Configuring an Initial Password Policy in ID Hub

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

ID Hub generates an initial password for new accounts at the time of account creation. If you do not change the default password policy configuration, ID Hub will generate a random password. If you choose to change the default configuration, you can select source attributes on which to base the initial password, or include custom text.

The Example box in the Policy Builder menu displays the resulting password as you add criteria. For example, if you select an attribute, then enter "123454321" in the Custom Text field, the password displays as value123454321 in the Example box. You can drag attributes and custom text to reorder them.

Note:

If you use an attribute or custom text in your password policy, ensure that the resulting passwords are complex and do not include values that an unauthorized user could easily guess. Jamf recommends using the default policy, which generates a random password. An attribute-based policy may be acceptable if passwords will not sync to target systems and will only be used at initial login before the user creates their own password.

Requirements
  • An administrator account in RapidIdentity

  • A source of data synchronized to ID Hub

  • Roles configured in each source, with attributes standardized using the RapidIdentity Cloud Directory Schema

  1. Log in to your RapidIdentity administrator portal.
  2. In the Dashboard pop-up menu, choose "Identity Hub".
  3. Click the upper-left menu icon.
  4. In the Policies menu, choose a user group.

    If you select Students, you can specify a grade level for the policy.

  5. Click Password Policy.
  6. To accept the default password policy, select I want users to have a random initial password.

    ID Hub displays the name of the user group in place of "users." For example, if you are creating a password policy for teachers, I want teachers to have a random initial password displays as an option.

  7. To create a custom policy, click I want to build a custom initial password.
    1. To include an attribute, click Add Rule > Add Attribute.
    2. In the pop-up menu, choose an attribute.
    3. In the Rule menu, choose whether to use the complete value or whether to use a specified number of characters from the first or last part of the value.

      If you select Use First or Use Last, the Character(s) menu appears. You can click + or - in the menu to raise or lower the number of characters used from the beginning or end of the value.

    4. In the Case menu, choose whether to use uppercase or lowercase.
    5. To add custom text, click Add Rule > Add Custom Text, then enter your text in the Custom Text field.
  8. When you finish adding text and attributes, click Save.

Initial passwords generated for the user group now conform to your password policy.