Solved

Can a secret question and answer be stored in Active Directory (Server 2008 R2) for self service password reset (Forgotten Password)?

Posted on 2010-08-19
3
1,809 Views
Last Modified: 2013-11-05
We are developing a web site that uses Active Directory security.  We would like to store all information pertaining to users authentication credentials in Active Directory.  I have seen many references to ASP.Net Active Directory security model in the .Net framework classes.  In order to make password resets self service we would like to use the secret question and answer method to allow users to reset their password if they can answer the secret question correctly.  Is this ability native to Active Directory, or would we have to modify the schema to allow this?
0
Comment
Question by:jwright2375
3 Comments
 
LVL 4

Accepted Solution

by:
illhelpu earned 500 total points
ID: 33476659
Check this article out, it should help you out.

http://technet.microsoft.com/en-us/library/cc720655%28WS.10%29.aspx
0
 

Author Comment

by:jwright2375
ID: 33484598
Thank you very much for your suggestion illhelpyou.  In the newest version Forefront Identity Manager, we would have to install SharePoint in the DMZ, which is not an option right now.  We want to develop a lightweight solution.  If Active Directory cannot handle this natively, we have planned to store the old secret question and answer information in SQL Server with a salt and hash.  I so hoped it was built into AD 2008, but it looks like to build the functionality in, we will have to install and manage 2 additional server products.  Wow, that seems like a lot more work than we can handle.
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

More often than not, we developers are confronted with a need: a need to make some kind of magic happen via code. Whether it is for a client, for the boss, or for our own personal projects, the need must be satisfied. Most of the time, the Framework…
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now