Objective
This article explains how to remove the %Password% macro from reset password notifications in ADSelfService Plus. Including the %Password% macro inserts the newly reset password in plaintext into notification messages, which poses a significant security risk. Removing it ensures sensitive information is not exposed in email, SMS, or push notifications.
Prerequisite
- Administrative privileges in ADSelfService Plus
Steps to remove the %Password% macro
- Log in to the ADSelfService Plus admin console.
- Navigate to Configuration > Self-Service > Policy Configuration.
- Identify the self-service policy applicable to your users or domain.
- Click the Advanced icon next to the relevant policy, then navigate to the Notification tab.
- Select Reset Password from the notification types.
- In the Message field (for email, SMS, and push notifications), locate and delete the %Password% macro.
- Click OK to save the changes.
Validation and confirmation
- Trigger a test password reset from a user under the updated policy.
- Confirm that the notification no longer contains the password. The message should only include your updated confirmation text.
Tip
- Use macros like %Username%, %DomainName%, or %MailID% to personalize messages securely.
How to reach support
If the issue persists, contact our support team here.