Vivantio Passwords
by Juraj Krajcik
Top Right Image

Overview

Both the Vivantio Main Application and Self Service Portals are password protected, unless Single Sign On has been configured and you are using another Identity Provider such as Microsoft Azure, Okta etc..

The username and password configuration settings have been put in place to keep all user accounts safe and secure, but this must go hand in hand with a customer’s own security policies and procedures, specifically in regards to the local storage of usernames and passwords and how these are communicated within the customer’s own environment.

Vivantio would recommend always using Two Factor Authentication with any user accounts configured within Vivantio. Two Factor Authentication Help Guidance

Please note The Vivantio Support Team are not authorised to reset user passwords on behalf of customers, therefore users will need to contact their local Vivantio administrator to reset their password or use the reset password feature during the login process.

Guidance

Password Policy within Vivantio

Password Policy Configuration

Password Resets

Changing a Technicians Password using the Admin Area 

Changing a Password for the Self Service Portal using the Admin Area 

Users Changing their own Passwords

Troubleshooting 

 

 

Password Policy within Vivantio

Some configuration of the password policy that is applied to a customer’s system can be maintained as detailed in the next section. This allows the Administrators of the customer’s system to prevent the reuse of old passwords and specify the number of days users need to change their password.

Some core aspects of the Password Policy are enforced in line with industry best practice and these include:

  • Password Complexity

All passwords used need to conform to the following standards:

  • Be at least eight characters long
  • Contain at least one uppercase and one lowercase letter
  • Contain at least one number
  • Contain at least one special character from the following list: ! " # $ % & ' ( ) * + , - . / : ; < = > ? @ [ ] ^ _ ` { | } ~
  • Your password may also include spaces but cannot start or end with a space

 

  • Cross referencing known and breached passwords

    By default, Vivantio will also check for known and breached password to improve the security of all Vivantio user accounts for the main application and the Self Service Portal. This service is provided by Have I Been Pwned.

  • Account Lockouts

    After 5 failed login attempts that user account will be locked out and a Local Vivantio Administrator will need to unlock the account.

  • Notification of Incorrect Password entered

    For security reasons the application will not explicitly let the user know if they have entered the incorrect username or password. Indicting the username exists, but the password is wrong is a great indicator to malicious attackers that they know or are in possession of a valid username. This can then lead to a password hacking attempt on that username. 

 

Password Resets

If the user is unable to remember their Vivantio Username or Password, they will be presented with the screen below.

 

When they click on the above highlighted link they will be taken to this page:

When the user requests a password reset in this way, they will receive an email that contains a single use code.

Please note:

1) If unused, the code will expire after 24 hours for the Self Service Portal & 3hrs For the Main Application for security reasons

2) The links can only be clicked once, and the password reset on that initial click.

Changing a Password for the main application in the Admin Area

To change a password for a user in the main application navigate to the

Admin Area > Setup > User Management > Users > Select User > Change Password

Enter a new password

Please Note: this will not notify the user by email automatically and should communicated securely with the user

 

Changing a Password for the Self Service Portal

Navigate to the Contact and if their Self Service Login is enabled then the below 2 highlighted options will be available

When using the ‘Change Self Service Password’ a new password will need to be entered. The local administrator also has the option from this screen to email the user to notify them of this change using an email template which can be configured locally.

When the ‘Reset Self Service Password’ is used the following screen will be presented, a notification will be automatically sent to the User once ‘OK’ is clicked

 

Users Changing their own Passwords

If the User wishes to change their password in the main application, they can do this by navigating to their name in the top right hand corner of their screen > Change Password

The User will then be able to change their existing password

If the User wishes to change their password in the Self Service Portal, they can do this by navigating to their name in the top right hand corner of their screen > My Profile

 

Troubleshooting Password Reset Problems

Password Reset Emails Not Received

If the user has requested a Password Reset using the functionality above but has not received a password reset link via email, this could be caused by the email being moved to a junk folder or blocked by the customers exchange server.

In the first instance, please ask the user to check their Junk folder. If the email is not present, the user will need to contact their local Vivantio administrators to "change" their password from within the system.

Password reset links are already expired

Some email Spam systems will check and follow links in emails and if this happens this could expire the link immediately and as the link can only be used once this will prevent the user successfully resting their password. In this case we would recommend the customer speaking to their internal IT department or email provider to help prevent this from happening.

All Administrators are locked out of the Vivantio system or cannot reset their passwords

Please contact the Vivantio Support Team and they will be able to go through an identity verification process to help gain access to the customer’s Vivantio system. We do recommend there is more than 1 Administrator set up on a customer system to prevent this happening.