---
title: "How it works: PortalGuard Self-Service Password Reset"
description: How does self-service password reset (SSPR) work? How do administrators utilize PortalGuard's SSPR and how can it benefit administrators and users?
---

[®](https://biokey.wpengine.com/)

- [Products](https://www.bio-key.com/#) 
    - [PortalGuard](https://www.bio-key.com/portalguard/) 
          - [Multi-Factor Authentication](https://www.bio-key.com/multi-factor-authentication/)
          - [Self-Service Password Reset](https://www.bio-key.com/self-service-password-reset/)
          - [Single Sign-On](https://www.bio-key.com/single-sign-on/)
          - [MobileAuth](https://info.bio-key.com/mobileauth)
          - [Admin Panel](https://www.bio-key.com/portalguard/admin-experience/)
          - [PortalGuard Desktop](https://www.bio-key.com/portalguard/portalguard-desktop/)
    - [Identity-Bound Biometrics](https://www.bio-key.com/identity-bound-biometrics/) 
          - [Passkey:YOU](https://www.bio-key.com/identity-bound-biometrics/passkey-authentication/)
          - [Passwordless with IBB](https://www.bio-key.com/business-initiatives/phone-less-token-less-passwordless/)
    - [Hardware](https://www.bio-key.com/hardware/) 
          - [Fingerprint Scanners](https://www.bio-key.com/fingerprint-scanners/)
          - [FIDO Security Keys](https://www.bio-key.com/hardware/fido-key-security-key/)
          - [POS Terminal](https://www.bio-key.com/hardware/mobilepos-pro/)
    - [Civil & Large-Scale Identification](https://www.bio-key.com/civil-large-scale-biometric-identification/)
    - [Platform Services](https://www.bio-key.com/platform-services/)
- [Solutions](https://www.bio-key.com/#) 
    - [Business Initiatives](https://www.bio-key.com/business-initiatives/)
    - [Securing Roving User Access](https://www.bio-key.com/roving-users/)
    - [Zero Trust](https://www.bio-key.com/zero-trust/)
    - [Passwordless](https://www.bio-key.com/move-to-passwordless-authentication/)
    - [Cyber Insurance](https://www.bio-key.com/multi-factor-authentication/multi-factor-authentication-a-requirement-for-cyber-insurance/)
    - [Education](https://www.bio-key.com/expertise-in-education/)
    - [Financial](https://www.bio-key.com/financial-services/)
    - [Government](https://www.bio-key.com/government-agencies/)
    - [Healthcare](https://www.bio-key.com/healthcare/)
    - [Manufacturing](https://www.bio-key.com/discrete-and-process-manufacturing/)
    - [Retail](https://www.bio-key.com/retail/)
    - [MSPs & MSSPs](https://www.bio-key.com/msps-and-mssps/)
- [Resources](https://www.bio-key.com/#) 
    - [Resource Center](https://www.bio-key.com/resources/)
    - [Blog](https://blog.bio-key.com)
    - [Case Studies](https://www.bio-key.com/resources/?type=case-studies)
    - [White Papers](https://www.bio-key.com/resources/?type=white-papers)
    - [Webinars](https://www.bio-key.com/resources/?type=webinars)
- [About](https://www.bio-key.com/#) 
    - [Company](https://www.bio-key.com/company/)
    - [Leadership](https://www.bio-key.com/leadership/)
    - [International](https://www.bio-key.com/international/)
    - [Investors](https://www.bio-key.com/investor-relations/)
    - [News & Press](https://www.bio-key.com/news-events/)
    - [Awards](https://www.bio-key.com/awards/)
    - [Events](https://www.bio-key.com/resources/?type=events)
- [Partners](https://www.bio-key.com/partners/) 
    - [Partner Portal](https://partner.bio-key.com/)
    - [Locate a Partner](https://www.bio-key.com/partners/locate-a-partner/)
    - [Amazon Partner Network](https://www.bio-key.com/amazon-partner-network/)
- [Contact](https://www.bio-key.com/contact-us/)
- [Free Trial](https://info.bio-key.com/pg-free-trial)
- [Support](https://www.bio-key.com/support/)

- [Products](https://www.bio-key.com/#) 
    - [PortalGuard](https://www.bio-key.com/portalguard/) 
          - [Multi-Factor Authentication](https://www.bio-key.com/multi-factor-authentication/)
          - [Self-Service Password Reset](https://www.bio-key.com/self-service-password-reset/)
          - [Single Sign-On](https://www.bio-key.com/single-sign-on/)
          - [MobileAuth](https://info.bio-key.com/mobileauth)
          - [Admin Panel](https://www.bio-key.com/portalguard/admin-experience/)
          - [PortalGuard Desktop](https://www.bio-key.com/portalguard/portalguard-desktop/)
    - [Identity-Bound Biometrics](https://www.bio-key.com/identity-bound-biometrics/) 
          - [Passkey:YOU](https://www.bio-key.com/identity-bound-biometrics/passkey-authentication/)
          - [Passwordless with IBB](https://www.bio-key.com/business-initiatives/phone-less-token-less-passwordless/)
    - [Hardware](https://www.bio-key.com/hardware/) 
          - [Fingerprint Scanners](https://www.bio-key.com/fingerprint-scanners/)
          - [FIDO Security Keys](https://www.bio-key.com/hardware/fido-key-security-key/)
          - [POS Terminal](https://www.bio-key.com/hardware/mobilepos-pro/)
    - [Civil & Large-Scale Identification](https://www.bio-key.com/civil-large-scale-biometric-identification/)
    - [Platform Services](https://www.bio-key.com/platform-services/)
- [Solutions](https://www.bio-key.com/#) 
    - [Business Initiatives](https://www.bio-key.com/business-initiatives/)
    - [Securing Roving User Access](https://www.bio-key.com/roving-users/)
    - [Zero Trust](https://www.bio-key.com/zero-trust/)
    - [Passwordless](https://www.bio-key.com/move-to-passwordless-authentication/)
    - [Cyber Insurance](https://www.bio-key.com/multi-factor-authentication/multi-factor-authentication-a-requirement-for-cyber-insurance/)
    - [Education](https://www.bio-key.com/expertise-in-education/)
    - [Financial](https://www.bio-key.com/financial-services/)
    - [Government](https://www.bio-key.com/government-agencies/)
    - [Healthcare](https://www.bio-key.com/healthcare/)
    - [Manufacturing](https://www.bio-key.com/discrete-and-process-manufacturing/)
    - [Retail](https://www.bio-key.com/retail/)
    - [MSPs & MSSPs](https://www.bio-key.com/msps-and-mssps/)
- [Resources](https://www.bio-key.com/#) 
    - [Resource Center](https://www.bio-key.com/resources/)
    - [Blog](https://blog.bio-key.com)
    - [Case Studies](https://www.bio-key.com/resources/?type=case-studies)
    - [White Papers](https://www.bio-key.com/resources/?type=white-papers)
    - [Webinars](https://www.bio-key.com/resources/?type=webinars)
- [About](https://www.bio-key.com/#) 
    - [Company](https://www.bio-key.com/company/)
    - [Leadership](https://www.bio-key.com/leadership/)
    - [International](https://www.bio-key.com/international/)
    - [Investors](https://www.bio-key.com/investor-relations/)
    - [News & Press](https://www.bio-key.com/news-events/)
    - [Awards](https://www.bio-key.com/awards/)
    - [Events](https://www.bio-key.com/resources/?type=events)
- [Partners](https://www.bio-key.com/partners/) 
    - [Partner Portal](https://partner.bio-key.com/)
    - [Locate a Partner](https://www.bio-key.com/partners/locate-a-partner/)
    - [Amazon Partner Network](https://www.bio-key.com/amazon-partner-network/)
- [Contact](https://www.bio-key.com/contact-us/)
- [Free Trial](https://info.bio-key.com/pg-free-trial)
- [Support](https://www.bio-key.com/support/)

#### BIO-key Blog

#### Read below for news, insights, and discussion on identity and access management.

- [Blog Home](https://blog.bio-key.com)
- How it works: PortalGuard Self-Service Password Reset

# How it works: PortalGuard Self-Service Password Reset

 September 20, 2021 [by BIO-key Team](https://blog.bio-key.com/author/bio-key-team)

[With PortalGuard](https://www.bio-key.com/portalguard/), we offer both the ability have the users reset their password on their own. If you’d like to also configure the ability for the users to see their password instead of resetting it, that is available too. From the *PortalGuard Admin Guide*, which can be found here:

[PortalGuard Installation and Administration Guide](https://portalguard.app.box.com/s/xpvk0vvf82sxhvdsl3znvswgt8aqctef)

***Password Reset*** - Users can reset their forgotten passwords after sufficiently proving their identity via challenge answers, authenticating biometrically/providing OTPs sent to their mobile device or alternate email address or both.

***Password Recovery*** - Users can recover or see their current password after sufficiently proving their identity via challenge answers, authenticating biometrically/providing OTPs sent to their mobile device or alternate email address or both.

 

## Why do you want this feature?

If you are an old guy like myself, resetting passwords is just another necessary bane of our existence that we need to do, get right, and get them done and out of the way so we can address the next concern of life. Hopefully, this time, you remember your new password. Similar to your users, they do not want to admit they forgot their password by asking for help, and they do not want someone else fixing these issues for them. With [Self-Service Password Reset (SSPR)](https://www.bio-key.com/self-service-password-reset/), it is simple, fast, and secure. What else can administrators ask for?

And for older administrators, they do not want to spend their time resetting the CEO's password daily. There are more crucial tasks at hand, and organizations are paying high costs for administrators, but not to expend resources on having to reset everyone's password every 30 days.

 

## How does it work with Microsoft’s Active Directory (AD) or Azure Active Directory (Azure AD)

PortalGuard supports multiple user repository types for network credentials including AD and Azure AD. With the SSPR feature, the user’s changed password is propagated to the user repository: you reset the password once in within the PortalGuard browser and it “syncs” the password with user repository.

For example, here is a PortalGuard instance that has a “hybrid” connection to both AD and Azure AD with a user *AZTest4@ondemanduser.com* that we will reset.

Before reset:

![before reset account management](https://blog.bio-key.com/hubfs/Picture1-png.png)

Here is the user in Azure-AD:

![azure ad user](https://blog.bio-key.com/hubfs/Picture2-png.png)

 

Also, here is the user attributes displayed by using *PowerShell* commands:

PS C:\\WINDOWS\\system32> Connect-MsolService

PS C:\\WINDOWS\\system32> Get-MsolUser -EnabledFilter EnabledOnly -SearchString "AZTest4" | select DisplayName,LastPasswordChangeTimeStamp, SignInName, whencreated

DisplayName LastPasswordChangeTimestamp SignInName               WhenCreated

----------- --------------------------- ----------               -----------

AZTest4     **8/23/2021 8:47:49 PM**       AZTest4@ondemanduser.com 11/23/2020 8:37:47 PM

 

This user has been configured so that they can reset their own password within PortalGuard:

![forget password portalguard](https://blog.bio-key.com/hs-fs/hubfs/Picture3-png.png?width=336&name=Picture3-png.png)![self service portalguard prompt](https://blog.bio-key.com/hs-fs/hubfs/Picture4-png.png?width=298&name=Picture4-png.png)

 

In this case, the user has been configured to answer a previously defined question:

![security question self service portalguard prompt](https://blog.bio-key.com/hubfs/Picture5-png.png)

 

Also, the user has defined a *Two Factor Authentication* (2FA) when resetting their password. In this case, we are using *Authy Push*, but other 2FA methods are available:

![push approval portalguard prompt](https://blog.bio-key.com/hubfs/Picture6-png.png)

 

Once the Authy Push is approved from the user’s cell phone, the user is directed to reset their password, with the password rules that have been defined by the administrators:

![new password portalguard sspr](https://blog.bio-key.com/hubfs/Picture7-png.png)

 

The user will show a message confirming their password reset:

![successful password reset portalguard](https://blog.bio-key.com/hubfs/Picture8-png.png)

 

Once logged in, the user can see their *Password Reset* activity:

![account details and activity portalguard](https://blog.bio-key.com/hubfs/Picture9-png.png)

 

## How Administrators See Reporting and User Insight

The administrators can also see the *Password Reset* activity in MULTIPLE places:

PS C:\\WINDOWS\\system32> Get-MsolUser -EnabledFilter EnabledOnly -SearchString "AZTest4" | select DisplayName,LastPasswordChangeTimeStamp, SignInName, whencreated, StsRefreshTokensValidFrom

 

DisplayName                 : AZTest4

LastPasswordChangeTimestamp : 8/27/2021 2:11:03 PM

SignInName                 : AZTest4@ondemanduser.com

WhenCreated                 : 11/23/2020 8:37:47 PM

StsRefreshTokensValidFrom   : 8/27/2021 2:11:03 PM

 

Also, from the *PortalGuard Administrative Panel*:

![activity tools password reset portalguard](https://blog.bio-key.com/hubfs/Picture10-png.png)

 

From the *User Detail Lookup* screen in the *Administrator Dashboard*:

![user detail lookup portalguard](https://blog.bio-key.com/hubfs/Picture11-png.png)

 

Also, on the PortalGuard server, the administrators can check the *Event Viewer* to see the *Password Reset* activity:

![event viewer portalguard](https://blog.bio-key.com/hubfs/Picture12-png.png)

## Active Directory (AD)

Active Directory *Password Reset* functionality works the same way as *Azure-AD*. The user experience does NOT change regardless of repository type.

Here is an example of an AD user resetting their password:

![active directory forgot password](https://blog.bio-key.com/hubfs/Picture13-png.png)

 

The reset methodology can be configured for different user group security policies. This user must answer **two** security questions and have an email passcode entered to reset the password:

![security questions sspr portalguard](https://blog.bio-key.com/hs-fs/hubfs/Picture14-png.png?width=337&name=Picture14-png.png)![email otp portalguard](https://blog.bio-key.com/hs-fs/hubfs/Picture15-png.png?width=324&name=Picture15-png.png)

 

The user’s profile has been updated with the last password change and last password reset:

![account details and activity portalguard](https://blog.bio-key.com/hubfs/Picture16-png.png)

 

Active Directory properties displays the password changed date, which is the same date and time in the Account Management page above:![account management active directory properties](https://blog.bio-key.com/hubfs/Picture17-png.png)

 

## Choosing a Multi-Factor Delivery Method for Password Recovery

Your administrator may have allowed you to *Enable Multi-Factor* authentication and choose which method to use when resetting your password.

From the *Account Management* page, select *Enable/Disable Multi Factor:*

*![enable disable multi factor](https://blog.bio-key.com/hubfs/Picture18-png.png)*

 

Then, select the *Multi-Factor Delivery Methods* for *Password Reset*. Choose which method you prefer to receive your OTP from the drop-down box and press the *Continue* button:

![password reset method portalguard](https://blog.bio-key.com/hubfs/Picture19-png.png)

 

## How Admins Setup with PortalGuard Configuration Editor

If you are an administrator using PortalGuard, this section will assist with *Password Reset* functionality.

Run the *PortalGuard Configuration Editor* on your PortalGuard server. There may already be several *Security Policies* associated with different user groups. *Edit* or *Create* a policy that that you choose to configure *Password Reset:*

*![admin security policies](https://blog.bio-key.com/hubfs/Picture20-png.png)*

#### Select Actions → PW Reset → Authentication

![default policy password reset](https://blog.bio-key.com/hubfs/Picture21-png.png)

 

On this screen, you can:

- Define if the user can have single or multiple combined authentications
- The number of *Challenge Answers* if any
- They *Accepted OTP* method that have been previously configured
- The *Default OTP Method*
- *Allow the users to Override* the OTP method

#### Select Actions → PW Reset → Notifications

![notifications password](https://blog.bio-key.com/hubfs/Picture22-png.png)

 

On this screen, you can:

- Define if notifications are sent went a user resets their password
- Who receives the notification
- The subject and body of the notification

## Choose PortalGuard for SSPR

For IT administrators, supporting an entire user base can be taxing for IT departments, and with password resets costing $75 per incident, self-service password reset has never been more necessary than before.

With PortalGuard, IT administrators can setup the Password Reset functionality easily. This makes it easy and simple for users including the CEO's to reset their passwords by themselves. PortalGuard's SSPR solution provides users with password reset and recovery, account unlock, end-user self registration, and forgotten username lookup. Administrators can also utilize MFA and SSO in addition to the SSPR capabilities, allowing for organizations to have a secure yet user-friendly experience.

Try PortalGuard's SSPR for yourself with our free trial sandbox demo. [Click here to try it out!](https://info.bio-key.com/pg-free-trial)

![BIO-key Team](https://blog.bio-key.com/hubfs/favicon.svg)

### Author: BIO-key Team

[← Previous Post](https://blog.bio-key.com/identity-bound-biometrics-what-is-ibb)

[Next Post →](https://blog.bio-key.com/ask-christopher-benefits-of-cloud-based-iam)

### Subscribe to the BIO-key blog!

### Recent Posts

### PLEASE FOLLOW & LIKE US :)

<https://www.facebook.com/BIOkeyInternational> <https://www.linkedin.com/company/bio-key-international> <https://twitter.com/BIOkeyIntl>

[Contact Us](https://biokey.wpengine.com/#) [732.359.1100](https://biokey.wpengine.com/#) [info@bio-key.com](mailto:info@bio-key.com)

- [About](https://biokey.wpengine.com/#) 
    - [Company](https://biokey.wpengine.com/company/)
    - [Leadership](https://biokey.wpengine.com/leadership/)
    - [International](https://biokey.wpengine.com/international/)
    - [Investors](https://biokey.wpengine.com/investor-relations/)
    - [News & Press](https://biokey.wpengine.com/news-events/)
    - [Awards](https://www.bio-key.com/awards/)
    - [Events](https://biokey.wpengine.com/resources/?type=events)
    - [Careers](https://biokey.wpengine.com/careers/)
- [Products](https://biokey.wpengine.com/#) 
    - [PortalGuard®](https://biokey.wpengine.com/portalguard/)
    - [Admin Panel](https://www.bio-key.com/portalguard/admin-experience/)
    - [Hardware](https://www.bio-key.com/hardware/)
    - [Identity-Bound Biometrics](https://www.bio-key.com/identity-bound-biometrics/)
    - [MobileAuth](https://info.bio-key.com/mobileauth)
    - [Platform Services](https://biokey.wpengine.com/platform-services/)
- [Partners](https://biokey.wpengine.com/#) 
    - [Our Partners](https://biokey.wpengine.com/partners/)
    - [Partner Portal](https://partner.bio-key.com/)
    - [Amazon Partner Network](https://www.bio-key.com/amazon-partner-network/)
- [Solutions](https://biokey.wpengine.com/#) 
    - [Business Initiatives](https://biokey.wpengine.com/business-initiatives/)
    - [Securing Roving User Access](https://www.bio-key.com/roving-users/)
    - [Zero Trust](https://www.bio-key.com/zero-trust/)
    - [Passwordless Authentication](https://www.bio-key.com/move-to-passwordless-authentication/)
    - [Cyber Insurance](https://www.bio-key.com/multi-factor-authentication/multi-factor-authentication-a-requirement-for-cyber-insurance/)
    - [Education](https://biokey.wpengine.com/expertise-in-education/)
    - [Financial](https://biokey.wpengine.com/financial-services/)
    - [Government](https://biokey.wpengine.com/government-agencies/)
    - [Healthcare](https://biokey.wpengine.com/healthcare/)
    - [Manufacturing](https://biokey.wpengine.com/discrete-and-process-manufacturing/)
    - [Retail](https://biokey.wpengine.com/retail/)
    - [MSPs & MSSPs](https://www.bio-key.com/msps-and-mssps/)
- [Resources](https://biokey.wpengine.com/#) 
    - [Resource Center](https://biokey.wpengine.com/resources/)
    - [Sustainability](https://biokey.wpengine.com/sustainability/)
    - [Policies & Legal](https://biokey.wpengine.com/polices-and-legal/)
    - [Patents](https://biokey.wpengine.com/patents/)

[![BIO-key International new](https://blog.bio-key.com/hubfs/raw_assets/public/BioKeyWpengine_Oct2020/images/logo-white.svg "BIO-key International new")](https://biokey.wpengine.com/)

© 2026 BIO-key International®. All rights reserved. Privacy policy.