The Password Invalidator is a feature in ZTrust that helps keep user accounts secure. It automatically forces users to change their login passwords after a predefined time period.
This ensures that weak, old, or compromised passwords are regularly updated, keeping your organization's data safe.
Why Use Password Invalidator? (Use Cases)
Admin defines a password validity period (e.g., 30 days, 45 days, 60 days).
When the period ends, the Password Invalidator forces the user to reset their password on the next login.
Set up warning emails to notify users before their password expires, so they can be aware and update their password on time.
Enhanced Security
The system makes you change your password regularly so that old or weak passwords don’t put your account at risk.
Compliance with Company Policies
Some organizations require you to change your password after a certain time.
This feature automatically enforces those rules.
Reduce Unauthorized Access Risks
If someone manages to steal your password, they can’t use it for long because it will expire after the set time.
Warning Notifications
You’ll receive notifications before your password expires, so you have time to update it without being locked out.
Step 1 – Login to ZTrust Admin Console
Open your ZTrust Admin Console in your browser.
Sign in with your admin credentials.
Fig. 4.16.a: Welcome page of customer_demo realm
Step 2 – Enable Password Invalidator in Events
Navigate to Realm Settings → Events.
In the Event Listener dropdown, selectpassword-invalidation.
Fig. 4.16.b: Navigating to Realm Settings ⇒ Events and adding 'password_invalidation' to event listeners
Step 3 – Configure the Scheduler & Notifications
Go to Realm Settings → Authentication.
Go to Policies Tab → Password Policy
Fig. 4.16.c: Navigating to Authentication ⇒ Policies ⇒ Password Policy
In Password Invalidator execution: Click on Add policy and define the required policy
Set the password expiry duration (e.g., 30 days, 45 days).
Set the Minimum length, Maximum length, Special characters, Digit, Uppercase and Lowercase and the policy to secured their password.
Step 4 – Create a Custom Authentication Flow
Go to Realm Settings → Authentication.
Click on the Flows tab.
Fig. 4.16.d: Navigating to Authentication ⇒ Flows and duplicate browser form
Create a duplicate in browser flow → Name "password invalidator notification" an click on Duplicate
Fig. 4.16.e: Duplicating the browser flow for Password Invalidation notification
Click on Add execution and find Password Invalidator from the execution