Configuring self-service password reset in Yandex Identity Hub
You can enable self-service password reset (SSPR)
To configure self-service password reset:
-
Log in to Yandex Identity Hub
. -
In the left-hand panel, select
Security settings. -
Navigate to the MFA policies tab.
-
In the MFA policy list, click
in the policy row and select Edit. If you do not have an MFA policy, create a new one. In the window that opens:-
To enable self-service password reset for users added to an MFA policy target group, under Self-reset password:
- Enable Allow password reset.
- In the Reset method field, select at least one user verification method during the password reset:
-
Sequential entry of any two authenticators: Reset method where the user confirms their identity using any two verification methods, e.g., a TOTP and an SMS code.To use this method, the user account must have at least two MFA factors configured. Otherwise, only a user pool administrator can reset the password.
-
FIDO2 with mandatory user verification: Reset method where the user can verify their identity using a FIDO2 key or Passkey , but only together with local verification, such as a PIN, biometrics, etc.To use this password reset method, the user account must have a WebAuthn
MFA factor configured. Otherwise, only a user pool administrator can reset the password.
Note
To disable self-service password reset, disable Allow password reset under Self-reset password.
-
-
Click Save.