---
sourceDocument: Zurich ServiceNow AI Platform Capabilities
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/servicenow-platform

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich ServiceNow AI Platform Capabilities

ft:clusterId :

    - platcap

bundleId :

    - platcap

workflow :

    - Platform


---

# Configure your Password Reset process to auto-enroll users

# Configure your Password Reset
process to auto-enroll users {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

To simplify management, many organizations auto-enroll users in the Password Reset program. Every base-system verification type
enables you to specify automatic enrollment for your process.

## Before you begin

Role required: password_reset_admin

## About this task

To enable automatic enrollment, you configure settings for the verification type that
your Password Reset process is based on.

## Procedure

1. Navigate to AllPassword ResetExtensionsVerification Types.
2. Click the verification type for the verification that your Password Reset process uses.  
   The verification type for each base-system verification is identified in [Password Reset verifications](https://www.servicenow.com/docs/orEF5HrlFL52aqG_TdDj~w "Each verification specifies the method and process for verifying the identity of the user that is requesting a password reset.").
3. On the Verification Types page, specify the following settings:  
   {#configure-auto-enroll-for-pwd-reset__table_p5w_mgz_h1b__entry__2}

   | Field | Description |
   |-|-|
   | Enrollment check | Script that determines whether a user is enrolled for verification. Note: For automatic enrollment to work, the Enrollment check script must return true. This may require additional setup by the admin to ensure that the preconditions are met. For example, for the SMS Code verification type, records must be populated in particular tables. If no script is specified when Automatic Enrollment is selected, a default script is provided. |
   | Automatic enrollment | Select the check box to auto-enroll users. Note: If Automatic enrollment is not selected, then you must provide an enrollment UI macro and enrollment processor script as described in [Create a custom Password Reset verification type](https://www.servicenow.com/docs/DNQssRX09n_OCkSsR3~Qhw "Each verification in Password Reset is based on the settings for a verification type. If the verification types in the base system do not meet your needs, you can create a custom verification type."). |
   [ ]

   {#configure-auto-enroll-for-pwd-reset__table_p5w_mgz_h1b}
4. Repeat the procedure for all verifications that your Password Reset process uses.
{#configure-auto-enroll-for-pwd-reset__steps_nkg_n2w_2bb}
**Related concepts**   

* [Credential stores for Password Reset](https://www.servicenow.com/docs/B2o4_xz3aujP8N0Tvss_WA "Credential stores hold user information such as user names and passwords that can be used as login credentials. Examples include the User table [sys_user] or an Active Directory server.")
* [Password Reset verifications](https://www.servicenow.com/docs/orEF5HrlFL52aqG_TdDj~w "Each verification specifies the method and process for verifying the identity of the user that is requesting a password reset.")  
**Related tasks**   

* [Configure password expiration reminder](https://www.servicenow.com/docs/vlFW04Iw8_1VqwEX5ECRPQ "You can configure the password reset expiration reminder feature to send notifications to change or reset a user’s password whenever it is going to expire.")
* [Enable users to enroll for Password Reset](https://www.servicenow.com/docs/zuJBfFGCQ1Jw6HilqhEITQ "To enable users to enroll for the Password Reset program, you specify a UI macro that takes the user through the enrollment process and a script that processes the enrollment data that the user entered. The base system includes a functioning macro and script.")
* [Configure Password Reset properties](https://www.servicenow.com/docs/jdKpp6jCIMGgSDOZMBfcqQ "You can specify properties that configure the Password Reset experience for end users.")
* [Send email to remind users to enroll for Password Reset](https://www.servicenow.com/docs/_CZvPyDN5_WgvCSEbSvkKw "You can automatically send messages that remind users to enrolled in the Password Reset process. You specify the text of the message and can configure the messages to repeat at intervals.")
* [Configure the required strength for passwords](https://www.servicenow.com/docs/Di3dzeXkSDPCFZWZg8HU3Q "The password that a user defines must meet certain requirements — for example, it must contain at least 12 characters, it must include a numeral, and so on. You can configure the requirements as needed for your organization.")
* [Specify lockout for failed login attempts](https://www.servicenow.com/docs/cTuslDvMH53XxD9zsioIrw "The system provides inactive script actions that enable you to specify the number of failed login attempts before a user account is locked and to reset the count after a successful login.")
* [Configure Google reCAPTCHA for the password reset process](https://www.servicenow.com/docs/ewytz5526jHZbblqlBXxSQ "To use the Google reCAPTCHA service, instances that are running on a domain other than service-now.com require an API key pair from Google.")  
**Related reference**   

* [Calculating the security score for password reset process](https://www.servicenow.com/docs/PtS~sWW6lduN5mEYgLIR5w "The security score of the password reset process is a critical metric for the password reset administrators to assess the strength and configuration of the password reset process.")

*[\>]: and then


