<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007mQf8JCASOkta Identity EngineAuthenticationAnswered2025-10-11T09:00:47.000Z2022-07-06T09:37:36.000Z2023-01-04T12:45:21.000Z

servicea.28287 (Customer) asked a question.

Forgot Password Email expiration time

Hi,

 

Is the duration of the Forgot Password Email's (self-recovery flow) expiration time customizable? If so, could you kindly explain how to achieve this? This is by default 1 hour. Can we change this?


  • b5n6c (b5n6c)

    Hi Megha Rathod,

    To customize Forgot Password Email Expiration time in :

    Identity Engine

    1. In the Admin Console, go to Security > Authenticators.
    2. From the Email tile click on Actions > Edit.
    3. Change the default Email challenge lifetime (minutes).

    The default value is five minutes, but you can increase the value in five-minute increments, up to 30 minutes. This value is applied to emails used for self-service password resets and self-service account unlocks in addition to emails used for authentication.

    Classic Engine

    The setting for this is controlled via Password policy.  

    1. In the Admin Console, go to Security > Authentication > Password tab
    2. Select the appropriate policy on the left hand side > In the Account Recovery section, configure > "Reset/Unlock recovery emails are valid for" setting to the desired number of hours.

    Please Upvote if this address your query.

    Expand Post
    Selected as Best
  • b5n6c (b5n6c)

    Hi Megha Rathod,

    To customize Forgot Password Email Expiration time in :

    Identity Engine

    1. In the Admin Console, go to Security > Authenticators.
    2. From the Email tile click on Actions > Edit.
    3. Change the default Email challenge lifetime (minutes).

    The default value is five minutes, but you can increase the value in five-minute increments, up to 30 minutes. This value is applied to emails used for self-service password resets and self-service account unlocks in addition to emails used for authentication.

    Classic Engine

    The setting for this is controlled via Password policy.  

    1. In the Admin Console, go to Security > Authentication > Password tab
    2. Select the appropriate policy on the left hand side > In the Account Recovery section, configure > "Reset/Unlock recovery emails are valid for" setting to the desired number of hours.

    Please Upvote if this address your query.

    Expand Post
    Selected as Best
  • servicea.28287 (Customer)

     

    image.pngimage.png 

    Thank you for your assistance, @b5n6c (b5n6c)​ . I got the necessary setting in the Classic Engine. But this doesn't appear to be in Identity Engine; it appears to be for Email OTP(I'm not using Email as authenticator , only using it for recovery). Here I'm asking about expiration time of reset password link received in the email, when user goes through forgot password flow. Could you also assist me in locating this setting in Identity engine? To see more details, please refer to the screenshots:

     

    Thanks

    Expand Post
  • b5n6c (b5n6c)

    Hi @servicea.28287 (Customer)​ ,

    In Identity engine , the expiration time limit customised in the Email settings is applicable for emails used for self-service password resets and self-service account unlocks in addition to emails used for authentication , even if you are using email only for recovery.

  • servicea.28287 (Customer)

    Hey @b5n6c (b5n6c)​ , This means that the maximum expiration period for this in Identity Engine can only be set to 30 minutes ? While the expiration time for this on Classic Engine is in hours.😟

    megha SS

This question is closed.
Loading
Forgot Password Email expiration time