- Free Edition
- Quick Links
- MFA
- Microsoft Entra ID Security
- Self-Service Password Management
- Single Sign-On
- Password Synchronizer
- Password Policy Enforcer
- Employee Self-Service
- Reporting and auditing
- Integrations
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- Exchange Reporter Plus Exchange Server Auditing & Reporting
- EventLog Analyzer Real-time Log Analysis & Reporting
- M365 Manager Plus Microsoft 365 Management & Reporting Tool
- DataSecurity Plus File server auditing & data discovery
- RecoveryManager Plus Enterprise backup and recovery tool
- SharePoint Manager Plus SharePoint Reporting and Auditing
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools
The problem with password resets at the service desk
Password resets are one of the most frequent and repetitive requests a service desk handles. They consume IT staff time that should go toward higher-priority work and keep users locked out of systems while they wait in a queue.
The obvious answer is self-service password reset. But many organizations hesitate, particularly for privileged accounts or users with access to sensitive systems, because self-service removes the human check. What they may not realize is that the human check at a traditional service desk is already the weakest link.
When an agent resets a password over the phone, identity is verified through knowledge-based authentication such as a mobile number, a department name, or a manager’s name. This is information that is rarely hard to find. A social media profile or a prior data breach is often enough for an attacker to answer correctly. In 2025, Marks and Spencers experienced a breach in which attackers used social engineering to obtain a credential reset from a third-party service desk, exfiltrated the Active Directory database, deployed ransomware, and caused an estimated £300 million in damages. The agent did exactly what they were trained to do. The verification process itself was the failure point.
The answer is not to choose between self-service and help desk oversight. It is to combine both, backed by MFA-enforced identity verification at every step.
How approval-based help-desk-assisted password reset helps
ADSelfService Plus places an approval-based workflow between a user’s self-service request and the final change in Active Directory. Users initiate the password reset or account unlock themselves, from any device, at any time. They verify their identity through Active Directory attribute-based security questions, and the request is routed to a technician for review. The change is written to Active Directory only after the technician approves it. For directory self-update and mail group subscription, users authenticate through MFA at portal login before initiating the request, which then follows the same approval process.
The workflow integrates with ADManager Plus, which serves as the workflow engine and the technician-facing approval console. Admins configure rules per OU or Active Directory group; standard users can self-reset freely while privileged accounts, contractors, and remote workers pass through the approval step. Different rules can apply to different parts of the directory simultaneously. The model covers four self-service action types: password reset, account unlock, directory self-update, and mail group subscription. Every action is recorded in full, creating an audit trail that supports compliance with SOX, HIPAA, the PCI DSS, and the GDPR.
“With ADSelfService Plus, we were able to implement a solution that is both secure and easy for users to adopt.”
– Daniel Webb, IT infrastructure support specialist at Dryden Mutual
How help-desk-assisted self-service works
- The user initiates the request by:
- Opening the self-service password reset or account unlock portal from the Windows, macOS, or Linux login screen portal; web browser; or mobile app and providing their username
- Entering the latest directory attribute details, or subscribing to the required mail groups after accessing the ADSelfService Plus user portal
- For self-service password reset and account unlock, the user has to additionally answer Active Directory attribute-based security questions to verify their identity.
- The request is automatically routed to ADManager Plus and the user receives confirmation it has been sent.
- A service desk agent approves or rejects the request according to the configured workflow rules.
- If approved, the user receives an email link to reset their password or unlock their account. For directory self-update and mail group subscription, the change is written automatically to Active Directory.
- The full transaction is recorded in ADSelfService Plus reports, and the user is notified of the outcome.
For self-service password reset and account unlock, users authenticate through MFA before completing the reset. For directory self-update and mail group subscription, users authenticate through MFA at portal login before initiating the request.
Supported authentication methods
ADSelfService Plus supports 20 authentication methods for MFA, including FIDO2 passkeys (Windows Hello, Apple Touch ID, Android biometrics, and FIDO2/U2F-compliant security keys such as YubiKey and Google Titan Key), TOTP authenticator apps (Google Authenticator, Microsoft Authenticator, Zoho OneAuth, and custom TOTP apps), push notifications via the ADSelfService Plus mobile app, QR code-based authentication, biometric authentication via Android or iOS devices, SMS OTP, email OTP, RSA SecurID, Duo Security, Azure AD MFA, RADIUS, SAML-based IdP authentication (Okta, OneLogin, and others), smart card authentication, and Active Directory attribute-based security questions.
Admins select and enforce required methods per OU or group, and can mandate specific factors, such as requiring a hardware security key for privileged account resets, independently of the methods applied to standard users.
Benefits of approval-based help-desk-assisted password reset
- Eliminate hold times: Users submit reset requests online at any hour without waiting in a call queue.
- Reduce ticket volume: Fewer password reset requests reach the service desk, freeing agents for higher-priority work.
- Replace verbal verification with security questions: Users verify their identity through the portal before any request reaches a technician, removing human interaction.
- Give technicians verified evidence: Agents review confirmed authentication data, not a self-reported claim.
- Apply granular approval policies: OU- and group-based rules enforce different requirements for privileged users, contractors, and remote workers.
- Prevent unauthorized changes: Users cannot bypass the approval step or write changes directly to Active Directory.
- Log every request in full: Each transaction records the requesting user, authentication methods used, approving technician, and timestamp of each step.
- Support compliance requirements: Records meet audit needs for SOX, HIPAA, the PCI DSS, and the GDPR.
- Remove the dependency on VPN or phone: Remote workers and employees on unmanaged devices initiate resets entirely online.
Frequently asked questions
In fully self-service password reset, the user completes the entire reset after verifying their identity—no technician is involved. In help-desk-assisted password reset, a service desk agent must review and approve the request before the reset is completed. The assisted model is suited to organizations with strict identity security requirements or for specific user groups—such as Active Directory administrators or users with access to sensitive systems—where fully autonomous resets carry too high a risk.
Yes. Admins configure approval workflow rules per OU or Active Directory group in ADManager Plus. Standard users can be permitted to complete self-service resets directly, while privileged accounts or specific departments can be required to pass through the help desk approval step. Multiple rules for different user segments can run simultaneously.
ADSelfService Plus supports 20 authentication methods for MFA. These include FIDO2 passkeys (Windows Hello, Apple Touch ID, Android biometrics, YubiKey, and Google Titan Key), TOTP apps, push notifications, biometric authentication, SMS OTP, email OTP, RSA SecurID, Duo Security, RADIUS, SAML-based IdP authentication, smart card authentication, and Active Directory attribute-based security questions. Admins configure required methods per OU or group and can make specific factors mandatory.
The approval workflow runs through ADManager Plus, which acts as the workflow engine and technician-facing approval console. Admins create and manage workflow rules in ADManager Plus, and technicians approve or reject requests from the ADManager Plus interface. ADSelfService Plus also integrates with ServiceDesk Plus, but that integration allows users to raise general IT support tickets from the self-service portal—it is a separate feature with no role in the password reset approval workflow.
ADManager Plus must be integrated with ADSelfService Plus for the approval workflow to function. It can be installed separately and then integrated, or you can deploy AD360—ManageEngine’s integrated IAM solution—which bundles both components and configures the integration automatically.
Each request generates a record in ADSelfService Plus reports that includes the requesting user, the authentication methods used, the approving or rejecting technician, the timestamp of each step, and the final outcome. Records can be exported for compliance review.
Highlights of ADSelfService Plus
Password self-service
Unburden Windows AD users from lengthy help desk calls by empowering them with self-service password reset and account unlock capabilities.
Multi-factor authentication
Enable context-based MFA with 20 different authentication factors for endpoint, application, VPN, OWA, and RDP logins.
One identity with single sign-on
Get seamless one-click access to more than 100 cloud applications. With enterprise single sign-on (SSO), users can access all their cloud applications using their Windows AD credentials.
Password and account expiry notifications
Notify Windows AD users of their impending password and account expiry via email and SMS notifications.
Password synchronization
Synchronize Windows AD user passwords and account changes across multiple systems automatically, including Microsoft 365, Google Workspace, IBM iSeries, and more.
Password policy enforcer
Strong passwords resist various hacking threats. Enforce Windows AD users to adhere to compliant passwords by displaying password complexity requirements.