FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
tbarua
Staff
Staff
Article Id 427445
Description

 

This article describes how to resolve 'Admin Reset Password Failed: Insufficient Access' when resetting a password in the Self-Service Portal Pre-Login Services.

 

Scope

 

FortiAuthenticator.

 

Solution

 

When 'Password Reset' is enabled for Pre-Login Services in the Self-service Portal, users can reset passwords by selecting 'Forgot password'. In this scenario, a remote LDAP user is being used.

 

psw1.png

 

psw2.png

 

However, while changing the password, the following error may appear: 'Password change failed. Please contact your system administrator.'

 

psw3.png

 

Upon checking the Raw logs in FortiAuthentication, it shows that the LDAP bind user does not have the permission to reset the password. 

 

After allowing the required permission to LDAP bind user, a remote user can reset their password in the Self-Service Portal Pre-Login Services. 

 

Furthermore, FortiAuthenticator requires a specific configuration to support password change operations for remote LDAP users, as detailed below:

 

Requirements for user password change with FortiAuthenticator as user database

How to allow an LDAP user to change password at first logon or renew an expired password With Forti...