Self-service password reset in Yandex Identity Hub
You can enable self-service password reset (SSPR)
Users can reset their password on their own on the Yandex Cloud login page. At the same time, the user must verify their identity using the verification methods set by the MFA policy.
The option for users to reset their own passwords and the available reset methods are configured in the MFA policy settings. Currently, you can only configure this option in the Cloud Center UIorganization-manager.editor role or higher.
Password reset methods
To enable self-service password reset for users in the MFA policy settings, you must set at least one password reset method:
-
Sequential entry of any two authenticators: Reset method where the user confirms their identity using any two verification methods, e.g., a TOTP and an SMS code.To use this method, the user account must have at least two MFA factors configured. Otherwise, only a user pool administrator can reset the password.
-
FIDO2 with mandatory user verification: Reset method where the user can verify their identity using a FIDO2 key or Passkey , but only together with local verification, such as a PIN, biometrics, etc.To use this password reset method, the user account must have a WebAuthn
MFA factor configured. Otherwise, only a user pool administrator can reset the password.
You can also enable multiple password reset methods simultaneously in the MFA policy's self-service password reset settings.