# Password Expiry for LDAP users

**URL:** <https://forum.keycloak.org/t/password-expiry-for-ldap-users/27333>\
**Category:** Getting advice\
**Tags:** ldap\
**Created:** [August 6, 2024, 4:16am UTC](https://forum.keycloak.org/t/password-expiry-for-ldap-users/27333 "2024-08-06T04:16:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![keaz](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/keaz/32/7607_2.png) [@keaz](https://forum.keycloak.org/u/keaz)\
**Post date:** [August 6, 2024, 4:16am UTC](https://forum.keycloak.org/t/password-expiry-for-ldap-users/27333/1 "2024-08-06T04:16:02Z")

</div>

I’m trying to configure password expiry in Keyloack. But my data source is LDAP. Is it possible to configure password expiry for federated data sources like LDAP?

---

<div class="post-metadata">

**Author:** ![lamoboos223](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/lamoboos223/32/9748_2.png) [@lamoboos223](https://forum.keycloak.org/u/lamoboos223)\
**Post date:** [August 6, 2024, 9:02am UTC](https://forum.keycloak.org/t/password-expiry-for-ldap-users/27333/2 "2024-08-06T09:02:37Z")

</div>

I haven’t tested it, but I think yes since the data is provisioned from and to keycloak. I will test it locally and get back to you.

@keaz

---

<div class="post-metadata">

**Author:** ![djordje](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/djordje/32/10815_2.png) [@djordje](https://forum.keycloak.org/u/djordje)\
**Post date:** [August 6, 2024, 9:33am UTC](https://forum.keycloak.org/t/password-expiry-for-ldap-users/27333/3 "2024-08-06T09:33:05Z")

</div>

I would say no, or maybe you can implement some custom provider that will do password check but I think it is not possible by default. When you implement custom user federation, you have to do it manually because method isValid is calling external service for password check.  
Let’s see what @lamoboos223 says after testing.

---

<div class="post-metadata">

**Author:** ![lamoboos223](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/lamoboos223/32/9748_2.png) [@lamoboos223](https://forum.keycloak.org/u/lamoboos223)\
**Post date:** [August 7, 2024, 1:44am UTC](https://forum.keycloak.org/t/password-expiry-for-ldap-users/27333/4 "2024-08-07T01:44:20Z")

</div>

I’m sorry @keaz I couldn’t manage to pull it off.

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [August 7, 2024, 7:41am UTC](https://forum.keycloak.org/t/password-expiry-for-ldap-users/27333/5 "2024-08-07T07:41:00Z")

</div>

A quick look into the source code will you, that the password policies are not taken into account when validating the password. Only during update of a password and if you enabled the usage of Keycloak password policies in your LDAP config.

---

<div class="post-metadata">

**Author:** ![keaz](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/keaz/32/7607_2.png) [@keaz](https://forum.keycloak.org/u/keaz)\
**Post date:** [August 9, 2024, 3:08am UTC](https://forum.keycloak.org/t/password-expiry-for-ldap-users/27333/6 "2024-08-09T03:08:12Z")

</div>

Thank you all for the response. I created a custom authenticator for this. For now, this is working for direct grant flow and I’m trying to get this to work for Browser flow.
