To specify which password are managed by the central password, use QER_PasswordWeb_IsByCentralPwd script to define password dependencies.
For more information about scripts, see the One Identity Manager Configuration Guide.
To define password dependencies
-
Start the Designer program.
-
Connect to the relevant database.
-
Copy the QER_PasswordWeb_IsByCentralPwd script and customize the copy. Use the following parameters for this:
-
UID_Person of the logged in user
-
Key (ObjectKey) of the object to have the password reset option
-
Column names of the password
Using this input parameter, the script must return the information regarding whether or not a password is managed by the central password.
-
Save the changes.
-
Compile the script.
The central password is set separately from other password to prevent problems.
If at least one password of the logged-in user is managed by the central password, the following options are available after logging in to the Password Reset Portal.
- Setting the central password
- Setting one or more passwords
If setting one or more passwords, it is possible to set a password managed by the central password. If you want to prevent this, you can exclude the password from being reset.
For more information, see Excluding passwords from being reset.
Once a user has changed their central password and the user account is linked to other target system accounts, the password can be checked against all the password policies of the connected target systems.
To configure checks for all passwords
-
Start the Designer program.
-
Connect to the relevant database.
-
Set the QER | Person | UseCentralPassword | CheckAllPolicies configuration parameter:
TIP: To find out how to edit configuration parameters in Designer, see the One Identity Manager Configuration Guide.