Self-Service Password Reset Activity Reports
The SSPR Activity report lists Self-Service Password Reset (SSPR) activity for one user during a specified period. Use the report to check whether the user completed or failed a password reset and which authentication method the user used to verify their identity.
Previously, administrators had to compare the Login Activity and User Activity reports to find this information. The SSPR Activity report displays these events in one report.
Running the Report
Run the report from the Reports page in the Admin Console.
-
In the Admin Console, go to Reports.
-
Click Add new report and select SSPR Activity.
-
Set the filters and run the report. For more information, see Filters.
You can save the report and re-run it later, like any other EAM report. Viewing and editing the report follow your existing report permissions. An administrator without report view rights sees the filters disabled.
For more information, see Using Reporting Tools.
Filters
Use the report filters to select the user, reporting period, and authentication method.
| Filter | Description |
|---|---|
| User | The user whose SSPR activity you want to see. This report covers one user at a time. |
| Date | The reporting period. |
| Authentication Method | Restricts results to resets where the user authenticated with a specific method. Choose Any Authentication Method to see all results. |
Authentication Method Values
The Authentication Method list offers the standard EAM authentication methods, including Password, Question and Answer, Fingerprint, Proximity Card, Security Key, Device-bound Key, Smart Card, Face Recognition, ID Token, and Temporary Code, plus one value specific to this report:
-
Identity verification — the user proved their identity through the Imprivata identity verification (IdV) flow instead of a knowledge- or token-based factor. This option appears only on the SSPR Activity report.
Identity verification is an authentication method, not something a user enrolls in. Unlike modalities such as Fingerprint or Proximity Card, there is no enrolled/unenrolled state for identity verification, and results are not filtered by enrollment status.
Report Columns
Review the report columns to identify the SSPR event, result, authentication method, and request source.
| Column | Description |
|---|---|
| Date | When the event occurred. |
| User | The user account the reset applies to. |
| Domain | The user's domain. |
| Activity | The type of SSPR event. For more information, see Activities Included. |
| Result | Whether the event succeeded or failed. |
| Method | The authentication method used, for example Identity verification. |
| Host | The host the request came from. |
| IP | The source IP address. |
| MAC | The MAC address, where available. |
If Show more user attributes is enabled for the report, the configured additional user fields, for example Department or Employee ID, are appended as extra columns.
Activities Included
The report returns these SSPR event types:
-
Self-Service Password Reset — the domain password reset event.
-
Authenticate Self-Service Password Reset — authentication for the SSPR workflow.
-
Authenticate Self-Service Password Reset (CAUI) — authentication for the SSPR workflow performed through the common authentication UI (CAUI), which is the path that supports identity verification.
-
Primary Password Reset (ProveID Web) — reset performed through ProveID Web.
-
Primary Password Reset (ProveID Embedded) — reset performed through ProveID Embedded.
Events outside SSPR, such as ordinary logins, PIN resets, or help desk (Service Desk) verification, do not appear here. For Service Desk Verification activity, use the User Activity and Administrator Activity reports.
Typical Tasks
Use the report to investigate common password reset and identity verification scenarios.
Confirm a user reset their own password successfully
Run the report for that user over the relevant dates with Any Authentication Method, then check the Activity and Result columns.
Find out whether a user completed identity verification
Run the report for that user and set Authentication Method to Identity verification. Rows returned are resets where the user authenticated through the identity verification flow. The Result column shows whether verification succeeded.
Investigate a failed self-service reset
Run the report for the user and period, and look for rows where Result indicates a failure. The Method column shows which factor was attempted, and IP and Host identify where the attempt came from.