Reset a user password
You can reset a user's password, whether their account is in University Directory (UD), Active Directory (AD), or Lightweight Directory Access Protocol (LDAP).
- In the Admin Console, go to .
- Find and select the user whose password you want to reset.
- Click Reset Password.
- Choose a Reset password option. - Send a password reset password email: Choose this option to send an email with a password reset link to the user's primary and secondary email addresses. Their password is immediately reset. The link expires in one hour.
- Create a temporary password: Choose this option to set a temporary password for the user. The user's account is marked as expired, and the user must change their password upon signing in.
 
- Optional. Select Sign out user to sign the user out of all devices and browsers.
- Click Reset password.
Admin-initiated password reset flows require the user to enter the temporary password that you set or click the link that's provided in the email, without providing other factors. Okta recommends securing all of your apps with MFA.
AD-sourced users in a Delegated Authentication environment
When a password is reset, the original password doesn't expire in AD. If the user remembers their original AD password, they can use it to sign in despite the password reset.
If you select both the Temporary Password and Password never expires options, the user isn't prompted to change their password after entering the temporary password.
LDAP-sourced users in a Delegated Authentication environment
If you set a temporary password for an LDAP-sourced user, they must change their password the next time they sign in. This applies if the LDAP server password policy requires or allows it. To create password policies that support temporary passwords, consult the LDAP server manual provided by the vendor.
