Impersonation Account Password Maintenance on the Calendar Connector- Webex
For the Hybrid Services > Calendar Services > Microsoft Exchange Configuration, you are required to keep a working password at all times. This step is essential to ensuring the smooth running of the service. The password of the impersonation account is routinely used by the calendar connector as part of the authentication process whenever it engages in conversation with Active Directory domain controllers or Exchange Client access servers.
Take into consideration the following to lower the likelihood of a service interruption brought on by an invalid password:
- When the password’s expiration date arrives, the calendar connector will not send out a warning. Be mindful of the password policy for any impersonation accounts you use, particularly the time period during which the password is valid. Make sure that the password for the account that is being used to impersonate someone is changed well in advance of the date on which the password will become invalid.
- When conducting any change to the password for the impersonation account (whether it be due to its impending expiration or another reason), you are required to coordinate the manual update of the Microsoft Exchange Configuration for the Calendar Service to coincide with the change in the password in Active Directory. Failing to do so will result in the impersonation account not being able to be used. In the following circumstances, it is possible that the Calendar Service will be unable to carry out its duties:
-
- In the event that the password for the Microsoft Exchange Configuration record is changed before the new password has been applied to Active Directory and Exchange, the old password will continue to be used.
- In the event that the previous password stops working before you update the password for the Microsoft Exchange Configuration record.
-
- It is not always instantaneous to propagate a new password throughout Active Directory and Exchange, especially in larger businesses. After changing the password for the impersonation account, there is a possibility that some users will experience a temporary disruption in service.
Due to these factors, we strongly advise that you set up two impersonation accounts for the Calendar Service that are completely identical to one another, with expiration dates that are spaced out.
An Example Password Rotation Strategy
In this particular illustration, the length of time until a password for calaccountA@example.com or calaccountB@example.com becomes invalid is 180 days. The administrator decided to rotate the accounts every two months in order to be prudent with their spending. There is a possibility that the real password expiration term for your company is different.
January 1, 2017
Make two accounts using a different person’s identity, such as calaccountA@example.com and calaccountB@example.com.
Set up the accounts in accordance with the instructions provided in the documentation for the Hybrid Calendar Service.
Replace the password on both of these accounts.
Use calaccountA@example.com when configuring Microsoft Exchange Configuration for Hybrid Services > Calendar Services > Microsoft Exchange Configuration.
March 1, 2018
You need to update the password for the calaccountB@example.com email address.
March 8, 2018
Make the necessary changes to the Hybrid Services > Calendar Services > Microsoft Exchange Configuration so that calaccountB@example.com is used together with the new password that was chosen on March 1.
May 1, 2018
Make a new password for the account that starts with calaccountA@example.com.
May 8, 2018
Change the password for calaccountA@example.com in the Hybrid Services > Calendar Services > Microsoft Exchange Configuration so that it matches the new one that was set on May 1st.
July 1, 2018
You need to update the password for the calaccountB@example.com email address.
July 8, 2018
Change the password for calaccountB@example.com in the Hybrid Services > Calendar Services > Microsoft Exchange Configuration so that it matches the new one specified on July 1st.
Carry on with this practice of rotating the password.