aaa authentication password local require-change force

Prev Next

Use this command to force one or more users to update their passwords when they next log in to the system.

The new password must be different from the current password, even if no password reuse restrictions are configured. After users change their passwords, they must log out and then log in again to access the functionality their role allows.

If the password is not changed and expires, the account will not be locked. However, users cannot do anything until they change their passwords.

Important

Password change policies only apply to users who authenticate locally. They are not enforced if a user authenticates remotely and is then mapped to a local user account that requires a password change, or if a user authenticates using an SSH authorized key.

Caution

The connection between the Central Management System appliance and its managed appliances requires "admin" credentials. The Central Management System Web services API uses "admin" credentials to authenticate requests. There are ramifications in both scenarios when the "admin" password changes. For details, see the Central Management System Administration Guide and the Central Management System Web Services API Guide.

Note

For more information about password change policies, see your System Administration Guide or Administration Guide.

Syntax

[no] aaa authentication password local require-change force {all | user <username>}

Parameters

<term>
no
</term>

Removes the new password restriction.

<term>
all
</term>

Requires a password change for all users at the next login attempt.

<term>
user <username>
</term>

Requires a password change for the specified user at the next login attempt.

Example

This example requires Laura to change her password the next time she logs in.

hostname (config) # aaa authentication password local require-change force user laura

User role

Admin

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Release 7.7

  • Central Management System: Release 7.5

  • Email Security — Server: Release 7.6

  • File Protect: Release 7.5

  • Endpoint Security (HX): Release 3.0

  • Network Security: Release 7.5

  • Intelligent Virtual Execution - Server: Release 7.9