AD password rotation: rotate passwords through an agent you run
Rotation in VaultPilot applies to Active Directory credential records only. A connected DC Agent generates the new password, sets it in AD and returns it encrypted to a VaultPilot public key. An authorized browser with the vault unlocked then writes it into the encrypted record.
- Applies to
- AD credential records
- Schedules
- Daily, weekly, monthly, custom
- Missed runs
- Not replayed in bulk

A rotation policy on each record
The Configure rotation action on an Active Directory record sets a daily, weekly, monthly or custom schedule in the time zone you pick. A custom interval is 1 to 365 days, 1 to 52 weeks or 1 to 12 months and needs a start date. A daylight-saving change never creates the same run twice.
Four account actions
With a writable license, an Owner can queue these actions for a resolved Active Directory user through a connected agent that reports the matching capability. Each one asks for confirmation and joins a queue instead of finishing on the spot.
Protected and privileged targets
Built-in identities and the agent's bind identity are always blocked, and both the server and the agent enforce this. Other privileged targets need a second confirmation for a manual action. Automated rotation on such a target needs a durable approval stored on the policy, and turning the policy off clears it.
The Rotation dashboard only ranks
The Rotation dashboard sorts credential records into age bands and shows directory action counts. It schedules nothing, generates no password and changes no account. To act, open the policy from its record.
Agent result and vault update are separate
After the agent resets a password in AD, the vault record changes only when a browser can decrypt the returned value and write it back. Check the agent result, the record update notice and the audit trail together. If they disagree, treat the AD password as changed and stop before any retry.
Limits to know
- API keys, website passwords and other non-AD records are not rotated.
- The DC Agent cannot read an existing AD password, so a freshly imported record starts without one.
- Restoring an older record revision changes only the vault record, not the AD password.
Check step by step
Read more in the guides: Active Directory records screen, Rotation dashboard screen, Executions screen, Server settings screen: password policy