Imprivata Self-Service Password Reset

The Imprivata Enterprise Access Management self-service web application lets users securely identify themselves and reset their primary password if they have forgotten their primary password or lost an authentication device.

This application has been replaced with a design that supports MFA, and aligns with the interface users are familiar with from Web SSO authentications.

This updated feature is not available for the Imprivata agent on thin clients.

The legacy application that enables self-service password reset with security questions is still available when the new feature is not enabled.

Configuration

This feature is available after your Imprivata Cloud Platform tenant has been provisioned and integrated with your Imprivata EAM enterprise.

  1. On the Imprivata Admin Console, go to gear icon > Settings.

  2. Go to EAM self-service web app and select Use Self-Service Password Reset workflow.

    IMPORTANT:

    This selection disables password reset with security questions, as configured below. See Legacy — Password Reset with Security Questions

  3. In the Imprivata Admin Console, go to Users > Workflow policy > Self-service workflows.

  4. Select the authentication method combinations required to reset a password.

    The authentication methods required can include:

    • face biometric

    • SMS

    • email

    • Imprivata ID

    • Imprivata PIN

    Security question-based authentication is not supported.

  5. Associate this workflow with user policies as needed.

  6. Click Save.

Expected User Workflow

  1. If the user must reset their password, there are two paths to access the application:

    • The user clicks the "forgot password" link on the Imprivata login screen;

    • The user visits your Imprivata Cloud Platform tenant Self-service page.

      The URL for this page is displayed in the Imprivata Admin Console > gear icon > Settings > Self-service > Self-service URL. The default is https://yourtenant/sso/passwordhelp

  2. The Self-service page opens.

  3. On the Self-service page, the user clicks Reset your primary authentication password.

  4. The same authentication interface the user sees every day appears.

  5. The user enters their username, and completes multi-factor authentication as configured above.

  6. After they successfully authenticate, they are prompted to reset their password.

Verify Identity with Government ID

When a user cannot complete the authentication methods configured above — because they have no enrolled device or cannot remember their credentials — the user may click the "Verify Identity" option. In this workflow, the user displays their government-issued ID to their web camera, and takes a live selfie. Imprivata validates the match using the Persona ID proofing service, and then permits a password reset. All attempts are logged in the audit log.

Requirements

  • Your enterprise must have an Imprivata Cloud tenant provisioned and integrated with Imprivata EAM.

  • The Verify Identity feature is enabled by default for customers with the Advanced Passwordless Access license.