Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ sidebar_position: 20

# Administration

Administration

# Administration

Netwrix Password Reset is a self-service password management system that helps you to reduce the
number of password related help desk calls. Password Reset allows users to securely change their
password and unlock their account, even if they have forgotten their password. This section details
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ sidebar_position: 70

# About Tab

About Tab

# About Tab

Use the **About** tab to check the version and license information, and to install a new license
key.

Expand All @@ -18,6 +14,9 @@ key.
To install a new license key, copy the entire license e-mail to the clipboard, and then click Get
license from clipboard.

**NOTE:** Password Reset includes a 30-day evaluation license for up to 50 users. Please
:::note
Password Reset includes a 30-day evaluation license for up to 50 users. Please
[contact Netwrix support](mailto:[email protected])[](mailto:[email protected]) if you would like
to evaluate Password Reset with more than 50 users.

:::
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ sidebar_position: 30

# Configuring Password Reset

Configuring Password Reset

# Configuring Password Reset

In the previous section, you used Password Reset with a default configuration. You can use the
Configuration Console to edit the configuration settings. Click **Start** > **Netwrix Password
Reset** > **NPR Configuration Console**on the Password Reset Server computer to open the
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ sidebar_position: 30

# E-mail Tab

E-mail Tab

# E-mail Tab

Use the **E-mail** tab to configure how e-mail is sent to users, when it is sent, and also to edit
the e-mail templates.

Expand All @@ -25,8 +21,11 @@ Select the **Save e-mail to a pickup folder** option if NPR should save e-mails
delivery by a mail server. Click **Browse...** to select a folder. The mail server must monitor this
folder for new e-mail.

**NOTE:** Saving e-mail to a pickup folder is the fastest and most reliable delivery method. Use
:::note
Saving e-mail to a pickup folder is the fastest and most reliable delivery method. Use
this option if your mail server supports pickup folders.
:::


### Triggers

Expand All @@ -50,9 +49,12 @@ macros.
| [AD_OR_NPR_EMAIL] | The e-mail address in AD, or the e-mail address in Password Resetif the AD address is blank |
| [NPR_OR_AD_EMAIL] | The e-mail address in NPR, or the e-mail address in AD if the Password Reset address is blank |

**NOTE:** Use [NPR_OR_AD_EMAIL] with caution as Password Reset does not check the validity of e-mail
:::note
Use [NPR_OR_AD_EMAIL] with caution as Password Reset does not check the validity of e-mail
addresses. If the e-mail address in Password Reset's database is no longer valid, then the alert is
only sent to the invalid address.
:::


Type additional recipient e-mail addresses in the **Bcc** text box if you want to send any blind
carbon copies. Separate multiple recipients with a semicolon.
Expand Down Expand Up @@ -82,9 +84,12 @@ understand their e-mail alerts.

![configuring_npr_5](/img/product_docs/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_5.webp)

**CAUTION:** An attacker may choose a specific language to avoid detection. E-mail alerts are sent
:::warning
An attacker may choose a specific language to avoid detection. E-mail alerts are sent
in the Web Interface language chosen by the attacker if the target user has not enrolled or changed
their password with Password Reset. The target user will receive the e-mail alerts, but they may not
understand them. Use the Rest API to remind new users to enroll so their preferred language is known
to Password Reset. See the [Enroll Tab](/docs/passwordreset/3.3/administrationoverview/configuringpasswordreset/enroll_tab.md) topic
for additional information.

:::
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ sidebar_position: 20

# Enroll Tab

Enroll Tab

# Enroll Tab

Use the **Enroll** tab to maintain the list of enrollment questions and options.

![configuring_npr_2](/img/product_docs/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_2.webp)
Expand All @@ -19,7 +15,7 @@ Use the **Enroll** tab to maintain the list of enrollment questions and options.
Users must answer some questions about themselves when they manually enroll. They choose their
questions from the Question List.

Add a question
**Add a question**

Follow the steps below to add a question to the list.

Expand All @@ -31,7 +27,7 @@ Follow the steps below to add a question to the list.

**Step 4 –** Click **OK**, and then click **Apply**.

Remove a question
**Remove a question**

Follow the steps below to remove a question from the list.

Expand All @@ -43,9 +39,12 @@ Follow the steps below to remove a question from the list.

**Step 4 –** Click **Apply**.

**NOTE:** You can rearrange questions by dragging them. You can also replace question lists with
:::note
You can rearrange questions by dragging them. You can also replace question lists with
text boxes so users can enter their own questions. See the
[Editing the HTML Templates](/docs/passwordreset/3.3/administrationoverview/editing_the_html_templates.md) document for more information
:::


### Options

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ sidebar_position: 10

# General Tab

General Tab

# General Tab

Use the General tab to maintain the list of managed domains, set the database options, and enable
the Password Policy Enforcer integration. See the Netwrix Password Policy Enforcer topic for
additional information.
Expand All @@ -21,7 +17,7 @@ additional information.
The Domain List is empty when Password Reset is first installed, and users must type their domain
name. You can configure Password Reset to display a list of domains instead of an empty text box.

Add a Domain to the list
**Add a Domain to the list**

Follow the steps below to add a domain to the list.

Expand All @@ -31,11 +27,14 @@ Follow the steps below to add a domain to the list.

**Step 3 –** Click **OK**, and then click **Apply**.

**NOTE:** The most frequently used domain should be first in the list as it will be the default. You
:::note
The most frequently used domain should be first in the list as it will be the default. You
can rearrange the domains by dragging them to another position. You can also click Sort to sort them
alphabetically.
:::


Remove a Domain from the list
**Remove a Domain from the list**

Follow the steps below to remove a domain from the list:

Expand Down Expand Up @@ -96,11 +95,14 @@ Enforcer queries to a specific IP address by setting the `PPEIPAddress` registry
address of a Password Policy Server. The `PPEIPAddress` value is in
`HKEY_LOCAL_MACHINE\SOFTWARE\ANIXIS\ANIXIS Password Reset\3.0`.

**NOTE:** Due to a protocol upgrade, Netwrix Password Reset v3.3 is not compatible with Netwrix
:::note
Due to a protocol upgrade, Netwrix Password Reset v3.3 is not compatible with Netwrix
Password Policy Enforcer v8.x and earlier versions. If you are using Netwrix Password Reset with any
of those older Netwrix Password Policy Enforcer versions, please consider upgrading Netwrix Password
Policy Enforcer first to a current version, and only then upgrade Netwrix Password Reset to v3.3 (or
later).
:::


Users are more likely to see the Password Policy Enforcer Generic Rejection message rather than the
more detailed Rejection message when this registry value is set. Users may also have the wrong
Expand All @@ -109,9 +111,12 @@ domain.
Queries to the Password Policy Server are sent to UDP port 1333 by default. You may need to create
firewall rules to open this port. See the Password Policy Enforcer documentation for additional information.

**NOTE:** Due to a protocol upgrade, it is now recommended to enable protocol encryption for
:::note
Due to a protocol upgrade, it is now recommended to enable protocol encryption for
clients. To do so, please navigate to the PPS Properties in your Netwrix Password Policy Enforcer
server configuration, and enable "Only accept encrypted client request".
:::


![using_ppe_with_npr](/img/product_docs/passwordpolicyenforcer/11.0/passwordreset/administration/using_ppe_with_npr.webp)

Expand All @@ -120,6 +125,9 @@ Policy Enforcer v8.x or earlier versions, or with Netwrix Password Policy Enforc
using Netwrix Password Reset v3.3 with any of those older versions of Netwrix Password Policy
Enforcer, please consider upgrading first to a current and supported version.

**NOTE:** Password Policy Enforcer is not included with Password Reset. Go to
:::note
Password Policy Enforcer is not included with Password Reset. Go to
[www.netwrix.com/password_policy_enforcer](https://www.netwrix.com/password_policy_enforcer.html) to
learn more about Password Policy Enforcer.

:::
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ sidebar_position: 60

# Permissions Tab

Permissions Tab

# Permissions Tab

Use the **Permissions** tab to control which users can use Password Reset.

![configuring_npr_9](/img/product_docs/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_9.webp)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ sidebar_position: 50

# Security Tab

Security Tab

# Security Tab

Use the **Security** tab to configure the inactivity timeout, password reset policies, and the
lockout threshold.

Expand Down Expand Up @@ -43,11 +39,14 @@ them from resetting a recently changed password.
Users whose passwords are set to never expire in Active Directory will not be forced to change their
password during logon, even if this check box is selected.

**NOTE:** Password Policy Enforcer's History rule is enforced for password resets if the **Enforce
:::note
Password Policy Enforcer's History rule is enforced for password resets if the **Enforce
policy when password is reset** check box is selected in the PPS properties page, and if the
**Enforce this rule when a password is reset** check box is selected in the History rule's
properties page. Netwrix Password Policy Enforcer does not enforce the Minimum Age rule for password
resets. See the Security Tab topic for additional information.
:::


Users may try to evade the password history policy by resetting their password several times in
quick succession to push a password off the password history list. Select a value from the
Expand All @@ -70,6 +69,9 @@ the lockout feature. Incorrect verification codes are counted as incorrect answe
users if they enter too many incorrect verification codes** check box is selected on the
**Verification** tab.

**NOTE:** Locked out users must re-enroll before they can use Password Reset to reset their password
:::note
Locked out users must re-enroll before they can use Password Reset to reset their password
or unlock their account. The incorrect answer count is reset when a user enrolls, or answers all
questions during a reset or unlock.

:::
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ sidebar_position: 40

# Verification Tab

Verification Tab

# Verification Tab

Use the **Verification** tab to enable verification codes for resets and unlocks. Verification codes
are used for two-factor authentication, and to authenticate users that have not manually enrolled. A
verification code is sent to the user's mobile phone by e-mail and/or SMS, and the user enters the
Expand Down Expand Up @@ -115,9 +111,12 @@ The user's Active Directory mobile phone number is read from the mobile attribut
**AD Attribute** if you want to use a phone number from a different attribute. Type the name of the
attribute, and then click **OK**.

**NOTE:** Use a script to perform additional processing before sending the SMS. For example, a
:::note
Use a script to perform additional processing before sending the SMS. For example, a
script could read the user's phone number from a database, or send a language-specific SMS based on
the value of the [LANG] macro. Put the path of the scripting engine executable in the **Command**
text box, and the path to the script file and other parameters in the **Parameters** text box.
:::


![configuring_npr_7](/img/product_docs/passwordpolicyenforcer/11.0/passwordreset/administration/configuring_npr_7.webp)
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,6 @@ sidebar_position: 70

# Editing the HTML Templates

Editing the HTML Templates

# Editing the HTML Templates

Password Reset's user interface is built with customizable templates. You can easily modify the user
interface by editing the templates. The templates are written in HTML5 and formatted with CSS3, so
they work with all modern web browsers. Older browsers such as Internet Explorer 8 may work, but the
Expand All @@ -34,24 +30,27 @@ code. The files for the US English language are:
The formatting information is in `apr.css`, and the image files are in the images folder. These
files are installed into the `\Inetpub\wwwroot\pwreset\` folder by default.

**NOTE:** Always backup the user interface files before and after editing them. Your changes may be
:::note
Always backup the user interface files before and after editing them. Your changes may be
overwritten when Password Reset is upgraded, and some changes could stop Password Reset from working
correctly. Having a backup allows you to quickly revert to a working setup.
Web browsers display pages differently, so test your changes with several versions of the most
popular browsers to ensure compatibility.
:::


### Ranges and Fields

`en_default.htm` contains static HTML, but the other .htm files contain special comment tags that
are used to prepare the pages. Some of these comments define ranges. A range looks like this:

<!--RANGE_NAME-->Some text or HTML<!--/RANGE_NAME-->
**<!--RANGE_NAME-->Some text or HTML<!--/RANGE_NAME-->**

The Web Interface deletes ranges (and the text inside them) when they are not needed. Some ranges
span only one word, while others span several lines. The other type of comment tag is called a
field.

<!--USERNAME-->
**<!--USERNAME-->**

Fields are replaced by some other information. For example, the field above is replaced with a
username.
Expand Down Expand Up @@ -80,8 +79,11 @@ text_short and text_long classes are used to display different content depending
text_short elements are shown on small screens (up to 420 pixels wide). text_long elements are shown
on larger screens.

**CAUTION:** You may rebrand the Password Reset user interface, but it is a violation of the License
:::warning
You may rebrand the Password Reset user interface, but it is a violation of the License
Agreement to modify, remove or obscure any copyright notice.
:::


## Examples

Expand Down Expand Up @@ -209,8 +211,11 @@ Change the three question numbers on each line so they match the original number
Password Reset will not work correctly. You should also edit the validation error messages in
`en_enroll.htm` as some of them make reference to selecting questions from a list.

**NOTE:** Users may not choose appropriate security questions, so it is advisable to leave the
:::note
Users may not choose appropriate security questions, so it is advisable to leave the
question lists for some of the enrollment questions.
:::


### Change Font Sizes and Colors

Expand Down Expand Up @@ -243,6 +248,9 @@ Replace the hexadecimal color code with your desired color code. You can use a c
this one to generate the color code:
[https://www.w3schools.com/colors/colors_picker.asp](https://www.w3schools.com/colors/colors_picker.asp)

**NOTE:** Some old web browsers with basic HTML5 support cannot display SVG images. Password Reset
:::note
Some old web browsers with basic HTML5 support cannot display SVG images. Password Reset
works with these browsers, but the SVG images are not shown. You can convert the icons to GIF or PNG
format if you want them shown on these older browsers.

:::
Loading
Loading