes and syncs just fine. However, if the test user does it, I receive the windows password complexity message. I can confirm with 100% certainty that the password is meeting the GPO defined password complexity. Has anyone encountered this? the only step I haven't completed yet is the SSO profile that redirects users to a Google Site to tell them how to change their password, but this should have no bearing on the actual password sync process. Anyone been in my shoes?? Ready to give up on the project... Thanks, Harry
timbo343 Posted June 19, 2023 Posted June 19, 2023 Basic question, have you got Google Password Sync on all your DCs?
Planehazza Posted June 19, 2023 Author Posted June 19, 2023 I have indeed. With them all authorised with a service account and application security context. I have double checked my project settings and that the admin account is authorised to use the service account and all checks out. I suspect if any of this was wrong then I would not be able to change and sync test account password on the DC. We use Lightspeed so I'm wondering if that is causing a problem as I believe it installs itself as a proxy...
Planehazza Posted June 20, 2023 Author Posted June 20, 2023 (edited) Just built a VM without lightspeed agent and still have the same problem. If I reset the password for the test account on the DC, it works. If I make the test account change the password at next logon, it also works. However, if the test user simply presses ctrl alt del and 'change a password', it says the password isn't complex enough. I'm confirming with certainty that the passwords are unique, haven't been used, and matches the requirements. It's like the user don't have permission to change and sync the password. I need to find the logs to see if it's Google or AD breaking the chain... I've just asked a real user to change their AD password and they had no issue, and I've moved the test user outside of the Base DN scope for password sync, but it would NOT accept the password. Something very weird is going on... Edited June 20, 2023 by Planehazza
timbo343 Posted June 20, 2023 Posted June 20, 2023 You shouldn't have those issues as the agent on the DC recognizes the user change of password and pushes the hash up to Google. I've been thinking about this on and off for most of the morning but each avenue i go down, i come to a dead end.
David44 Posted June 20, 2023 Posted June 20, 2023 (edited) If the error when you attempt to change the password is in Windows then it's a Windows/AD issue. Google Password Sync can actually change passwords on Google accounts so that they don't comply with the the password complexity rules you have set in Google. It just syncs the password from AD to Google, no questions asked and no checks made. Edited June 20, 2023 by David44
Planehazza Posted June 20, 2023 Author Posted June 20, 2023 If the error when you attempt to change the password is in Windows then it's a Windows/AD issue. Google Password Sync can actually change passwords on Google accounts so that they don't comply with the the password complexity rules you have set in Google. It just syncs the password from AD to Google, no questions asked and no checks made. Yeah that's what I understood it to be too, just confusing the hell out of me as to why it's not working for this test account. It'll turn out to be some horrific, non related coincidence, I'm sure
Planehazza Posted June 20, 2023 Author Posted June 20, 2023 (edited) Urgh, think I may have sussed it, and if correct, it's really f***ing annoying. Stand by... EDIT: in the default policy at root level we have our password policy set, and minimum age for changing is 1 day. I coincidentally changed my admin password at 4PM yesterday and I cannot change my password today either. I've change it to 0 days and still no luck but I suspect the policy hasn't updated yet. EDIT2: Yep. Just done a live test with a friendly member of staff whose password was change more than 24 hours ago and it worked perfectly. So password sync is working for accounts within my test OU, just now need to get the SSO profile to come out of 'Draft' status so I can apply it to the Google OUs so that any google password change attempts redirect to a instructional site I have created. Any ideas on why it's still 'Draft' status 24 hours later? Edited June 20, 2023 by Planehazza
fiza Posted June 21, 2023 Posted June 21, 2023 I may need to utilise Google password sync shortly. Any instructions and gotchas that you have would be greatly appreciated.
Planehazza Posted June 25, 2023 Author Posted June 25, 2023 I may need to utilise Google password sync shortly. Any instructions and gotchas that you have would be greatly appreciated. It's very simple to install and set up; it's only time consuming if you have many DCs. The only caveat is the way that it means users can no longer change their password via their google account settings, but for most this is absolutely no problem. Tell me 5 people at your school that proactively change their passwords without being made to... The SSO profile bit for the change password redirect URL is a bit fiddly and I couldn't get it to work. The Google Password Sync documentations says you can assign it to the organisation SSO settings OR you can create profiles and assign them to OUs, but the latter wouldn't work and the google lad wasn't really that helpful, so I ended up just applying it at org level. Again, not a problem as people with password change admin rights (teachers and SLT at my schools) can still reset forgotten google passwords for students anyway. The documentation for the most part is pretty good and will give you the CLI to create and set up the project. It's a lot more straight forward to set up than GCDS was and that wasn't really too bad. Whilst your in the Google Cloud Console setting this stuff up, take a look at GAM. It's a third party CLI tool, a bit like PowerShell for O365, but not as powerful. 1
ktntech2 Posted February 15, 2025 Posted February 15, 2025 Hello, please can I ask did you resolve the 'Draft' status issue? Thank you for your help Urgh, think I may have sussed it, and if correct, it's really f***ing annoying. Stand by... EDIT: in the default policy at root level we have our password policy set, and minimum age for changing is 1 day. I coincidentally changed my admin password at 4PM yesterday and I cannot change my password today either. I've change it to 0 days and still no luck but I suspect the policy hasn't updated yet. EDIT2: Yep. Just done a live test with a friendly member of staff whose password was change more than 24 hours ago and it worked perfectly. So password sync is working for accounts within my test OU, just now need to get the SSO profile to come out of 'Draft' status so I can apply it to the Google OUs so that any google password change attempts redirect to a instructional site I have created. Any ideas on why it's still 'Draft' status 24 hours later?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now