How to remove the %Password% macro from reset password notifications in ADSelfService Plus

How to remove the %Password% macro from reset password notifications in ADSelfService Plus

Objective

This article explains how to remove the %Password% macro from reset password notifications in ADSelfService Plus. Including the %Password% macro inserts the newly reset password in plaintext into notification messages, which poses a significant security risk. Removing it ensures sensitive information is not exposed in email, SMS, or push notifications.

Prerequisite 

  • Administrative privileges in ADSelfService Plus

Steps to remove the %Password% macro

  1. Log in to the ADSelfService Plus admin console.
  2. Navigate to Configuration > Self-Service > Policy Configuration.
  3. Identify the self-service policy applicable to your users or domain.
  4. Click the Advanced icon next to the relevant policy, then navigate to the Notification tab.
  5. Select Reset Password from the notification types.
  6. In the Message field (for email, SMS, and push notifications), locate and delete the %Password% macro.
  7. Click OK to save the changes.

Validation and confirmation 

  1. Trigger a test password reset from a user under the updated policy.
  2. Confirm that the notification no longer contains the password. The message should only include your updated confirmation text.

Tip 

  • Use macros like %Username%%DomainName%, or %MailID% to personalize messages securely.

How to reach support                                 

If the issue persists, contact our support team here