Password Reset
Configuration · Password reset
Create the profile that connects the password reset App to account lookup, identity verification, and the actions that set a new password.
A password reset profile defines how a particular group of users moves through self-service recovery. The Self-Service Identity overview explains where password reset fits among NIM's user-facing workflows, while the Password Reset App explains the user experience. This page documents the profile settings behind it. For a complete worked example, follow the Self-Service Password Reset tutorial.
How the profile fits togetherDirect link to How the profile fits together
Reset password
Review
Before you create a profileDirect link to Before you create a profile
- Prepare the PasswordReset App and an account filter that finds the right person. The lookup should uniquely identify the intended password reset record. See the filter tutorial.
- Identify the target system's account key and password input. The profile tutorial shows an Active Directory example.
- Configure the mail and, if used, SMS delivery required by the verification methods.
Create a profileDirect link to Create a profile
- In NIM Studio, go to Configuration → Password reset.
- Select Add, enter a profile name that identifies its audience, and save. The screenshot shows an
Employeeprofile. - Open the profile to configure its tabs. Use the search field on the profile list when you have several profiles.
Configure the App, lookup, and formsDirect link to Configure the App, lookup, and forms
On the Configuration tab, set the fields that connect the profile to the App and its account data:
| Field | Purpose | Example shown |
|---|---|---|
| Password reset app | Selects the App that displays the recovery forms. | PasswordReset |
| Account filter | Selects the records eligible for this profile's lookup. | Employee_User_PasswordReset |
| Password reset app error form | Selects the App form used to show an error. | message |
| Error description id | Selects the App item that displays the error text. | message |
The Password reset profile forms grid defines the order of the App forms. The example progresses through welcome, registration, method, confirm, password, and completed. Match each Form name to its Form function and, where the form collects or displays a value, its Form variable. Review the Execute and Notification controls for the forms that need them, then save. Select a form to review its text in Form contents.
Use Preview to inspect the configured experience before publishing the App. Check that the lookup, verification, password entry, completion, and error screens appear in the expected order.
Map action variablesDirect link to Map action variables
The Action variables tab lists columns from the account filter. Map a column to a password reset variable when a later form or action needs its value. In the screenshot, the Active Directory objectGUID column is mapped to vprObjectGUID; the action can then identify the account to update.
Map only values needed by the reset flow. A variable name in this tab makes the filter value available to the configured action; it does not change the source record by itself.
Configure password reset actionsDirect link to Configure password reset actions
On Password reset actions, select Add, choose the target System and Function, then map its required inputs. The example runs Active Directory's UserUpdate function:
| Input | Value source | Example variable | Why it matters |
|---|---|---|---|
objectGUID | Variable | vprObjectGUID | Targets the account found by the profile lookup. |
accountPassword | Variable | vPassword | Supplies the new password entered in the App. |
Review the function's remaining inputs and its Output tab for your target system. If a reset must update multiple systems, configure and test the required actions for each one. The Generate notification event and Hide protected data in notification event options are also shown below the input grid; use them when your notification design calls for an action event, and keep password data protected.
Set messages and security limitsDirect link to Set messages and security limits
Error messagesDirect link to Error messages
The Error messages tab controls the text shown for unsuccessful or completed reset states. Review the wording before publishing, especially messages that users see when a code is wrong or delivery fails.
| Message | When to review it |
|---|---|
errorBlocked | The reset is temporarily blocked after too many errors. |
errorCodeConfirmRetry and errorCodeConfirmNoRetry | A confirmation code is incorrect, with or without another attempt available. |
errorCompleted | The flow has completed. Despite its name, this is completion text in the example. |
errorInternal and errorMethodFailed | Processing failed or a verification code could not be delivered. |
errorRegistrationRetry, errorStatusBusy, and errorTimeOut | Registration failed, another session is active, or the session expired. |
SettingsDirect link to Settings
The Settings tab controls code delivery, retries, blocking, and inactivity. The values below are from the screenshot; review them for your organization's security and user experience requirements.
Use NIST SP 800-63B-4 to evaluate the full account-recovery design, including how a person is verified before a password is changed. The OWASP Forgot Password Cheat Sheet gives practical guidance for recovery responses, code lifetime, retry limits, and abuse resistance. Check the profile's messages and limits against your policy, then test both successful and failed recovery paths; these example values alone do not establish a particular assurance level.
| Setting | What it controls | Screenshot value |
|---|---|---|
| Confirmation code length | Number of characters in the emailed or texted verification code. | 4 |
| Confirmation code maximum send count | Maximum times a code can be sent during the reset. | 5 |
| Maximum errors per sessions | Failed attempts allowed before blocking the session. | 3 |
| Blocking interval base duration | Starting block duration, in minutes. | 10 |
| Blocking interval multiplier | Factor used to increase later blocking intervals. | 2 |
| Form time-out in minutes | Inactivity period before the form session expires. | 5 |
Validate and testDirect link to Validate and test
Open Validation to review its Status, Category, Name, and Description columns. The example shows zero errors, 32 warnings, and six successful checks. Its warnings name tables in several systems, so inspect each warning's named resource before deciding whether it affects this reset profile. Select a description to open the configuration item that needs attention. See Configuration Validation for how to trace dependencies.
Save the profile, then use Preview and a test account to walk through identification, code delivery, an incorrect code, a valid code, password change, and completion. Confirm the intended target account changed and review the Password Reset troubleshooting guide if a step fails. The Password Reset App overview explains what users see after the profile is published.