Build a Self-Service Password Reset App
End-user access tutorial
Build a secure self-service password reset experience that verifies users with a one-time passcode.
NIM lets users reset a forgotten password without waiting for IT support. To protect the process, users verify their identity with a one-time passcode (OTP) sent by email or SMS.
OTP sent over SMS requires additional configuration and licensing for NIM. If you are not currently licensed for SMS features, please contact your sales representative.
This tutorial supports multiple target systems, including Active Directory and Google Workspace.
Start with the Self-Service Identity overview if you are deciding which user-facing workflow to build. When you reach Step 4, use the Password Reset profile guide to understand the profile tabs, form settings, action mappings, messages, and limits shown in NIM Studio.
Build the experienceDirect link to Build the experience
Complete the stages in order. The record relationship, filters, mappings, job, and notifications build on the configuration from the stages before them.
Prepare the environment
Install NIM and confirm that Internal, Active Directory, email, and SMS services are ready. Skip this only when your environment already has these prerequisites.
Open tutorial →Step 1Enable password reset records
Enable the Internal password-reset table so NIM has a secure place to track reset enrollment and verification data.
Open tutorial →Step 2Relate users to reset records
Create the relationship that matches people in your source system to their Internal password-reset records.
Open tutorial →Step 3Define the record lifecycle
Create filters that identify records to create, update, delete, and use for profile lookups.
Open tutorial →Step 4Configure the reset profile
Choose verification settings, set action variables, and define what NIM does when a reset is requested.
Open tutorial →Step 5Synchronize reset records
Create mappings that maintain Internal password-reset records from the lifecycle filters.
Open tutorial →Step 6Create the synchronization job
Combine the create, update, and delete mappings into one safe, reusable execution job.
Open tutorial →Step 7Schedule synchronization
Run the job automatically so each user’s password-reset data stays current.
Open tutorial →Step 8Send verification codes
Configure the email or SMS templates and event actions that deliver one-time passcodes.
Open tutorial →Step 9Test and publish
Test the end-user journey, confirm verification works, and publish the app to your organization.
Open tutorial →For a walkthrough of every stage, see the full video tutorial.