Identity Director Administration Guide
This is not the latest version of Identity Director documentation.View available documentation.
Configure Password Reset
At Setup > Login Page Services > Password Reset, enable users to reset their Active Directory password. This reduces the number of help desk password tickets and enhances productivity of the user. Users can reset their Active Directory password from the Microsoft Windows logon screen, or from the Identity Director Web Portal or Mobile client logon page, either via a wizard or via service delivery.
- You can add code validation to password resets. This adds an extra check to authenticate the identity of the user who requests a password reset: a verification code is sent to the user e.g. by SMS or e-mail. Users then need to provide this verification code before they can proceed with a password reset. This ensures that passwords are reset as secure as possible.
- Using organizational context, you can define to whom the Verification Code and/or Security Questions apply.
- You can configure password complexity policies based on regular expressions, to ensure that passwords provided by your users meet the complexity requirements of your organization.
- You can add translations for the labels and messages that appear to end users in the Web Portal.
- The availability of this functionality may be subject to the license type used in your environment.
- See Ivanti Identity Director Password Reset Guide for more information and scenarios.
Configuration
General tab
Field |
Explanation and Tips |
---|---|
Password reset settings |
Specify the availability of the password reset functionality.
|
Reset link text |
Specify the text of the password reset link. |
People identifier |
Specify the identification method of users when they request a password reset. |
Service |
Specify the service that is delivered as part of the password reset (for example, the service Reset password based on user input that is provided with the Identity Director Password Reset Guide). |
User instructions |
Specify instructions when users click the password rest link. |
Status page message |
Specify status information. |
Redirection URL |
Specify a URL of choice after a password reset, rather than the default Web Portal sign-in page. In certain scenarios, for example when users access the Web Portal from a thin client, redirecting them to the default page may not be user-friendly. You can prevent this by specifying a different URL. |
Password input |
Specify if password input is provided through the wizard or through a service workflow. |
Password attribute |
Specify the service attribute that can store the password that the user provides.
|
Password complexity hints |
Configure a password complexity policy. This ensures that passwords provided by your users meet the complexity requirements of your organization.
|
Verification Code tab
Select organizational context |
Specify the Organization(s) or Organizational attribute(s) that determine if the Verification Code applies to a user.
|
Organizational context diagnostics |
After you specify organizational context, the first (max) 100 people that meet the conditions are listed here. |
Generating verification code message |
Specify status information that is displayed to the user about generation of the code. |
Enter verification code message |
Specify user instructions to validate the code.
|
Invalid verification code message |
Specify the message that is that is displayed to the user if the provided code is incorrect. |
Exceeding maximum number of attempts message |
Specify the message that is that is displayed to the user when he exceeds the limit. This field is only available if you have selected the option Limit number of attempts. |
Validating verification code message |
Specify status information about validation of the code. |
Security Questions tab
Field |
Explanation and Tips |
---|---|
Security questions |
Specify the number of questions in the wizard. If this number exceeds the number of questions and answers stored in a user's Security Questions and Answers attribute (see below), the user will get an error and cannot complete the Password Reset service. |
Questions attribute |
This field shows the default people attribute Security Questions and Answers that stores the security questions and answers of the wizard. The attribute can be filled using the User Validation Service you specify on the Login Page Services page.
|
Select organizational context |
Specify the Organization(s) or Organizational attribute(s) conditions that determine if the Security Questions apply to a user.
|
Organizational context diagnostics |
After you specify organizational context, the first (max) 100 people that meet the conditions are listed here. |
If you allow users to reset their password through a wizard, do not configure Active Directory to require a password change on next logon. This may lead to situations in which users can no longer sign in.
Translations tab
If you have enabled translations at Setup > Translations, you can add translations for the labels and messages that appear to end users in the Web Portal for password reset.
To add translations:
- Alongside the default language, click to export its RESX to use as the basis of translations for the other supported languages.
The name of this file is passwordresetsettings.resx. - Save a renamed copy of this file and translate it as required.
- Click to import the RESX of the language.
This ensures that custom labels are translated in the correct language.
Each supported language uses the default language if you do not upload a RESX file.
Click to reapply the default language.
Click to export the RESX of the language to make adjustments to the translation.
See also
- Example regular expression "Password Reset" functionality
- Configure people attributes
- Provide Verification Code
- Licensing
- Login Page Services
- Configure Unlock Account
Copyright © 2019, Ivanti. All rights reserved.