Password and identifier recovery
The Password and identity recovery settings let you control how customers recover access to their accounts when they forget their credentials or lock themselves out. You can configure options for username reminders, password resets, deferred password entry, and self-service unlocks.
Allow self-service username reminders
This setting adds a "Forgot your username?" link to the self-service login screen. Customers can have the reminders sent to either their email address or phone number. You can find out more about the username reminder customer experience at the link.
If an email address or phone is missing from a customer's account information, administrators can add it via the Admin Console.

Identifier screen
Username reminders work for identity stores that support usernames. Disable username reminders if your application's identity store only supports the email or phone identifiers.
Allow customers to change their password
Allow your customers to reset their password in their self-service account (MyAccount page).

If you disable this option, your
- customers can still use the password reset email option (if enabled) at login
- service desk can still provide password support via the Admin Console
Defer password input
When enabled, this option places the password input fields at the end of the registration flow (if password authentication is required in the workflow).
This allows you to insert event hooks in the registration journey to check customer data against a third-party system, prepare account migration, or just lead customers through a flexible progressive profiling experience.

Allow self-service unlock for password locks
When enabled, this setting automatically prompts customers to reset their password after they reach the maximum number of failed password attempts.
After the final failed attempt, customers see the Account lock screen with a Reset password button. Selecting this button starts the out-of-band password reset flow.
You can customize the text above and below the reset button in the Branding policy settings to match your brand's voice and provide clear instructions.
For examples of how self-service unlock interacts with custom journeys and Adaptive Access policy settings, see Account lockout scenarios.
Allow self-service password reset
This setting adds a self-service password reset option to the login screen.

Password step
The option is displayed after customers have successfully identified themselves by a username or email address.
In case of identity stores that only support the 'USERNAME' identifier, the password reset option is only available when a customer has a confirmed email address or phone number.
When customers request a password reset:
- They are sent a secure link to their confirmed email address or
- They are provided with a one-time passcode via their confirmed phone number.
If customers have a confirmed email address and a confirmed phone number, they are sent a reset link by default but can re-request password reset via phone.
If customers only have a confirmed phone number, a one-time passcode is provided for password reset.
Customers can also choose to have their passcode in a voice call.

Password reset workflows
If you disable self-service password reset at login, your service desk can still provide password support for your customers via the Admin Console.
Lifetime of password reset link by email
Specify how much time customers have to use a magic link. The lifetime of the link is set to 60 minutes by default.
Lifetime of password reset passcode by phone
Specify how much time customers have to use a passcode. The lifetime of the passcode is set to 6 minutes by default.
Length of password reset passcode by phone
You can specify the length of the one-time passcodes sent to customers. The default passcode length is set to 6 characters.
Updated 4 months ago
