Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-7269: How to force an AD user to re-authenticate for every dzdo operation

Authentication Service ,  

8 August,16 at 08:31 PM

Applies to:

All versions of Centrify DirectControl on all supported platforms


Is there a way to require an AD user to re-authenticate for every operation which 
dzdo is used?


dzdo.timestamp_timeout parameter in /etc/centrifydc/centrifydc.conf will specify how many minutes between operations which dzdo does not need to re-authenticate. Changing the value of dzdo.timestamp_timeout to 0 will result in AD users being prompted for re-authentication for every dzdo operation.


#dzdo.timestamp_timeout: 5

dzdo.timestamp_timeout: 0

Parameter can also be applied with the following group policy:
 Controlled by group policy under the settings
      "Computer Configuration"
      -> "Centrify Settings"
         -> "DirectControl Settings"
            -> "Dzdo Settings"
               -> "Set dzdo authentication timeout interval"

For additional information on the use of these parameters, please refer to our official 'Configuration and Tuning Refrence Guide' which can be found via: