and more in a single search tool across platforms. Read the announcement here. |
11/08/2023 04:21 AM
Does saviynt store password for accounts somewhere. Like if we have a password policy for not to use last 4 passwords, how does saviynt comply to this policy ?
If it stores the passwords to manage history, what is the encryption method.
The temporary password used to "create account" or "change password" .. where is it stored? .. does it get deleted post account creation?
11/08/2023 04:58 AM
Saviynt stores the passwords in the encrypted format using the bcrypt alogorithm.
Refer the below forum threads
11/08/2023 05:15 AM
@SumathiSomala The articles you shared and I read in other places covers the password for "Service account" used in connector .. and "user credentials" ( local authentication password) ..
No where it gives a clear understanding upon password for accounts on endpoints. My question is primarily for accounts on endpoints. When we create the account, saviynt use a temporary password to create account, does that password get stored in Saviynt? or when we change password for an account ..does that get stored?
11/08/2023 09:01 PM
In both cases password is stored in arstasks table
11/16/2023 08:05 AM
As per my understanding, password stored in arstasks table is Temporary, and should be removed post email notification is sent (notification that is linked with endpoint).
My question is: does Saviynt store password permanently for application accounts.
also for the feature of password history in "password policy" .. does saviynt store password .. or it stores hash to compare against the new password.
11/16/2023 10:15 PM
Saviynt needs to store password to compare in future but it will be hashed