When an existing user in Identity Manager is assigned a Provisioning Role via a "Modify User" task, the system may trigger a "Force Password Change" requirement.
This article explains the technical reasoning for this behavior and provides recommendations to prevent it.
Identity Manager 14.x & 15
When a Provisioning Role is added after the initial user creation, the system cannot retrieve the existing Identity Manager user's password to synchronize it with the Provisioning User. Forcing a password change ensures that both the Identity Manager User and the Provisioning User share the same credentials, maintaining consistency for account creation via Account Templates.
Understand the Behavior Assigning a Provisioning Role to an existing user forces a password reset to ensure password synchronization between the Identity Manager User and the Provisioning User.
Preventative Recommendation To avoid this requirement, use a Policy Express (PX) policy to assign the base Provisioning Role during the initial Create User task. This ensures the Provisioning User is created simultaneously with the Identity Manager User, allowing both to inherit the same password at inception.
To speak with a customer representative or a Support Engineer see . Scroll to the bottom of the page and click on your respective region.