2.3 Understanding Password Management in Identity Governance

Self Service Password Reset (SSPR) is an optional program that helps users to reset their passwords without administrative intervention. When you run Identity Governance with SSPR in a non-Identity Manager environment, SSPR uses a proprietary protocol for managing authentication methods. However, if you integrate Identity Governance with Identity Manager, you can instruct SSPR to use the NetIQ Modular Authentication Services (NMAS), which Identity Manager has traditionally used for its password management program.

SSPR automatically integrates with OSP, the single sign-on process for Identity Governance and Identity Reporting. It is the default password management program for Identity Manager, even when you do not install SSPR. When a user requests a password reset, SSPR requires the user to answer the challenge-response question. If the answer is correct, SSPR responds in one of the following ways:

  • Allows the user to create a new password

  • Creates a new password and sends it to the user

  • Creates a new password, sends it to the user, and marks the old password as expired

You configure this response in the SSPR Configuration Editor.

The Identity Governance installation package does not include an installation program for SSPR. To install and manage SSPR, see the Self Service Password Reset 4.2 Administration Guide.