Pricing  Get Quote
 
 
 

Why manual password resets cost more than organizations realize

Password-related requests account for 20 to 50 percent of all help desk tickets in a typical enterprise. Gartner estimates that each manually handled password reset costs an organization approximately $70, factoring in IT staff time, user downtime, and overhead. Across hundreds or thousands of employees, those individual incidents add up quickly.

The administrative burden falls heaviest on organizations running hybrid identity environments. When employees authenticate across on-premises Active Directory (AD) and cloud platforms like Microsoft Entra ID (formerly Azure AD) or Google Workspace, a single expired password can generate login failures across multiple connected applications before the help desk even opens the ticket. IT engineers are pulled away from higher-priority work, and users lose productive time waiting for a resolution that should take seconds.

Scheduled password reset automation removes this friction entirely.

Password reset automation with ADSelfService Plus

ManageEngine ADSelfService Plus enables automatic password reset for expired AD accounts, automated account unlock for users locked out after failed login attempts, and on-demand self-service password reset (SSPR) for individual users. The product connects directly with your identity infrastructure to execute each of these without manual IT intervention at the time of the event.

Every automated reset enforces your configured password policy, synchronizes the new credential across all connected applications, logs the action in a complete audit trail, and notifies the affected user.

For organizations with hybrid identity environments, ADSelfService Plus extends the same password reset automation capabilities to Microsoft Entra ID, Google Workspace, and Microsoft 365 from a single administration console.

How automated password reset works in ADSelfService Plus

  1. ADSelfService Plus scans the domain at configured intervals and identifies accounts with expired passwords, soon-to-expire credentials, and active lockouts.
  2. For scheduled resets, the system generates a policy-compliant password and applies it directly to the target AD account. No admin action is required at execution time.
  3. For user-initiated resets, the user's identity is verified through multi-factor authentication (MFA) before the reset proceeds. Over 20 authentication methods are supported, including FIDO passkeys, biometrics, Microsoft Authenticator, and YubiKey.
  4. Once the reset is complete, ADSelfService Plus propagates the new password to all integrated platforms (AD, Microsoft Entra ID, Google Workspace, and others) through cross-system password synchronization.
  5. Every reset event is captured in an audit trail log, recording the account, timestamp, initiating policy, and outcome for compliance review.
  6. The user receives an email or SMS notification confirming their updated credentials and login instructions.

Password reset automation capabilities in ADSelfService Plus

Scheduled automatic password resets

IT admins configure automatic password reset tasks to run at defined intervals across targeted domains, organizational units (OUs), or security groups. ADSelfService Plus scans the entire domain, generates reports on expired and soon-to-expire passwords, and executes the resets on schedule, maintaining credential hygiene proactively rather than reactively. Any user added to a targeted group is automatically included in the scope without additional configuration.

Automated account unlock

Alongside scheduled password resets, ADSelfService Plus detects and resolves account lockouts caused by repeated failed login attempts. Locked-out users regain domain access automatically, without waiting for an IT admin to intervene.

MFA-secured identity verification

Every self-service password reset request is gated by multi-factor authentication to prevent unauthorized account access. ADSelfService Plus supports over 20 authentication methods, including:

  • FIDO passkeys
  • Fingerprint biometrics
  • Microsoft Authenticator
  • Google Authenticator
  • Duo Security
  • YubiKey Authenticator
  • Custom TOTP apps

Fine-grained MFA policies allow admins to apply stronger authentication requirements for privileged accounts or departments handling sensitive data.

Password policy enforcement during automated resets

When ADSelfService Plus executes an automated password reset, it generates credentials that comply with your configured password policy enforcer settings. Admins can restrict:

  • Consecutive repetition of the same character.
  • Strings derived from the username, dictionary words, patterns, or palindromes.
  • Passwords that appear in known breach databases (via Have I Been Pwned integration).

Mandatory character requirements (lowercase, uppercase, numeric, special, and Unicode characters) ensure every auto-generated password meets the complexity standards required by NIST, the GDPR, the PCI DSS, the CJIS, and other applicable regulatory frameworks.

Cross-system password synchronization

A reset that updates AD credentials but leaves cloud applications out of sync creates a different disruption. When ADSelfService Plus resets a password, it instantly propagates the change to all integrated platforms. Password synchronization covers:

  • AD (on-premises)
  • Microsoft Entra ID
  • Google Workspace
  • Microsoft 365
  • OpenLDAP and AD LDS
  • IBM AS400, HP UX, and other connected systems

This eliminates mismatched credentials and the secondary help desk contacts they generate.

Proactive password expiration notifications

Before accounts reach their expiration date, ADSelfService Plus sends automated notifications to end users and IT admins via email and SMS. After an automated reset completes, users receive a confirmation message with their updated credentials and instructions for their next login. These notifications reduce the number of users who encounter a lockout in the first place and cut the volume of password-expiration-related help desk tickets.

Complete audit trail and reporting

Every automated password reset, account unlock, scheduled reset execution, and self-service reset attempt is captured in a detailed audit trail. ADSelfService Plus generates reports covering:

  • Soon-to-expire and expired password accounts.
  • Locked-out account history.
  • Automated reset execution logs (account, timestamp, policy, outcome).
  • Self-service reset activity by user, domain, or group.
  • Failed authentication attempts during SSPR.

These reports give IT teams the visibility required for internal audits and regulatory compliance reviews.

"ADSelfService Plus has saved our IT support staff many hours of responding to locked out users' accounts and forgotten passwords."

—Edwin Proano, technician at Hirsch Pipe & Supply

Automated password reset vs. self-service password reset

These two capabilities solve different problems and work best when deployed together.

  Password reset automation Self-service password reset (SSPR)
Who triggers it IT admins configure the rules once, and ADSelfService Plus runs the resets automatically. The end user initiates the reset on demand when they need to recover access.
When it runs At configured intervals. Whenever a user is locked out or has forgotten their password and requests a reset.
User involvement No user action is required at execution time. The user verifies their identity through MFA, then sets a new password themselves.
Password set by The system generates a password that complies with the configured password policy. The user chooses their own password, guided by the displayed policy requirements.
Best suited for Proactive credential hygiene, bulk resets after a suspected breach, and password age policy compliance across domain accounts. Individual account recovery where a user has forgotten their password or been locked out.
Help desk calls eliminated Expired password tickets and requests to reset passwords across groups of accounts. Forgotten password calls and individual lockout tickets that arrive one at a time.

ADSelfService Plus delivers both capabilities in a single platform, so organizations can address proactive credential hygiene through scheduled automation and reactive password recovery through self-service, without managing separate tools.

How to set up password reset automation in ADSelfService Plus

  1. Log in to ADSelfService Plus with administrator credentials.
  2. Navigate to Configuration > Self-Service > Policy Configuration > Advanced.
  3. Open the Automation tab within the Advanced settings panel.
  4. Define the reset frequency, target domains, OUs, or groups, and the password generation rules the automatic password reset task should follow.
  5. Optionally, enable Force password change at next logon to prompt users to set their own password after an automatic reset.
  6. Click OK to save the configuration.
Automation tab in ADSelfService Plus showing weekly automatic password reset and next-logon password change
Configuring automatic password reset in ADSelfService Plus

Why organizations choose ADSelfService Plus for password reset automation

  • Measurable reduction in help desk costs: Each manually handled reset costs an average of $70. Automating resets and enabling self-service recovery recovers that cost at scale across IT staff time and direct ticket overhead.
  • Lower help desk ticket volume: Password and account lockout tickets typically represent 20 to 50 percent of total help desk call volume. ADSelfService Plus removes these from the queue, freeing admins for higher-priority work.
  • Hybrid identity coverage: ADSelfService Plus manages password reset automation across on-premises Active Directory, Microsoft Entra ID, and Google Workspace from a single administration console.
  • Compliance-ready audit logging: Every automated and self-service reset is recorded in a detailed audit trail supporting NIST, GDPR, PCI DSS, and CJIS requirements.
  • Granular scope and targeting: Automation can be scoped to specific domains, OUs, or security groups, with privileged accounts excluded where needed.
  • Users stay informed: Proactive expiration notifications and post-reset confirmations via email and SMS keep users aware of their credential status and reduce unnecessary help desk contacts.
 

FAQ

What is password reset automation?

Password reset automation is the use of software to automatically execute password resets and account unlocks across user accounts on a defined schedule or in response to account events, without requiring manual IT action. The resulting automatic password reset is policy-enforced, cross-system synchronized, logged in an audit trail, and confirmed to the user via notification, with no IT involvement required.

How much does a manual password reset cost?

Gartner estimates the average cost of a manually handled password reset at approximately $70 per incident, accounting for IT staff time, user downtime, and organizational overhead. Since password-related tickets typically represent 20 to 50 percent of total help desk volume, the cumulative cost across a large organization is substantial.

How is password reset automation different from self-service password reset (SSPR)?

Automated password reset runs on a schedule or in response to an event trigger, applying policy-compliant credentials to accounts without any user or admin action at execution time. Self-service password reset (SSPR) allows an individual user who has forgotten their password to reset it on demand after verifying their identity through MFADSelfService Plus supports both capabilities in one platform.

Does ADSelfService Plus support password reset automation for Microsoft Entra ID and Google Workspace?

Yes. ADSelfService Plus supports password reset automation and synchronization for AD, Microsoft Entra ID (formerly Azure AD), Google Workspace, and Microsoft 365, propagating credential changes across all connected platforms from a single administration console.

Is there an audit log of every automated password reset?

Yes. ADSelfService Plus logs every automated password reset, account unlock, and self-service reset event in a complete audit trail, capturing the account affected, the timestamp, the triggering policy, the authentication method used, and the outcome.

Can admins limit automated resets to specific user groups?

Yes. IT admins can configure password reset automation to apply only to users in specified domains, OUs, or security groups. Any user added to a targeted group is automatically included in the scope. Privileged accounts or sensitive groups can be excluded from scheduled resets entirely.

ADSelfService Plus trusted by

FREE TRIAL