Manage Users: Password
Overview
This tab is visible to System Administrators to manage user access.
Users can go to System / Change Password to re-set their own passwords. The page is similar.
If Roles / Details "Single Signon" or "Disable Passwords" are checked for the user's role, then this tab is hidden as passwords are not applicable.
If a password is changed, it is effective immediately and will need to be used on next login.
New passwords must meet the Password Validation requirements that have been set for your business. Passwords cannot be re-used.
If a user logs in using a Temporary Password, they are navigated to the System / Change Password tab to change their password before they can continue. If the password is entered incorrectly three times in succession, the user's status is updated to 'Locked'.
Users can also use the Reset Password hyperlink on the Login screen to reset their passwords if they become locked out or can't remember their password.
Processes page
Issue a temporary password
Change a user's password
Fields description
Actions button
Troubleshooting
Visit the main Troubleshooting page for a list of all the available problem-solving tips.
403 Forbidden
If you get a '403 Forbidden' message when you are logging in, you are trying to log in from a Geo-blocked location.
To login, you will need to either
Run a VPN connection from an unblocked location (like Australia)
Arrange for the IP address to be whitelisted. This can only be done if you are running a static IP address. Go to the process page Whitelist an IP address for the steps to do this.
Invalid Token
If a user clicks on the URL link sent by the Forgot Password? feature and gets this error, it means either
They have clicked on the link previously (it will only work once) or
Their email system has triggered the URL while running security tests for phishing (thus using up the one-time link)
In both cases, the easiest way to manage this is to go to Users / Password and Issue a temporary password to the user.
My browser tells me to change this password
Your browser has a monitoring tool enabled that checks the passwords you enter against databases that store known stolen credentials.
If your browser alerts you about this, it means your login password is no longer secure.
You can confirm this by using a site like haveibeenpwned.com/Passwords to check this.
Below are our recommendations if you get this message:
Change your password immediately
Use a good password manager to help you generate and maintain strong, unique passwords for each different system or website you use.
Maintain a unique password for your Catch-e login.
Do not use your Catch-e login password on any other system or website.
Site {Client URL} unavailable cannot connect to endpoint!
Contact Catch-e Support to investigate this issue for you.