RapidIdentity integrates with Have I Been Pwned to screen passwords against known data breach databases at the time of reset, and rejects passwords found in a breach before they are set. You can configure the following password reset controls in :
- Force password reset on next login, which can be set as the default or hidden from users
- Password reset to a specific attribute value
- Random password generation
- Administrative overrides for password history and password policy