A. Yes, the PCNS software must be installed on all DCs in the domain whose passwords should be captured for transmission to Identity Lifecycle Manager or the Identity Integration Feature Pack.
- Q. How do I exclude users from my domain-password policy, and can I exclude those same users from domain-policy read-and-apply permissions?
- Q. Can I sync the Directory Services Restore Mode (DSRM) password with the password of another account on a one-time basis?
- Determining the Expiration of AD Domain Passwords
- Windows Server 2008’s Fine-Grained Password Policies
Check out hundreds more useful Q&As like this in John Savill's FAQ for Windows. Also, watch instructional videos made by John at ITTV.net.