[keycloak-dev] Require password change on login when AD is the federation provider and pwdLastSet equals 0

Cory Snyder csnyder at iland.com
Mon Sep 14 10:05:12 EDT 2015


With Active Directory, a user is required to change their password on next login if the pwdLastSet attribute on their account is set to zero. It would be nice to redirect the user to a form where they can change their password if they try to login under this scenario. On Keycloak 1.4 it seems that the application currently just displays a login error when this is the case. Any thoughts on this or can I go ahead and create an issue and try to implement this change?

Thanks,

Cory Snyder
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.jboss.org/pipermail/keycloak-dev/attachments/20150914/957fc7db/attachment.html 


More information about the keycloak-dev mailing list