How do users reset their password?
If a staff member has forgotten their password, they can reset it in one of the following ways.
Option 1: Request a reset from the web login
Go to 1Life Forgot Password and follow the instructions on the page. Instructions to reset their password will be sent to their email. If the user does not have an email address, the reset email is sent to their supervisor, who can help them regain access.
Option 2: Request a reset from the mobile app
On the mobile app login screen, tap Forgot Password and follow the instructions. If the user does not have an email address, the reset email is sent to their supervisor, who can help them regain access.
Option 3: Have an administrator generate a temporary password
An administrator can open the user's account, click Change Password and then either set a specific password, or generate a temporary password.
When setting a password manually, you can select Send Credentials. The email will notify the user about their login, but it will not include the password. You’ll need to share the password separately through a secure channel.
The recommended option is to instead, generate a temporary password by clicking the Generate Random Password. button beside the Enter new password field. The new temporary password is displayed and you can optionally email the credentials to the user. Since this is a temporary password it will be included in the email. When the user logs in with this temporary password, they will be prompted to choose a new password.
Why permanent passwords should not be sent by email
When an administrator enters a new password manually and chooses to send a notification email, that email does not include the password. The administrator must give the password to the user separately.
We do this because ordinary email is not a safe place to send a permanent password. Email can be forwarded to other people, left open on a shared computer or phone, or accessed by someone who gets into the recipient's inbox. Messages can also be copied or stored in more than one place. Anyone who sees the password could use it to sign in as that person.
A temporary password is safer for this situation because the user must replace it with a password of their own when they sign in. Even so, the user should avoid forwarding the message and should change the temporary password promptly.
Which option should I use?
- The user can access their email: Start with the web or mobile Forgot Password option.
- An administrator needs to help: Use Generate Random Password so the user receives a temporary password and is prompted to create a new one.
- An administrator manually enters a password: Tell the user that the notification email will not contain it. Share it separately through a secure channel, and ask the user to change it after signing in.
If the reset email does not arrive, check that the user’s email address is correct and look in the junk or spam folder. If the user does not have an email address, ask their supervisor to check for the message. If the issue continues, contact your 1Life support representative.