Recovery account
Account recovery allows users to request a reset of their master password if they have lost it.
There are 2 prerequisites:
- Account recovery must be enabled in the administration page
- At least one user must have account recovery rights.
The workflow will be as follows:
- User requests master password reset
- Admin accepts reset
- User sets new master password
Enable Account recovery
- Go to the admin Enterprise Vault app
- Go to Settings
- Enable the line "Authorize account recovery"
- Save
Add account recovery right to a user
- Go to your WALLIX ONE IDaaS admin page
- Go to Users and select a user
- Click on Edit then Add an attribute
- Provide the following attribute
name: recovery_account
kind: bool
value: true
When this user will log in the User app, if he is the first one with recovery rights he will have the following message:
In fact, specific encryption keys are required to carry out recovery operations.
These are created when the first admin is authenticated.
Consequently, for subsequent admins, an admin who has the keys must share them.
- Go to your User Enterprise Vault app with an admin who has the recovery key
- Go to Settings, then Recovery keys
- Click on Activate access for the new admins
Workflow
User requests master password reset
Admin accepts reset
- The admin goes to his user Enterprise Vault app
- Then Recovery, an Approbation requests
- He can click on Approve or Dismiss