Enable password reset in RSA Identity Governance & Lifecycle
Originally Published: 2016-11-08
Article Number
Applies To
RSA Version/Condition: 6.9.1+
Platform: SUSE Linux Enterprise Server 11 SP3/Microsoft Windows Server 2008 R2
Issue
Resolution
Log in as a user with administrator privileges
Navigate to Admin -> System -> Settings and ensure Password Management is enabled.
Ensure Password Management is on, this activates the Password Management interface in the Requests menu.
Configure the Password Management settings as follows:
It is not necessary to explicitly define the port number for the external URL, it will default to port 80 if not defined. Do not try to use any other port number. The IP address is the RSA Lifecycle and Governance server address, and appropriate firewall rules must exist to allow access to it from client computers.
Under the Password Policies tab select Basic Password Policy.
On the Basic Password Policy screen select Choose Business Sources.
Select appropriate Business Sources.
Under Challenge Questions tab select the Edit button and choose how many challenge questions to define and from these how many will be randomly selected during the password reset process.
Under the Identity Confirmation tab choose whether you want to use the user name or account name as the main identifier for the password reset. In this example I am using user name.
The next step is to create the account. In this guide I am using Active Directory as the external authentication source so I will create a new account in Active Directory. I use ADSI to create the user and then enable it and assign password in Server Manager. With this technique it is possible to specify the Common Name attribute directly.
The new user appears in Server Manager.
Right click on user and select Enable Account
Right click on user and select Reset Password.
Provide first and last names.
Now that the user account has been created in Active Directory it needs to be collected into RSA Identity Governance and Lifecycle. This requires identity and account collectors configured appropriately for the Active Directory server used.
Under Resources -> Directory set up a directory to use for the collectors.
Configure the directory to use default AFX fulfilment.
Configure the Identity Collector
Account Collector
Either the identity or account collector needs to be associated with an authentication source in Admin -> System -> Authentication tab.
Collect the new user account by running the Active Directory collectors.
Check result.
Set up AFX connector for automatic provisioning of changed password.
Now that the connector is configured associate it with the collector as a connector binding.
Now that all the correct system configuration is in place the user can login and configure their challenge responses.
Log out to get back to the login screen and select Forgot My Password.
Enter the username and select the relevant external authentication source
Enter the correct responses to challenge questions.
Enter and confirm new password.
A change request is raised for the reset password operation.
It may take a short time for the change request to be automatically provisioned on the authentication source endpoint. To check the progress/success of this operation log in as a user with administrator privileges again.
Check that the change request completed.
The workflow should be similar to the below.
The user may now log in using the new password.
Related Articles
Reset Forgotten Password for the Cloud Administration Console 140Number of Views Error launching the Aveksa Kiosk Password-Reset-form aka Desktop Based Password Reset in RSA Identity Governance and Lifec… 54Number of Views How to reset a forgotten RSA SecurID Access Administration Console password 443Number of Views Amazon Web Services Identity Router Deployment Requirements 29Number of Views AM 7.1- can the isMemberOf attribute in SunOne DS 6.X be used in an identity source mapping filter 4Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Release Notes: Cloud Access Service and RSA Authenticators RSA Release Notes for RSA Authentication Manager 8.8 RSA-2026-04: RSA Governance and Lifecycle Security Update for SUSE Linux Enterprise Server Vulnerabilities
Don't see what you're looking for?