diff --git a/website/content/api-docs/secret/ldap.mdx b/website/content/api-docs/secret/ldap.mdx index 511d13194312..a2151ac719f6 100644 --- a/website/content/api-docs/secret/ldap.mdx +++ b/website/content/api-docs/secret/ldap.mdx @@ -170,6 +170,18 @@ The `static-role` endpoint configures Vault to manage the passwords of existing | `POST` | `/ldap/static-role/:role_name` | | `DELETE` | `/ldap/static-role/:role_name` | + + + Windows Servers hosting Active Directory include a + `lifetime period of an old password` configuration setting that lets clients + authenticate with old passwords for a specified amount of time. + + For more information, refer to the + [NTLM network authentication behavior](https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security new-setting-modifies-ntlm-network-authentication) + guide by Microsoft. + + + ### Parameters - `role_name` `(string: )` – URL parameter specifying the name of the