<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New hire passwords in Midwest User Group</title>
    <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220261#M20</link>
    <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;Reaching out to see how folks are handling distribution of first-time passwords. Our current process is not the best. The manager receives the email and has to distribute it to the new hire either via phone or email. I was wondering if someone had a more elegant solution.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pamela&lt;/P&gt;</description>
    <pubDate>Tue, 16 Aug 2022 14:11:51 GMT</pubDate>
    <dc:creator>walker_pa</dc:creator>
    <dc:date>2022-08-16T14:11:51Z</dc:date>
    <item>
      <title>New hire passwords</title>
      <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220261#M20</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;Reaching out to see how folks are handling distribution of first-time passwords. Our current process is not the best. The manager receives the email and has to distribute it to the new hire either via phone or email. I was wondering if someone had a more elegant solution.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pamela&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 14:11:51 GMT</pubDate>
      <guid>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220261#M20</guid>
      <dc:creator>walker_pa</dc:creator>
      <dc:date>2022-08-16T14:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: New hire passwords</title>
      <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220263#M21</link>
      <description>&lt;P&gt;We built a custom "Account Claiming" application that sits on top of our OUD instance.&amp;nbsp; &amp;nbsp;A new hire must claim their own account by entering 4 pieces of data about themselves (first, last, DOB, last 4 of NID/SSN) that came from our HR system.&amp;nbsp; &amp;nbsp;(The DOB/NID in OUD is secured to only the directory administers since it is PII).&amp;nbsp; &amp;nbsp;The user then is presented with their UPN and UID, and proceeds to set up their own password and security challenge questions and MFA choices.&amp;nbsp; &amp;nbsp;From there we sync the password from OUD to AD and Azure AD and the user is sent to Azure to complete their SSPR/MFA set up.&amp;nbsp; &amp;nbsp;We have had great success with it since it's original launch in 2005.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 14:25:40 GMT</pubDate>
      <guid>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220263#M21</guid>
      <dc:creator>mkscarberry</dc:creator>
      <dc:date>2022-08-16T14:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: New hire passwords</title>
      <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220266#M22</link>
      <description>&lt;P&gt;This is awesome, thanks so much for the fast reply! Is OUD your directory? I'm not familiar with that acronym. I'm guessing the HR system syncs with your OUD (either directly or via IDN/IIQ) and that the OUD is the authoritative source for your IDN/IIQ instance?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 14:46:47 GMT</pubDate>
      <guid>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220266#M22</guid>
      <dc:creator>walker_pa</dc:creator>
      <dc:date>2022-08-16T14:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: New hire passwords</title>
      <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220269#M23</link>
      <description>&lt;P&gt;Oracle Universal Directory (which was our primary LDAP until we shifted to AD for the enterprise).&amp;nbsp; &amp;nbsp;We do not put any private data into AD since too many employees have access to read it.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;Our HR system is authoritative for all human records in iDN.&amp;nbsp; &amp;nbsp;IDN then creates the AD and OUD record as birthright.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 14:51:52 GMT</pubDate>
      <guid>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220269#M23</guid>
      <dc:creator>mkscarberry</dc:creator>
      <dc:date>2022-08-16T14:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: New hire passwords</title>
      <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220271#M24</link>
      <description>&lt;P&gt;We use similar approach, &amp;lt;character&amp;gt;&amp;lt;NID&amp;gt;&amp;lt;special char&amp;gt; and we set the password a day before start date. If the user doesn't change the password in 3 days, we reset it. After which, they have to reach to the help desk to reset their password (the user will be forced to reset their password at next login).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 15:01:47 GMT</pubDate>
      <guid>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220271#M24</guid>
      <dc:creator>sathieshg</dc:creator>
      <dc:date>2022-08-16T15:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: New hire passwords</title>
      <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220280#M25</link>
      <description>&lt;P&gt;Thank you for the reply! It sounds like you have an algorithm for creating the password for the identity.&amp;nbsp;I just want to make sure I'm understanding. I think we are looking for more of a "claiming" approach.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 16:18:30 GMT</pubDate>
      <guid>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/220280#M25</guid>
      <dc:creator>walker_pa</dc:creator>
      <dc:date>2022-08-16T16:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: New hire passwords</title>
      <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/277643#M52</link>
      <description>&lt;P&gt;Is anyone doing account claiming with just ISC? the last post to this thread was almost 3 years ago.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 18:38:31 GMT</pubDate>
      <guid>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/277643#M52</guid>
      <dc:creator>swcoleman</dc:creator>
      <dc:date>2026-03-30T18:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: New hire passwords</title>
      <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/277646#M53</link>
      <description>&lt;P&gt;You could probably find a way to do this with workflows and forms, but I don't think it would be very secure and it would heavily rely on your identity data being complete and accurate.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Check out &lt;A href="https://community.sailpoint.com/t5/IdentityNow-Articles/Best-Practices-for-Provisioning-with-Passwords-in-IdentityNow/ta-p/75459" target="_blank"&gt;this article&lt;/A&gt; on provisioning new account passwords. Specifically, options 2 and 3.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 19:23:08 GMT</pubDate>
      <guid>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/277646#M53</guid>
      <dc:creator>TomNimmo</dc:creator>
      <dc:date>2026-03-30T19:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: New hire passwords</title>
      <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/277648#M54</link>
      <description>&lt;P&gt;Tom, we are currently doing option 2. The challenge is that nothing is really secret anymore. Birthdays, addresses, mother's maiden name, etc. you can find on social media and almost everyone's SSN is on the dark web.&lt;/P&gt;&lt;P&gt;We are getting personal mobile and personal email from HR. Assuming that those haven't been compromised and that they can't be changed in ISC then emailing a password reset link there is potentially more secure than a known formula.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 19:44:03 GMT</pubDate>
      <guid>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/277648#M54</guid>
      <dc:creator>swcoleman</dc:creator>
      <dc:date>2026-03-30T19:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: New hire passwords</title>
      <link>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/277649#M55</link>
      <description>&lt;P&gt;Sorry, I misunderstood your post.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I agree that the scope of applying option 2 is more limited now, for the reasons you outlined in your post.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Off the top of my head, you could consider creating a workflow with the "&lt;A href="https://documentation.sailpoint.com/saas/help/workflows/workflow-triggers.html#interactive-trigger" target="_blank"&gt;interactive trigger&lt;/A&gt;" to trigger a workflow with an &lt;A href="https://documentation.sailpoint.com/saas/help/forms/index.html#interactive-forms" target="_blank"&gt;interactive form&lt;/A&gt; that collects and tests the end-user's responses. The main caveat here is that it relies on your end-users being invited to their ISC accounts. If you're already leveraging something like request center, then this could be an easy expansion of what people do in ISC.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 20:18:29 GMT</pubDate>
      <guid>https://community.sailpoint.com/t5/Midwest-User-Group/New-hire-passwords/m-p/277649#M55</guid>
      <dc:creator>TomNimmo</dc:creator>
      <dc:date>2026-03-30T20:18:29Z</dc:date>
    </item>
  </channel>
</rss>

