Skip to main content

Password Reset

Configuration · Password reset

Create the profile that connects the password reset App to account lookup, identity verification, and the actions that set a new password.

A password reset profile defines how a particular group of users moves through self-service recovery. The Self-Service Identity overview explains where password reset fits among NIM's user-facing workflows, while the Password Reset App explains the user experience. This page documents the profile settings behind it. For a complete worked example, follow the Self-Service Password Reset tutorial.

How the profile fits togetherDirect link to How the profile fits together

The profile coordinates the App and target-system action; each dependency must be configured before users rely on the reset flow.

Before you create a profileDirect link to Before you create a profile

  • Prepare the PasswordReset App and an account filter that finds the right person. The lookup should uniquely identify the intended password reset record. See the filter tutorial.
  • Identify the target system's account key and password input. The profile tutorial shows an Active Directory example.
  • Configure the mail and, if used, SMS delivery required by the verification methods.

Create a profileDirect link to Create a profile

  1. In NIM Studio, go to Configuration → Password reset.
  2. Select Add, enter a profile name that identifies its audience, and save. The screenshot shows an Employee profile.
  3. Open the profile to configure its tabs. Use the search field on the profile list when you have several profiles.

Configure the App, lookup, and formsDirect link to Configure the App, lookup, and forms

On the Configuration tab, set the fields that connect the profile to the App and its account data:

FieldPurposeExample shown
Password reset appSelects the App that displays the recovery forms.PasswordReset
Account filterSelects the records eligible for this profile's lookup.Employee_User_PasswordReset
Password reset app error formSelects the App form used to show an error.message
Error description idSelects the App item that displays the error text.message

The Password reset profile forms grid defines the order of the App forms. The example progresses through welcome, registration, method, confirm, password, and completed. Match each Form name to its Form function and, where the form collects or displays a value, its Form variable. Review the Execute and Notification controls for the forms that need them, then save. Select a form to review its text in Form contents.

Use Preview to inspect the configured experience before publishing the App. Check that the lookup, verification, password entry, completion, and error screens appear in the expected order.

Map action variablesDirect link to Map action variables

The Action variables tab lists columns from the account filter. Map a column to a password reset variable when a later form or action needs its value. In the screenshot, the Active Directory objectGUID column is mapped to vprObjectGUID; the action can then identify the account to update.

Map only values needed by the reset flow. A variable name in this tab makes the filter value available to the configured action; it does not change the source record by itself.

Configure password reset actionsDirect link to Configure password reset actions

On Password reset actions, select Add, choose the target System and Function, then map its required inputs. The example runs Active Directory's UserUpdate function:

InputValue sourceExample variableWhy it matters
objectGUIDVariablevprObjectGUIDTargets the account found by the profile lookup.
accountPasswordVariablevPasswordSupplies the new password entered in the App.

Review the function's remaining inputs and its Output tab for your target system. If a reset must update multiple systems, configure and test the required actions for each one. The Generate notification event and Hide protected data in notification event options are also shown below the input grid; use them when your notification design calls for an action event, and keep password data protected.

Set messages and security limitsDirect link to Set messages and security limits

Error messagesDirect link to Error messages

The Error messages tab controls the text shown for unsuccessful or completed reset states. Review the wording before publishing, especially messages that users see when a code is wrong or delivery fails.

MessageWhen to review it
errorBlockedThe reset is temporarily blocked after too many errors.
errorCodeConfirmRetry and errorCodeConfirmNoRetryA confirmation code is incorrect, with or without another attempt available.
errorCompletedThe flow has completed. Despite its name, this is completion text in the example.
errorInternal and errorMethodFailedProcessing failed or a verification code could not be delivered.
errorRegistrationRetry, errorStatusBusy, and errorTimeOutRegistration failed, another session is active, or the session expired.

SettingsDirect link to Settings

The Settings tab controls code delivery, retries, blocking, and inactivity. The values below are from the screenshot; review them for your organization's security and user experience requirements.

Use NIST SP 800-63B-4 to evaluate the full account-recovery design, including how a person is verified before a password is changed. The OWASP Forgot Password Cheat Sheet gives practical guidance for recovery responses, code lifetime, retry limits, and abuse resistance. Check the profile's messages and limits against your policy, then test both successful and failed recovery paths; these example values alone do not establish a particular assurance level.

SettingWhat it controlsScreenshot value
Confirmation code lengthNumber of characters in the emailed or texted verification code.4
Confirmation code maximum send countMaximum times a code can be sent during the reset.5
Maximum errors per sessionsFailed attempts allowed before blocking the session.3
Blocking interval base durationStarting block duration, in minutes.10
Blocking interval multiplierFactor used to increase later blocking intervals.2
Form time-out in minutesInactivity period before the form session expires.5

Validate and testDirect link to Validate and test

Open Validation to review its Status, Category, Name, and Description columns. The example shows zero errors, 32 warnings, and six successful checks. Its warnings name tables in several systems, so inspect each warning's named resource before deciding whether it affects this reset profile. Select a description to open the configuration item that needs attention. See Configuration Validation for how to trace dependencies.

Save the profile, then use Preview and a test account to walk through identification, code delivery, an incorrect code, a valid code, password change, and completion. Confirm the intended target account changed and review the Password Reset troubleshooting guide if a step fails. The Password Reset App overview explains what users see after the profile is published.