AD password rotation: rotate passwords through an agent you run

Rotation in VaultPilot applies to Active Directory credential records only. A connected DC Agent generates the new password, sets it in AD and returns it encrypted to a VaultPilot public key. An authorized browser with the vault unlocked then writes it into the encrypted record.

Applies to
AD credential records
Schedules
Daily, weekly, monthly, custom
Missed runs
Not replayed in bulk
Illustration of a directory agent enrolling next to the domain controller

A rotation policy on each record

The Configure rotation action on an Active Directory record sets a daily, weekly, monthly or custom schedule in the time zone you pick. A custom interval is 1 to 365 days, 1 to 52 weeks or 1 to 12 months and needs a start date. A daylight-saving change never creates the same run twice.

Four account actions

With a writable license, an Owner can queue these actions for a resolved Active Directory user through a connected agent that reports the matching capability. Each one asks for confirmation and joins a queue instead of finishing on the spot.

Protected and privileged targets

Built-in identities and the agent's bind identity are always blocked, and both the server and the agent enforce this. Other privileged targets need a second confirmation for a manual action. Automated rotation on such a target needs a durable approval stored on the policy, and turning the policy off clears it.

The Rotation dashboard only ranks

The Rotation dashboard sorts credential records into age bands and shows directory action counts. It schedules nothing, generates no password and changes no account. To act, open the policy from its record.

Agent result and vault update are separate

After the agent resets a password in AD, the vault record changes only when a browser can decrypt the returned value and write it back. Check the agent result, the record update notice and the audit trail together. If they disagree, treat the AD password as changed and stop before any retry.