Azure-docs: Clarification concerning password protection proxy

Created on 8 May 2019  Â·  3Comments  Â·  Source: MicrosoftDocs/azure-docs

I have looked over the documentation and the FAQ but there is one detail I'm not sure on which may be worth clarifying in the documentation.

For those of us with large on-prem AD forests, it is already quite an undertaking to install an agent on every DC, so how many proxy servers would it be reasonable to maintain? Are they redundant? And if for example, we only have 2 proxies and these are offline for a period of time (say over an hour) what will happen on the DC's if they can't poll for a new password policy? Will they simply continue using the last known downloaded policy?

Thanks


Document details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

active-directorsvc assigned-to-author authenticatiosubsvc product-question triaged

Most helpful comment

Hi @WhatsMyNameLol,

The proxy servers are stateless, so yes having two is just for redundancy. It is usually a non-event if the proxy server(s) are offline for hours or even a day or three. Please take a look at the following section of the docs:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-deploy#high-availability

To answer the question directly though: yes even if all registered proxy servers become unavailable, the DC Agents continue to enforce their locally cached password policy.

All 3 comments

@WhatsMyNameLol Thanks for your feedback! We will investigate and update as appropriate.

Hi @WhatsMyNameLol,

The proxy servers are stateless, so yes having two is just for redundancy. It is usually a non-event if the proxy server(s) are offline for hours or even a day or three. Please take a look at the following section of the docs:

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-deploy#high-availability

To answer the question directly though: yes even if all registered proxy servers become unavailable, the DC Agents continue to enforce their locally cached password policy.

Thank you @jay98014 for this explanation. We will now proceed to close this thread. If you have further questions feel free to tag us in the comments and we will gladly continue the discussion.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

smcd253 picture smcd253  Â·  44Comments

ManuelMos picture ManuelMos  Â·  46Comments

aspnet4you picture aspnet4you  Â·  50Comments

andersgidlund picture andersgidlund  Â·  45Comments

jlorek picture jlorek  Â·  46Comments