<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
How to Add or Remove the Self Service Password Reset Option for End Users
Okta Identity Engine
Administration
Okta Classic Engine
Overview

This article describes how to enable or disable the ability for end users to initiate self-service password resets.

Applies To
  • Password Policy Rules
  • Password reset
Solution

NOTE: To ensure that users can perform a Self-service Password reset, make sure that the fields Password change (from account settings) for Okta Identity Engine (OIE) and change password for Classic are checked, or the other option checkboxes will not be available.

 

Okta Identity Engine (OIE)

  1. Log in to the Admin Dashboard and navigate to the Security.

  2. Select Authenticators, and under the Setup field, navigate to Password.

  3. On the right side of the Password authenticator, select Actions, then Edit.

  4. Scroll down to the bottom of the page and choose Add rule (or edit an existing rule).

  5. Locate the Users can perform self-service section.

  6. Check the options for Password change (from account settings) and Password Reset.

  7. Alternatively, uncheck the Password Reset option to disable the option for end users to whom the password policy is applied.

  8. Under the Recovery Authenticators section, Access Control can be set to Authentication Policy, which utilizes the Okta Account Management policy to manage how users can authenticate to reset their password. 
  9. The alternative would be to use this rule (legacy), which was the legacy method of allowing certain factors to initiate recovery. 

Recovery factor

Okta Classic Engine

  1. Log in to the Admin Dashboard and navigate to the Security tab.

  2. Select Authentication > Password Policy (tab).

  3. Scroll down to the bottom of the page and choose Add rule (or edit an existing rule).

  4. Locate the Users can section.

  5. Check the options for change password and perform self-service password reset.

  6. Alternatively, uncheck the perform self-service password reset option to disable the option for end users to whom the password policy applies.

Edit rule

 

 


Related References

Loading
How to Add or Remove the Self Service Password Reset Option for End Users