Managing Compromised Accounts in RapidIdentity SafeID

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Warning:You must be a Tenant Administrator to manage users in the Compromised Accounts delegation and MFA Authentication Policies.

Whenever an account has been found compromised by a SafeID breached accounts scan, that user will show up in an automatically created Compromised Accounts delegation in the People module.

  1. Notify the Affected User(s) by Email and/or SMS

    In the Compromised Accounts delegation, select the user(s) and choose to Send Email or Send SMS depending on the desired method for that user. The instructions configured within the theme will show in the message that is sent.

    1. Navigate to Configuration > Security > SafeID
    2. Locate the email and SMS templates
    3. Click Edit on the template
    4. Check the Enabled box to activate the template
    Note:More templates can be set up to address different user types with different messages if needed.
  2. Reset the Affected User's Password

    Once a user has been flagged as compromised, any method of changing that user's password will clear the flag. This can be done by the user through Self-Service, Delegations, or Connect. Compromised users who change their passwords through any method will immediately be removed from the Compromised Accounts delegation.

  3. Disable the Affected Account(s) if needed

    If the account(s) cannot be resolved for any reason, select the account(s) in the Compromised Accounts delegation. Then click Disable in the bottom action bar.

  4. Enroll the User(s) in MFA

    Create an Authentication Policy for compromised users to prevent future breaches.