msDS-UserPasswordExpiryTimeCompute d

Hi all,

is there a way to import the value of the "msDS-UserPasswordExpiryTimeComputed" attribute in Active Directory MA ?

The value is present in ADUC but in Import flow it is null.

June 3rd, 2015 4:43am

It is computed attribute, so it wont flow by design.

If you need to use it for password expiration workflow or something, you could check http://social.technet.microsoft.com/wiki/contents/articles/2171.understanding-password-expiration-notifications-in-fim-2010.aspx - there are some very helpful comments down the article.

Free Windows Admin Tool Kit Click here and download it now
June 4th, 2015 2:59am

It is computed attribute, so it wont flow by design.

If you need to use it for password expiration workflow or something, you could check http://social.technet.microsoft.com/wiki/contents/articles/2171.understanding-password-expiration-notifications-in-fim-2010.aspx - there are some very helpful comments down the article.

  • Proposed as answer by Vladimir Zanadvorov Thursday, June 04, 2015 6:57 AM
  • Marked as answer by ADelon 14 hours 34 minutes ago
June 4th, 2015 6:57am

It is computed attribute, so it wont flow by design.

If you need to use it for password expiration workflow or something, you could check http://social.technet.microsoft.com/wiki/contents/articles/2171.understanding-password-expiration-notifications-in-fim-2010.aspx - there are some very helpful comments down the article.

  • Proposed as answer by Vladimir Zanadvorov Thursday, June 04, 2015 6:57 AM
  • Marked as answer by ADelon Thursday, June 04, 2015 4:49 PM
Free Windows Admin Tool Kit Click here and download it now
June 4th, 2015 6:57am

It is computed attribute, so it wont flow by design.

If you need to use it for password expiration workflow or something, you could check http://social.technet.microsoft.com/wiki/contents/articles/2171.understanding-password-expiration-notifications-in-fim-2010.aspx - there are some very helpful comments down the article.

  • Proposed as answer by Vladimir Zanadvorov Thursday, June 04, 2015 6:57 AM
  • Marked as answer by ADelon Thursday, June 04, 2015 4:49 PM
June 4th, 2015 6:57am

Thank you Vladimir,

I wanted to import "msDS-UserPasswordExpiryTimeComputed" because we have FGPP and I want that the notification will be relevant.
So what I done as workaround :
- A powershell script that export to a csv the samaccountname, the msDS-UserPasswordExpiryTimeComputed and calculate the days to expiry.
- create a new MA "delimited text file" and import the  msDS-UserPasswordExpiryTimeComputed and daystoexpiry to MV.

Free Windows Admin Tool Kit Click here and download it now
June 4th, 2015 12:50pm

Cool :)

You probably can wrap that powershell into an action workflow inside of fim while computing required attributes to get rid of an extra MA.

June 5th, 2015 2:25am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics