In Password Manager, you can manually set when users get reminders before disabling their account. If the user does not update their Q&A account in the set time period, their account gets disabled. To configure the reminders, perform the following steps.
To disable the user account after a series of reminders
-
Connect to the Administration Site by typing the Administration Site URL in the address bar of your web browser. By default, the URL is http://<ComputerName>/PMAdmin/.
NOTE: When prompted to log in, provide your domain user name in a domainname\username format.
-
Select the Management Policy you want to modify.
-
Expand the User Enforcement Rules section and click Remind Users to Create/Update Q&A Profiles.
-
In the Apply the following notification scenarios to users from the rule’s scope section, click Add to add a new notification scenario, or click Edit to modify an existing notification scenario.
-
In Configure Notification Scenario window, do the following:
-
Select the User was invited to create/update Q&A profile N days ago option and enter the required number of days within which the users have to create or update their Q&A profiles.
-
Select Disable user account.
-
Select Notify users by email check box to configure email notification, or select Notify users via Secure Password Extension check box to configure notification by a dialog and click Next.
-
If you have selected the Notify users by email check box, edit the notification template if necessary. Specify the following settings if required and click Next:
-
To define the default notification language, click the language link next to the Default language option and select the required language.
-
To specify the notification text in another language, click Add new language and select the required language. Notification templates in 16 languages are available out of the box (English, Chinese (Simplified), Chinese (Traditional), Danish, Dutch, French, German, Japanese, Korean, Portuguese (Brazil), Portuguese (Portugal), Russian, Spanish, Polish, Czech, Swedish).
-
If you have selected the Notify users via Secure Password Extension check box, configure the postpone options that will be available to users on the notification dialog: select check boxes with required time intervals and click OK.
-
Click Save.
You can enable the accounts disabled through forced enrollment, using a customized enable account workflow.
NOTE: The custom workflow must be executed only through Secure Password Extension or through mobile browsers. Because user login is restricted on workstation after disabling of the account.
To enable the account, use the following activities in the workflow:
- Authenticate with password or any 2FA procedure such as Radius.
NOTE: In the activity settings, you must select Authenticate users with disabled accounts check box to unlock and re-enable the disabled user accounts.
-
Edit Q&A profile
-
Enable account.
NOTE: In the activity settings, you must select Enable user accounts disabled by forced enrollment check box to unlock and re-enable the disabled user accounts disabled through forced enrollment. If you do not select the check box, all the disabled user accounts in the organization are enabled.
-
If an error occurs, restart the workflow.
By using this enforcement rule you can configure Password Manager to notify users about password expiration. If you configure this notification, users will be notified by email.
The notification schedule is defined by the Reminder to Change Password scheduled task. Note that notification starts only after this scheduled task has run. For more information on the scheduled tasks, see Scheduled tasks.
NOTE: If you disable the Reminder to Change Password scheduled task, users will not be reminded of password expiration.
To enable the rule, on the Home page of the Administration Site, expand the required enforcement rules section, click Remind Users to Change Password, and then click Enable.
To configure this enforcement rule, you must specify a user scope, conditions when an email notification should be sent and an email notification text.
To configure this reminder
-
Connect to the Administration Site by typing the Administration Site URL in the address bar of your Web browser. By default, the URL is http://<ComputerName>/PMAdmin/.
NOTE: When prompted to log in, provide your domain user name in a domainname\username format.
-
Select the Management Policy you want to modify.
-
Expand the User Enforcement Rules section and click Remind Users to Change Password.
-
To set the user scope of this rule, click Configure under Configure the rule’s scope, specify the following settings and click Save:
Table 8: Configure the scope of rule
Users from the user scope of the Management Policy |
Select this option to include all users from the Management Policy user scope to the rule’s scope. |
The following users |
Select this option to specify groups included to and excluded from the rule’s scope. |
Users included both in the Management Policy user scope and the following groups |
Specify groups included in the rule’s scope.
NOTE: Only users belonging both to the Management Policy user scope and the specified groups will be included in the rule’s scope. To browse for groups, click Add, select the required groups and click Save. |
Users excluded from the rule’s scope |
Specify groups excluded from the rule’s scope. To browse for groups, click Add, select the required groups and click Save. |
-
To specify the conditions under which users should be notified to change their passwords, click Configure under Notify users who meet the following condition, specify the number of days before password expiration and click OK.
-
To edit the notification template, use a WYSIWYG editor in the Configure email notification section.
-
To define the default notification language, click the language link next to the Default language option and select the required language.
-
To specify the notification text in another language, click Add new language and select the required language. Notification templates in 17 languages are available out of the box (English, Chinese (Simplified), Chinese (Traditional), Danish, Dutch, French, German, Italian, Japanese, Korean, Portuguese (Brazil), Portuguese (Portugal), Russian, Spanish, Polish, Czech, Swedish). The language of the notification message corresponds to the language of a user’s Q&A profile. If the corresponding language is not available, the notification message is sent in the default language.
-
Click Save.
IMPORTANT: To send email notifications to users, you must specify an outgoing mail server (SMTP server). For more information on how to configure the SMTP server, see Outgoing mail servers.