Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Notify users during password reset/change process [Removed in Security Center 1.5]

Use this property to enable end users to reset or change passwords using a self-service process.

This property enables an end user to reset or change a password using a self-service process. Alternatively, your organization could implement a process that requires a service desk agent to reset passwords for end users. If a password change and or reset process doesn't notify users on password update, a bad actor may be able to lock that user out of their account without their knowledge. This would provide the bad actor more time to perform malicious activities. Ensure password reset process notifies users upon password change or reset.

More information

AttributeDescription
Configuration namepwd_process.change, pwd_process.reset
Configuration typeSystem Properties \(/sys\_properties\_list.do\)
Data typeBoolean
Recommended valuetrue
Default valuetrue
CategoryAuthentication
Security risk- Severity score: 8.1 - CVSS score: High - Security risk details: A bad actor may be able to lock a user out of their account without their knowledge if no notification is sent to them when a password change is reset.
Dependencies and prerequisitesNone

Parent Topic:Authentication