Password Policy Events Table

Hello Experts,

I am troubleshooting an issue where password policies that used to be deployed and working in an environment all of the sudden all have vanished (at least not showing in PMAdmin), other configuration settings are still present but password policies have vanished from all domains. We are using version 5.8.2.1831 of password manager. I am trying to find the table where password policies are stored and also table that would show any changes that have been done to password policies but not finding that information in documentation, could someone please point me to the docs or provide the name of the tables?

Thanks,

Sergei

Parents
  • Hi Sergei,

    Password Manager policies are actually real Group Policy Objects (GPOs) that reside in Active Directory.

    If they disappeared, chances are that an AD Administrator deleted them in the Group Policy Management tool. 

    Since they're encrypted GPOs, anyone looking at them in the native Group Policy Management tool would think they're empty because the data cannot be displayed. The only way to read the data is via Password Manager Admin site (/PMAdmin). In addition, the Password Policy Manager component that gets installed on the DCs decrypts it when users change their passwords and enforces the settings in that policy.

    I would recommend asking your AD team if anyone has deleted any "empty" GPOs that start with "QuestGPC".

    Kind regards

    Daniel

  • Daniel,

    Thank you so much for your reply! I have a follow up question, is there an industry standard or rather best practice solution to prevent the removal of GPOs for Password Manager, for example maybe a setting for accidental deletion or something like that. Basically trying to find out if there is a One Identity recommendation for how to prevent the removals of these GPOs since they are stored in AD?

    Thank you in advance for your help.

    Thanks,

    Sergei  

Reply
  • Daniel,

    Thank you so much for your reply! I have a follow up question, is there an industry standard or rather best practice solution to prevent the removal of GPOs for Password Manager, for example maybe a setting for accidental deletion or something like that. Basically trying to find out if there is a One Identity recommendation for how to prevent the removals of these GPOs since they are stored in AD?

    Thank you in advance for your help.

    Thanks,

    Sergei  

Children