Administrators can enable or disable end users' ability to initiate self-service password resets in Okta. The configuration is managed through password policy rules for both the Okta Identity Engine (OIE) and the Okta Classic Engine.
NOTE: Okta requires the selection of the Password change (from account settings) option for Okta Identity Engine (OIE) and the change password option for Okta Classic Engine to display the self-service password reset checkboxes.
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Password Policy Rules
- Password Reset
How can administrators enable or disable self-service password reset for users in Okta Identity Engine (OIE)?
Navigate to the password authenticator settings in the Admin Console to modify the password policy rules and adjust the self-service password reset options.
- Log in to the Okta Admin Console and navigate to Security.
- Select Authenticators, and under the Setup tab, navigate to Password.
- On the right side of the Password authenticator, select Actions, then Edit.
- Scroll down to the bottom of the page and choose Add rule (or edit an existing rule).
- Locate the Users can perform self-service section.
- Select the options for Password change (from account settings) and Password Reset.
- Alternatively, clear the Password Reset option to disable the feature for end users assigned to the password policy.
- Under the Recovery Authenticators section, set Access Control to Authentication Policy, which utilizes the Okta Account Management policy to manage how users authenticate to reset passwords.
- Alternatively, select the legacy rule option to allow specific factors to initiate recovery.
How can administrators enable or disable self-service password reset for users in Okta Classic Engine?
Navigate to the authentication settings in the Admin Console to modify the password policy rules and adjust the self-service password reset options.
- Log in to the Okta Admin Console and navigate to Security.
- Select Authentication, then choose the Password Policy tab.
- Scroll down to the bottom of the page and choose Add rule (or edit an existing rule).
- Locate the Users can section.
- Select the options for change password and perform self-service password reset.
- Alternatively, clear the perform self-service password reset option to disable the feature for end users assigned to the password policy.
