sparkeh Posted December 21, 2012 Posted December 21, 2012 Ok this is probably a stupid question but here goes: I am setting up Google Apps and have AD sync setup and working. I have tested with a few users and they have been created successfully, however, I can't seem to work out how I retrieve their passwords. Their user record just says that the password was set by the user, their new user instructions says the password was set by the admin. The bulk download doesn't have this info. I can reset their passwords easily enough but with about 700 users to provision this isn't a way forward. I guess I am missing something very obvious?
CyberNerd Posted December 21, 2012 Posted December 21, 2012 I guess I am missing something very obvious? Single Sign On ?
sparkeh Posted December 21, 2012 Author Posted December 21, 2012 Single Sign On ? This is further down the road, just want to get a test group on at the moment.
sparkeh Posted December 21, 2012 Author Posted December 21, 2012 I left the default password blank in GAPS so a random one is generated but you can't seem to retrieve it. Now to set to provide a default password and force them to change on initial login.
SPM Posted December 22, 2012 Posted December 22, 2012 You shouldn't be able to retrieve user passwords - that would not be a secure way of running things. The way passwords work is that only the user knows his/her password. If others can get hold of the password (and that includes the sys admin) then you can no longer identify the person logging is the person who they claim to be by his/her password. You can reset the password and send it to the user to log in and change password - this ensures that the sys admin cannot get hold of a user's password and masquerade as that user.
sparkeh Posted December 23, 2012 Author Posted December 23, 2012 You shouldn't be able to retrieve user passwords - that would not be a secure way of running things. The way passwords work is that only the user knows his/her password. If others can get hold of the password (and that includes the sys admin) then you can no longer identify the person logging is the person who they claim to be by his/her password. You can reset the password and send it to the user to log in and change password - this ensures that the sys admin cannot get hold of a user's password and masquerade as that user. Well the sysadmin should be able to get new users passwords to distribute without having to reset them. That's how it usually works. So what's the difference between these two scenarios: I bulk upload my users, I get the initial passwords, I hand them out, users login and are forced to change their passwords. I no longer know their passwords. I bulk upload my users with a generic initial password, they login and are forced to change their password. I no longer know their password. Actually scenario one is more secure as only I have access to the initial passwords, with scenario two anybody could log into anyone's else account before them as they know the generic initial password. 1
morganw Posted December 23, 2012 Posted December 23, 2012 You might find it more flexible to make your own solution with Google Apps Manager as it sounds like it's the restrictions of the sync tool that you have issue with. BulkOperations - google-apps-manager - Dito GAM - Google Project Hosting 1
CyberNerd Posted December 23, 2012 Posted December 23, 2012 Well the sysadmin should be able to get new users passwords to distribute without having to reset them. That's how it usually works. I appreciate you are planning Single Sign On later, so when you roll it out to everyone you won't need to distribute passwords at all. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now