Custom initial password policies can be created from the Initial Password Policies page for each role. When configuring a custom policy, there are two tabs that require completion. The first tab is Policy Builder which will appear different for specific roles.
For staff and teachers, the Policy Builder tab includes the option to enable or disable Random Initial Password. Once the switch is disabled, the Attribute Rule Builder will appear. These rules can be used to add attributes from the source for that role, as well as snippets of custom text.
Once an attribute is added, you can use the complete value or only a portion of characters from the front or back. You can also specify the case used for that attribute, which is important when passwords are case sensitive in your downstream systems. The rules can be reordered and you can view an example password generated with sample data at the top of the screen.
For students and sponsored accounts, the ability to set passwords at a more granular level for these roles adds an additional step on the Policy Builder tab. For each policy, you will use a pop-up menu to choose the specific subgroups to apply the policy to.
Once a subgroup is selected for a custom policy, it will no longer appear in the pop-up menu so that only one policy will apply per group. Any subgroup not assigned to a custom policy will receive the default policy for their role. These rules can be used to add attributes from the source for that role, as well as snippets of custom text. Once an attribute is added, you can use the complete value or only a portion of characters from the front or back. You can also specify the case used for that attribute, which is important when passwords are case sensitive in your downstream systems. The rules can be reordered and you can view an example password generated with sample data at the top of the screen.
In the Advanced Settings drop-down, you can configure the policy and force all users to reset their passwords in RapidIdentity on their first login to the platform when enabled. The Sync Options tab allows for additional configuration of the password syncing.