Skip to content

Latest commit

 

History

History
217 lines (119 loc) · 10.3 KB

configure-initial-password-and-email-link-validity-f8093f4.md

File metadata and controls

217 lines (119 loc) · 10.3 KB

Configure Initial Password and Email Link Validity

As a tenant administrator, you can configure the validity of the initial password and link sent to a user in the various application processes.

You are assigned the Manage Tenant Configuration role. For more information about how to assign administrator roles, see Edit Administrator Authorizations.

Context

The tenant administrator can specify how long the link sent to a user in the various application processes will be valid for. The link in the email can be set to expire after between 1 and 23 hours, or 1 and 30 days.

Expired links can't be used. The system automatically sends a new link in an email when a user uses an expired link.

Identity Authentication has predefined the following validity periods:

Default Email Link Validity Periods

Application Process

Default Validity Period

Self-Registration

14 Days

On-Behalf Registration

14 Days

Invitation

14 Days

Forgot Password

2 Hours

Locked Password

2 Hours

Reset Password

2 Hours

The tenant administrator can also set a validity for the initial password. The initial password can be valid between 1 and 365 days depending on the configuration. The default value is 14 days. After the validity of the initial password expires, the user can't log on to the application and must contact the administrator.

Remember:

It takes 2 minutes for the configuration changes to take place.

To change the validity period of the initial password and the links, follow the procedure below:

Procedure

  1. Sign in to the administration console for SAP Cloud Identity Services.

  2. Under Applications and Resources, choose the Tenant Settings tile.

    At the top of the page, you can view the administrative and license relevant information of the tenant.

  3. Under Authentication, choose the Initial Password and Email Link Validity list item.

  4. Choose Edit.

  5. Optional: (For email link validity) Under Configure Email Link Validity, choose an application process and set the validity period of the email link for it.

    1. From the radio buttons on the right, select either Days or Hours.

    2. From the dropdown list on the left, select a number for this.

    Note:

    You can choose a value between 1 and 23 for Hours, and 1 and 30 for Days.

    You can repeat the step for all processes.

  6. Optional: (For initial password validity) Under Configure Initial Password Validity, set a value for the validity of the initial password.

  7. Save your changes.

Related Information

Tenant SAML 2.0 Configurations

Get SAML 2.0 IdP Metadata via Parameter

Rotate Signing Certificates

Tenant OpenID Connect Configurations

Change Tenant Texts Via Administration Console

Configure Master Data Texts Via Administration Console

Configure Links Section on Sign-In Screen

Add Instructions Section on Sign-In Screen

Configure X.509 Client Certificates for User Authentication

Enable Users to Generate and Authenticate with Certificates

Configure Tenant Images

Configure Allowed Logon Identifiers

Configure User Identifier Attributes

Configure Trust this browser Option

Enable Back-Up Channels to Send Passcode for Deactivation of TOTP Two-Factor Authentication Devices

Password Recovery Options

Configure Session Timeout

Configure Trusted Domains

Use Custom Domain in Identity Authentication

Change a Tenant's Display Name

Configure Default Risk-Based Authentication for All Applications in the Tenant

Configure Sinch Service in Administration Console

Configure RADIUS Server Settings (Beta)

Configure Mail Server for Application Processes

Configure IdP-Initiated SSO

Send Security Alert Emails

Send System Notifications via Emails

Configure Customer Managed Keys in Administration Console (Restricted Availability)

Configure Default Language for End User Screens

Configure P-User Next Index

Reuse SAP Cloud Identity Services Tenants for Different Customer IDs