This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Reregister Users

Is there away to have already users register with PWM reregister?  We changed our security questions and we want the user that have already registered to redo their questions.

  • 1) after changing User Policy (Q/A etc....) on server side, on client side user logs into his profile will see bar/popup/notification in IE "you must update your current profile" (will need authenticate w/password)
    2) on http//pmadmin you can set to fire email notification reminder to all ad\pm-allow users. (like with enrollment)
  • Do I need to send the email after or does it automatically know that user needs to update?
  • We are looking to update the out-of-box required questions in our environment because 40% of our users forget the answers they gave to those questions, and we end up getting these calls at our Service Desk. If we update the required questions, does this completely block users from changing their password/unlocking their account until they update their Q&A profile?
  • Hi,
    i have changed the following setting in my test environment.
    Q&A profile from 2 optional question to 3 that have to be answered.

    I could change my password without answer the optional question. But if i click on my Q&A Profile, i see the missing answered question.
    I also deleted one of my question. I am able to reset my password even if i deleted a question that a user has configured.

    After you have done your changes, you can send the users a message to update their Q&A profile.
  • 3) change Q&A rules/questions on Server side. E
    nd-user logs into http://PMUser and will see notification/popup "you must update QA profile".
    (I guess) By default, PWM does allow user to proceed ahead with old questions to pass Security door Q&A, in case user forgot his password - to allow minimum impact on end-user (say 10-100K users).
    Another option, I think there is a way to enforce end-user "Updating Q&A (via login with known password)" via email notification and blocking old Q&A profile (to be used as security authentication door).