4.4 Configuring the Password Self-Service Feature

The User Application Roles Based Provisioning Modules comes with a feature that allows users to change a password that was forgotten. This reduces the number of help desk calls and frees time and resources to be used on other tasks.

Password self-service is installed when the User Application Roles Based Provisioning Module is installed. However, you must configure the password policy to use a challenge set of questions for a user when he or she needs to change a password.

  1. In iManager, click Roles and Tasks > Passwords > Password Policies.

  2. To edit the policy, click the name of the password policy you created in Section 4.2.1, Creating the Password Policy.

  3. Click the Forgotten Password tab.

  4. Select Enable Forgotten Password.

  5. Select Require a challenge set.

  6. Click Challenge Sets to create a new challenge set.

  7. Click New, then use the following information to create a challenge set:

    Challenge set name: Specify a name for the challenge set.

    Create in container: Accept the default location where the challenge set is created in the Password Policy container in the Security container.

    Required Questions: Select which questions a user is required to answer when changing a password. You can have required questions and random questions that are presented to the user.

    You can change whether a question is a required question or a random question by clicking on the question, then changing the question type. You can define your own questions or use one of the default questions. The default questions are:

    • What is your mother’s maiden name?

    • What is your User ID?

    • What is your PIN?

    • What is your childhood pet’s name?

    Number of random questions to ask user when password is forgotten: Specify the number of random questions presented to a user.

  8. Click OK.

  9. Click Close.

  10. Browse to and select the new challenge set you created.

  11. Select Allow user to reset password (Requires a challenge set and the Universal Password option).

  12. Select Force user to configure Challenge Questions and/or Hint upon authentication.

  13. Click OK.

  14. Verify that the password policy is assigned to the container where the user objects reside.

    The password policy is not enforced unless it is assigned. For more information, see Section 4.2.3, Assigning the Password Policy.