08-17-2016 09:34 AM
I am working at a customer that is using ISE local accounts as the identity source for device admin credentials (i.e. TACACS for switches, routers, FWs, etc.). I have all the policies configured without an issue. Now I am trying to develop a method that will allow the end user to change their password after the ISE admin creates their account.
I thought of trying to use the guest portal structure for this, but can't get it to work. I setup a guest portal that uses the local identity store as the source sequence. I have tried:
None of these seem to work. When I set do #1 I get an internal error trying to sign into the portal. If I remove the require password change checkbox on user ID I can get right in. For #2 and #3 I go right to the success message without being prompted to change the password.
I am running ISE 2.1. Any ideas on how best to allow the users to change their passwords after the ISE admin creates the account?
Thanks.
Solved! Go to Solution.
08-23-2016 01:10 PM
From what I understand the Guest Portal flow does not change internal user passwords. So you will need to use my devices or sponsor portal for example. You could do some customization to hide everything and make it into a password change portal. If you're looking for a dedicated password change flow then please reach out to the ISE Product Marketing Team through your local account team to ask for a feature
11-10-2017 04:17 AM
Please ask through sales channel to the ISE product marketing team for feature request
08-17-2016 11:25 AM
Hi Paul,
Have you tried the My Devices portal? Just be sure that the portal is configured so that internal users are allowed to change their own passwords. Just be sure to uncheck 'require user to change password at next login' when the account is created.
Regards,
-Tim
08-17-2016 12:50 PM
Tim,
The MyDevices works when I “Allow internal users to change their own passwords” but doesn’t work when I check “Change password on next login” under the User ID itself. How is the “Change password on next login” option under the User ID ever supposed to be used?
I really didn’t want to use the MyDevices because you could add or change MAC addresses in the system by mistake. The guest portal seemed like a harmless portal to allow the users to change their password.
Thanks for your feedback.
Paul Haferman
Office- 920.996.3011
Cell- 920.284.9250
08-23-2016 01:10 PM
From what I understand the Guest Portal flow does not change internal user passwords. So you will need to use my devices or sponsor portal for example. You could do some customization to hide everything and make it into a password change portal. If you're looking for a dedicated password change flow then please reach out to the ISE Product Marketing Team through your local account team to ask for a feature
08-23-2016 03:41 PM
Thanks Jason. I ended up using the MyDevices Portal and customized it and put “Do Not Use” on the various fields and buttons. Close enough.
Paul Haferman
Office- 920.996.3011
Cell- 920.284.9250
08-24-2016 09:22 AM
you can also remove items, here is a sample on how we removed tabs. play around more you can repurpose more if you like
ISE MyDevices Portal customization (remove the column for pending/register state)
How to hide buttons on the sponsor portal
10-18-2018 08:07 AM
How do the users get routed to the Portal to change their expired TACACS passwords?
10-18-2018 08:11 AM
10-18-2018 08:25 AM
Definitely looking for an Enterprise solution. We are migrating from Cisco ACS where we currently have a Portal (locally created) for users to reset passwords. We were looking for something similar with ISE.
10-18-2018 08:40 AM
11-10-2017 01:50 AM
Are there plans to support something like the UCP service on the ACS? Because misusing the MyDevices portal is an interessting idea. But that does not support to change the enable password.
11-10-2017 04:17 AM
Please ask through sales channel to the ISE product marketing team for feature request
01-05-2022 04:29 PM
Hi guys, this seems an old thread but still is a requirement. Has this been addressed in any way that you are aware?
Needed requirements are:
1) Expiring passwords need to be notified and a URL provided for change password (Could be the "My Devices" portal)
2) Portal needs to support "user must change password at next login"
3) Portal needs to support changing of password and enable password.
Any ideas? Thank you so much!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide