This section is about the user creation flow which allows users to decide their own passwords. This process is initiated by the administrator when selecting Ask password from user during the user creation process. This is different from the default flow, in which the administrator decides the passwords for users. Using the Ask Password option is the standard method for user management as the administrator does not have to remember and specify passwords when creating an account for a user. When selecting this option, the administrator must enter an Email Address. The Identity Server sends an email to this address that provides the users with a redirection URL. This directs the users to a screen where they can provide the password for the account newly created by the administrator.
Note the following before you begin:
From 5.3.0 onwards there is a new implementation for identity management features. The steps given below in this document follows the new implementation which is the recommended approach for creating users using the ask password option.
Alternatively, to see steps on how to enable this identity management feature using the old implementation, see Creating Users using the Ask Password Option documentation in WSO2 IS 5.2.0. The old implementation has been retained within the WSO2 IS pack for backward compatibility and can still be used if required.
Follow the instructions given below to configure this feature.
Configuring the Identity Server
Before you begin
Ensure that the "
IdentityMgtEventListener" with the
orderId=50 is set to false and that the Identity Listeners with
orderId=97 are set to true in the
This is already configured this way by default. You can skip this step if you have not changed this configuration previously.
Make sure the following configuration is set (uncommented) in the
<Server>element to set the redirection URL valid time period in minutes.
The redirection link that is provided to the user to set the password is invalid after the time specified here has elapsed.
Configure the email settings in the
If you are using a Google mail account, note that Google has restricted third-party apps and less secure apps from sending emails by default. Therefore, you need to configure your account to disable this restriction, as WSO2 IS acts as a third-party application when sending emails to confirm user registrations or notification for password reset WSO2 IS.Click here for more information.
Follow the steps given below to enable your Google mail account to provide access to third-party applications.
- Navigate to https://myaccount.google.com/security.
- Click Signing in to Google on the left menu and make sure that the 2-step Verification is disabled or off.
- Click Connected apps and sites on the left menu and enable Allow less secure apps.
Tip: The email template used to send this email notification is the AskPassword template.
You can edit and customize the email template. For more information on how to do this, see Customizing Automated Emails.
Start the Identity Server and log in to the Management Console.
- Click Resident under Identity Providers on the Main tab and expand the Account Management Policies tab.
Expand the User Onboarding tab and select Enable User Email Verification. Click Update to save changes.
EmailVerificationproperty can be enabled for each tenant at tenant creation by adding the following configuration to the
<IS_HOME>/repository/conf/identity/identity.xmlfile as seen below.
Try it out
You can use one of the following methods to try out creating a user with the ask password option.
Do the following steps to test the account creation using the password option.
The EnableAskPasswordAdminUI property value should be added in the
identity.xml in order to use this feature from Management Console. (i.e.:
Start the WSO2 Identity Server.
On the Main tab in the Management Console , click Add under Users and Roles.
Click Add new User.
In the above screen, do the following:
- In the Domain list, specify the user store where you want to create this user account. This includes the list of user stores you configured. See Configuring User Stores for more information.
Enter a unique user name that the person will use to log in.
Allow users to enter their own password by selecting Ask password from user.
Enter a valid Email Address and click Finish.
The Identity Server sends an email to the email address provided and sends the users a redirection URL. This directs the users to a screen where they must provide their own password.
Before you begin!
Follow the steps given in the Configuring SCIM 2.0 Provisioning Connector Documentation to configure IS 5.4.0 with SCIM 2.0.
user-schema-extension-enabledproperty in the
<IS_HOME>/repository/conf/identity/charon-config.xmlfile to 'true'.
Now you should be able to use askPassword SCIM 2.0. A sample curl commands is given below: