Configure your Password Reset process
To implement the process, you configure credentials, verification methods and settings, and enrollment settings. You also specify to which users the process applies.
Avant de commencer
Role required: password_reset_admin
- Be sure to Plan your Password Reset processes.
- Create the credential store record for user names and passwords that are managed.Remarque :For LDAP integrations: If the Active Directory settings require users to reset the password when logging in, the results depend on the installed Password Reset plugin.
- The Password Reset plugin cannot change an AD password. End users will not be able to log in to the instance.
- The Self Service Password Reset plugin depends on the Password Reset Basic plugin. Self service is intended for password reset only on the local ServiceNow instance and cannot change an AD password. In order to change AD password, you must install the Microsoft AD spoke for Password Reset.
- The Password Reset Windows App (com.glideapp.password_reset_desktop) plugin supports changing the AD password.
- Define the verifications that the process can use.
- Configure Password Reset to auto-enroll users or to enable users to enroll for the program. See Configure your Password Reset process to auto-enroll users and Enable users to enroll for Password Reset.
Pourquoi et quand exécuter cette tâche
A Password Reset process consists of the following elements:
- The credential store that contains user login credentials.
- Optionally, the user groups that are authorized to use the Password Reset process.
- The verifications that verify the identity of the requesting user and that enable the service desk agents to authorize reset of the password. (Verifications are implemented by script includes.)
- Process strength configuration that helps view the security score of the process. You see the score in digits and colors based on the verification methods you select for the process. If enabled, notifications can be sent for potential configuration improvements to the process. If there are any deviations between the maximum attainable and current scores, an email with an actionable list of recommendations to improve the configuration is sent.