Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Installed with Password Reset

Tables, roles, business rules, scripts, and workflows are installed with the Password Reset application.

Password Reset tables

Table nameDescription
Password Reset Active Answer \[pwd\_active\_answer\]Security questions and associated answers, in an encrypted state, that users selected while going through the enrollment process.
Password Reset Active Question \[pwd\_active\_question\]Security questions that users selected while going through the enrollment process.
Password Reset Activity Log \[pwd\_reset\_activity\]All Password Reset requests.
Password Reset Activity Monitor \[pwd\_activity\_monitor\]Password Reset lockout activity.
Password Reset Credential Store \[pwd\_cred\_store\]Password Reset credential stores that are available.
Password Reset Credential Store Parameters \[pwd\_cred\_store\_param\]User-created credential store parameters.
Password Reset Credential Store Types \[pwd\_cred\_store\_type\]Password Reset credential store types that are available.
Password Reset Desktop Access Control\[pwd\_access\_control\]Password Reset Windows Application access control.
Password Reset Desktop Access Log\[pwd\_access\_log\]Password Reset Windows Application access logs.
Password Reset Device Enrollment Code \[pwd\_dvc\_enrollment\_code\]Device enrollment codes that were sent to users during SMS code enrollment.
Password Reset Devices \[pwd\_device\]User SMS devices that are in a state of verified.
Password Reset Email Verification Code\[pwd\_email\_code\]Verification codes that were sent to users via email for password reset or email address enrollment.
Password Reset Enrollment for Verification \[pwd\_enrollment\]Information about user enrollment by verification.
Password Reset Enrollment Snapshot \[pwd\_enrollment\_snapshot\]

Snapshot of user enrollment by verification.

This table is used for the reporting purpose.

The Sync Password Reset Enrollment Snapshot Data Monthly scheduled job runs once a month to generate or sync snapshot data in this table. The data, such as sys_user creation or deletion, verification to process creation or deletion, and so on, is synchronized.

Password Reset DB listener is used to create or update the data in this table which is managed by the pwd_reset.enable.dbListener property with default value as true.

If you’re an admin and want to manually sync the data in this table related to an active process, select Sync Enrollment Snapshot Data on that Password Reset process.

You can turn off the data synchronization in this table through the DB listener or the monthly scheduled job by setting the pwd_reset.enable.enrollment_snapshot property to false.

Note: Initially, an inactive record is created by the DB listener for a user-verification pair. When the users enrol themselves on the Password Reset Enrolment page, the record becomes active in this table.

Password Reset Extension Type \[pwd\_extension\_type\]Extension types that are available.
Password Reset History\[pwd\_history\]History of passwords that users reset.
Password Reset Identification Type \[pwd\_identification\_type\]Password Reset identification types that are available.
Password Reset Process \[pwd\_process\]Password Reset processes that are available.
Password Reset Process Credential Store \[pwd\_map\_proc\_to\_cred\_store\]Credential stores and the associated Password Reset processes that the application is using.
Password Reset Process User Group \[pwd\_map\_proc\_to\_group\]Groups and the associated Password Reset processes that the application is using.
Password Reset Process Verification \[pwd\_map\_proc\_to\_verification\]Verifications and the associated Password Reset processes that the application is using.
Password Reset Question \[pwd\_question\]Questions that the application uses for security question verifications.
Password Reset Request \[pwd\_reset\_request\]Information about Password Reset requests.
Password Reset Request Verification\[pwd\_map\_request\_to\_verification\]Password reset requests and the associated verification that the application is using.
Password Reset SMS Verification Code \[pwd\_sms\_code\]SMS verification codes that were sent to users for a password reset.
Password Reset User Lockout \[pwd\_user\_lockout\]Users that are locked out of Password Reset.
Password Reset Verification \[pwd\_verification\]Verifications that are available.
Password Reset Verification Param \[pwd\_verification\_param\]User-created verification parameters.
Password Reset Verification Type \[pwd\_verification\_type\]Password Reset verification types that are available.

Password Reset roles

Note: Only the user with the following roles can have access to Password Reset tables. The deny unless authenticated ACLs restrict access to the Password Reset tables for any unauthenticated role such as public role user.

For more information, see Deny-Unless ACL.

RoleDescription
password reset administrator \[password\_reset\_admin\]Configures and maintains Password Reset and Password Change.
service desk agent \[password\_reset\_service\_desk\]Resets passwords on behalf of users, tracks password reset requests, and views logs.
credentials manager \[password\_reset\_credential\_manager\]Determines which credential stores are valid for use with Password Reset.

Password Reset business rules

Business ruleTableDescription
Abort if password history limit exceedsPassword Reset Credential Store Parameters\[pwd\_cred\_store\_param\]

Prevents setting password history limit that exceeds the value of the password_reset.history.limit property.You can set a password reset history value in the password_reset.history.limit property. This system property checks the history of previous passwords based on the specified value. By default, the value is 10. But you can set it based on your organizational needs.

Note: Currently, this property is applicable only to the ServiceNow credential store.

Add default parameters QA verificationPassword Reset Verification \[pwd\_verification\]If no parameters for Security Question verifications are specified, generates parameters.
Add default parameters SMS verificationPassword Reset Verification \[pwd\_verification\]If there are no parameters specified, generates SMS code verifications parameters.
Add params personal confirm verificationPassword Reset Verification \[pwd\_verification\]If there are no parameters specified, generates personal data confirmation verifications parameters.
Add params personal verificationPassword Reset Verification \[pwd\_verification\]If there are no parameters specified, generates parameters for personal data verification.
Check unique verificationsPassword Reset Process Verification \[pwd\_map\_proc\_to\_verification\]Prevents a verification from being assigned multiple times to a specific Password Reset process.
Clear parameters for Mock verificationPassword Reset Verification\[pwd\_verification\]Clears parameters for the Mock verification.
Deactivate process with no groupPassword Reset Process User Group \[pwd\_map\_proc\_to\_group\]Deactivates the process if it does not apply to all users or if the groups associated with it are removed.
Deactivate process with no min verPassword Reset Process Verification\[pwd\_map\_proc\_to\_verification\]Deactivates the process if the verifications associated with the process are less than the minimum value for the process.
Deactivate process with no verificationPassword Reset Process Verification \[pwd\_map\_proc\_to\_verification\]Deactivates the process if the verifications associated with it are removed.
Delete history passwords if neededPassword Reset Credential Store\[pwd\_cred\_store\]Deletes history passwords if needed.
Enforce password history messagePassword Reset Credential Store\[pwd\_cred\_store\]Passes enforce password history related messages to the client side.
Google Auth Enabled CheckPassword Reset Process\[pwd\_process\]Deactivates the process with Google Authenticator verification if the Google authenticator is disabled.
GoogleAuthSysPropertyCheckPassword Reset Process Verification\[pwd\_map\_proc\_to\_verification\]Deactivates the process with the Google Authenticator verification if the Google authenticator is disabled.
Handle req\_enroll validation/default valPassword Reset Process Verification\[pwd\_map\_proc\_to\_verification\]Handles requires\_enrollment and auto\_enroll values for the process.
Insert/update scheduled job for reminderPassword Reset Process\[pwd\_process\]Inserts/updates the scheduled job for enrollment reminder.
Order must be uniquePassword Reset Desktop Access Control\[pwd\_access\_control\]Enforces order to be unique.
Parameter Names Cannot Be UpdatedPassword Reset Verification Param \[pwd\_verification\_param\]Prevents parameter name changes.
Password Reset Activity MonitorPassword Reset User Lockout \[pwd\_user\_lockout\]Creates an event when the number of users locked out of Password Reset during a specific interval exceeds the threshold value.
Password Reset Validate Auto-generatePassword Reset Process \[pwd\_process\]Checks that either Email/SMS password or Display password is selected when the Auto-generate password check box is selected.
Personal Data Confirm Param ValidationPassword Reset Verification Param \[pwd\_verification\_param\]Checks that a column exists in the sys\_user table for the parameter used in a personal data confirmation verification.
Personal Data Param ValidationPassword Reset Verification Param \[pwd\_verification\_param\]Checks that a column exists in the sys\_user table for the parameter used in a personal data verification.
Prevent against deletionPassword Reset Credential Store \[pwd\_cred\_store\]Checks whether the credential store is part of an active process before allowing deletion.
Prevent against deletionPassword Reset Identification Type \[pwd\_identification\_type\]If an identification type is part of an active process, prevents the identification type from being deleted.
Prevent against deletionPassword Reset Verification \[pwd\_verification\]If the verification is part of an active process, prevents it from being deleted.
Prevent against deletion when in usePassword Reset Credential Store Types\[pwd\_cred\_store\_type\]Prevents deletion when the type is in use.
Prevent against deletion when in usePassword Reset Verification Type\[pwd\_verification\_type\]Prevents deletion when the type is in use.
Queue event if history limit decreasesPassword Reset Credential Store Parameters\[pwd\_cred\_store\_param\]Queues the pwd.credStore.history.limit.decrease event if history limit decreases.
Security Questions Param ValidationPassword Reset Verification Param \[pwd\_verification\_param\]Checks for valid parameters in security question verifications.
Send SMS codePassword Reset Device Enrollment Code \[pwd\_dvc\_enrollment\_code\]Sends an enrollment code to a device.
Set new record flagPassword Reset Process \[pwd\_process\]Sets a new record flag for the client to take appropriate action.
Send SMS Verification Code Via NotifyPassword Reset SMS Verification Code \[pwd\_sms\_code\]Sends out SMS authentication code via Notify if the Notify plugin is active.
Single credential store per processPassword Reset Process Credential Store \[pwd\_map\_proc\_to\_cred\_store\]Prevents having more than one credential store per process.
SMS Code Param ValidationPassword Reset Verification Param \[pwd\_verification\_param\]Checks for valid parameters in SMS code verifications.
Update action based on access conditionsPassword Reset Desktop Access Log\[pwd\_access\_log\]Updates the “action” field of this log record based on the access control conditions.
Update proc\_to\_cred\_storePassword Reset Process \[pwd\_process\]Enforces a one-to-one relation between a Password Reset process and a credential store.
Validate ProcessPassword Reset Process \[pwd\_process\]Verifies that a Password Reset process is configured correctly.
Validate Pwd Cred Store NamePassword Reset Credential Store\[pwd\_cred\_store\]Enforces the name to be unique.
Validate Pwd Cred Store Type NamePassword Reset Credential Store Types\[pwd\_cred\_store\_type\]Enforces the name to be unique.
Validate Pwd Extension Type NamePassword Reset Extension Type\[pwd\_extension\_type\]Enforces the name to be unique.
Validate Pwd Identification Type NamePassword Reset Identification Type\[pwd\_identification\_type\]Enforces the name to be unique and not empty.
Validate Pwd Process NamePassword Reset Process\[pwd\_process\]Enforces the name to be unique.
Validate Pwd Verification NamePassword Reset Verification\[pwd\_verification\]Enforces the name to be unique.
Validate Pwd Verification Type NamePassword Reset Verification Type\[pwd\_verification\_type\]Enforces the name to be unique.
Validate Security QuestionPassword Reset Question \[pwd\_question\]Validates rules for security questions such as no duplicates or empty questions.
Verify Account Lookup ScriptPassword Reset Credential Store \[pwd\_cred\_store\]Checks whether the account lookup script has the correctly named function.
VerifyAutoEnrollPassword Reset Verification Type \[pwd\_verification\_type\]Checks whether auto-enroll is selected and ensures that an enrollment check script is provided.

Password Reset UI pages

NameDescription
$pwd_resetFirst page of self-service reset process (asks for user ID).
$pwd_reset_serviceDeskFirst page of service desk assisted reset process (asks for user ID).
$pwd_verifySecond page of reset process (asks user to verify identity).
$pwd_newLast page of password change process (asks for new password).
$pwd_successPage that appears when password is reset successfully.
$pwd_errorPage that appears on error during reset process.
$pwd_confirmFor processes configured to email or SMS password reset URL: After successful verification, this page displays message about sending link to user.
$pwd_changePage for changing password.
$pwd_change_successPage that appears when password is changed successfully.
$pwd_change_errorPage that appears on error during password change process.
$pwd_enrollment_form_containerEnrollment page for all verifications.
$pwd_enrollment_successPage that appears when enrollment is successful.
$pwd_enroll_errorPage that appears when any error happens during enrollment.
$pwd_unlock_successPage that appears when locked user is successfully unlocked.
$pwd_reset_downloads_uiPage for downloading Password Reset Windows Application.

Password Reset UI macros

NameDescription
$pwd_csrf_validationCSRF validation for Password Reset Application. If violation is detected, the page will be redirected to the error page.
$pwd_display_passwordDisplays a temporary password on the success page if the process is configured to auto-generate.
$pwd_enroll_email_ui and $pwd_verify_email_uiUI for email enrollment and verification.
$pwd_enroll_google_auth_ui and $pwd_verify_google_auth_uiUI for Google Authentication enrollment and verification.
$pwd_enroll_questions_uiUI for question and answer security validation enrollment.
$pwd_enroll_questions_ui_jsJavaScript code that requires server-side data for security question and answer enrollment.
$pwd_enroll_sample_uiSample UI macro for enrollment for Mock Verification Type.
$pwd_enroll_sms_ui and $pwd_verify_sms_uiUI for SMS enrollment and verification.
$pwd_enrollment_form_titleJelly macro function that prints the title for the enrollment form. A verification ID is mandatory.
$pwd_error_messageUI for displaying error messages.
$pwd_process_flowUI for indicating current stage.
$pwd_process_footerJavaScript code to get the footer macro name.
$pwd_reset_stylesheetJavaScript code to get the default CSS file ID.
$pwd_verify_personal_data_ui and $pwd_verify_personal_data_confirmation_uiUI for verifying personal data and for confirming personal data.
$pwd_verify_questions_uiUI for verifying questions.
$pwd_verify_simple_uiInput section for a simple verification method. This field is a single input field.

UI scripts installed with Password Reset

You can create a UI script and reference the script from a UI macro or UI page by using a <g:include_script> Jelly tag. The following example shows how the $pwd_enroll_questions_ui UI macro can reference the $pwd_enroll_questions_ui script. In the example, [UI Script Name]+".jsdbx" is the name of the script:

<g:include_script src="$pwd_enroll_questions_ui.jsdbx" />

By referencing an external script, you can maintain separation between client JavaScript code and Jelly code, which simplifies maintenance. You can use the following installed scripts with Password Reset UI macros:

NameDescription
$pwd_csrf_common_ui_scriptCommon UI script for handling a Cross-site Request Forgery (CSRF).
$pwd_enroll_email_uiJavaScript code for the $pwd_enroll_questions_ui UI macro.
$pwd_enroll_google_auth_uiJavaScript code for the $pwd_enroll_google_auth_ui UI macro.
$pwd_enroll_questions_uiJavaScript code for the $pwd_enroll_questions_ui UI macro.
$pwd_enroll_sample_uiIncluded sample client JavaScript for the $pwd_enroll_sample_ui UI macro.
$pwd_enroll_sms_uiSMS enrollment UI script.
$pwd_enrollment_submit_eventUI script for an enrollment submission event.
$pwd_utilUtilities for password reset UI pages and UI macros.
$pwdWfManagerHelper class to handle workflow activities and post-processing.

Password Reset workflows

The Password Reset plugin adds workflows that you can use as examples to create custom workflows for Password Reset processes.

WorkflowDescription
Pwd Reset - ADConnects to an AD server.
Pwd Reset - Local ServiceNowCurrent (local) instance.
Pwd Reset - MasterPassword Reset primary workflow.
Pwd Reset - Mock FatalExample workflow to use in Password Reset testing to simulate a fatal error. No retries.
Pwd Reset - Mock Non FatalExample workflow to use in Password Reset testing to simulate a non-fatal error.
Pwd Reset - Mock SuccessExample workflow to use in Password Reset testing to simulate a successful completion.
Pwd Reset - Remote ServiceNowConnects to a remote(SOAP) ServiceNow instance.
WorkflowDescription
Pwd Connection Test - ADTests connection to an AD server.
Pwd Connection Test - Local SNTests connection to local instance.
Pwd Connection Test - MasterMaster workflow to test credential store connectivity.
Pwd Connection Test - Mock FailureExample credential store connection test that simulates a failed connection.
Pwd Connection Test - Mock SuccessExample credential store connection test that simulates a successful connection.
Pwd Connection Test - Remote SNTests connection to a remote(SOAP) ServiceNow instance.
WorkflowDescription
Pwd Get Lock State - ADGets a user account lock state for the AD server.
Pwd Get Lock State - Local SNWorkflow to get a user account lock state for the local instance.
Pwd Get Lock State - MasterPrimary workflow to get a user account lock state.
Pwd Get Lock State - Remote SNGets a user account lock state for the remote(SOAP) ServiceNow instance.
WorkflowDescription
Pwd Unlock Account – ADUnlocks a user account for a local instance.
Pwd Unlock Account - Local SNWorkflow to unlock a user account for a local instance.
Pwd Unlock Account - MasterMaster workflow to unlock a user account.
Pwd Unlock Account – Remote SNUnlocks a user account for a remote(SOAP) ServiceNow instance.
WorkflowDescription
Pwd Change - MasterPassword change primary workflow.
Pwd Change – Local ServiceNowConnects to a local instance to change a password.
Pwd Change – ADConnects to an AD server to change a password.
Pwd Change – Remote ServiceNowConnects to a remote(SOAP) ServiceNow instance to change a password.

Password Reset notifications

NameFired by event nameDescription
Password Reset – Send SMS Codepwd.send\_sms\_code.triggerSends out SMS authentication code for verification.
\[K\] Password Reset – Send Email Codepwd.send\_email\_code.triggerSends out authentication code via Email for verification.
Password Reset - Enrollment Reminderpwd.enrollment\_reminder.triggerSends emails to remind users to enroll in the required verifications.
Password Reset - New Password Confirmationpwd.email.triggerFor the Email/SMS Password process, sends an email or SMS \(if configured\) that includes the new password.
Password Reset - Send Verify Codepwd.send\_verify\_code.triggerSends authentication code to users using email or SMS for password reset or enrollment.Note: If the Notify plugin is active, SMS code is sent via Twilio instead of ServiceNow Notification.
Password Reset URLpassword.reset.url

For the Email/SMS Password Reset URL process: Sends email or SMS (if configured) that includes a link to the password reset URL.Note: Check the following items if the instance does not send the email notification to the user:

  • Check the System Event [sys_event] table to see if the email was sent.
  • Verify that the user is subscribed to the notification.
  • Verify that the Default Self Service password reset process and password reset properties are configured correctly.

SOAP messages for Password Reset

SOAP MessageDescription
Change PasswordWhen the Orchestration Add-on plugin is active, the system can use the SOAP protocol to change passwords on remote credential stores such as a remote ServiceNow instance.
Password Reset RequestWhen the Orchestration Add-on plugin is active, the system can use the SOAP protocol to reset passwords on remote credential stores such as a remote ServiceNow instance.

REST API

  • Name: Pwd Reset
  • API ID: pwd_reset
  • Base API path: /api/now/pwd_reset
NameResource pathAPI VersionDescription
pwd_init/api/now/v1/pwd_reset/initv1Initial request to establish session, write logs, and fetch UI messages.
pwd_identify/api/now/v1/pwd_reset/identifyv1Get identification page components.
pwd_verify/api/now/v1/pwd_reset/verifyv1Get verification page components.
pwd_new/api/now/v1/pwd_reset/resetv1Get resetting password page components.
pwd_success/api/now/v1/pwd_reset/successv1Get success page components.
pwd_failure/api/now/v1/pwd_reset/failurev1Get failure page components.
NameResource pathAPI VersionDescription
pwd_init/api/now/v2/pwd_reset/initv2Initial request to establish session, write logs, and fetch UI messages.
pwd_identify/api/now/v2/pwd_reset/identifyv2Get identification page components.
pwd_verify/api/now/v2/pwd_reset/verifyv2Get verification page components.
pwd_new/api/now/v2/pwd_reset/resetv2Get reset password page components.
pwd_success/api/now/v2/pwd_reset/successv2Get success page components.
pwd_failure/api/now/v2/pwd_reset/failurev2Get failure page components.