This command allows you to specify that users with new accounts must change their password when they first log in to the account.
Important
Password change policies only apply to users who authenticate locally. They are not enforced if a user authenticates remotely and is then mapped to a local user account that requires a password change, or if a user authenticates using an SSH authorized key.
For Intelligent Virtual Execution – Server version 11.0 and later, this command applies only to SSH sessions. The new Web UI does not enforce a password change upon first login; users must manually update their password in Settings.
Caution
The connection between the Central Management System appliance and its managed appliances requires "admin" credentials. The Central Management System Web services API uses "admin" credentials to authenticate requests. There are ramifications in both scenarios when the "admin" password changes. For details, see the Central Management System Administration Guide and the Central Management System Web Services API Guide.
Note
For more information about password change policies, see your System Administration Guide or Administration Guide.
Syntax
[no] aaa authentication password local require-change new-account
Parameters
noRemoves the requirement to change the password when users first log in to the account.
Example
In this example, the system will require users to reset their password when they first log in to their account.
hostname (config) # no aaa authentication password local require-change new-account
User role
Admin
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Malware Analysis: Release 7.7
Central Management System: Release 7.5
Email Security — Server: Release 7.6
File Protect: Release 7.5
Endpoint Security (HX): Release 3.0
Network Security: Release 7.5
Intelligent Virtual Execution - Server: Release 7.9