Join our Newsletter — 33% off our NHI Course
Home› Glossary› NHI Lifecycle Management› Change Password At Logon
NHI Lifecycle Management

Change Password At Logon

← Back to Glossary
By NHI Mgmt Group Updated September 26, 2026 Domain: NHI Lifecycle Management

Change Password At Logon is an account setting that forces a user to choose a new password during the next sign-in. Administrators use it after resets, onboarding, or policy-driven password changes. In Active Directory, this setting helps ensure that temporary or administrator-assigned passwords do not remain in use.

What the setting does and why it exists

Change Password At Logon is a password policy setting that forces the user to replace a temporary or administrator-assigned password at the next sign-in. It is commonly used after resets, onboarding, or any action that deliberately hands out a short-term credential.

The core purpose is to prevent an issued password from becoming a standing secret. That matters because temporary passwords are often disclosed out of band, set to something memorable, or known by support staff before the user changes them.

Where it fits in account lifecycle and access control

This setting sits at the boundary between account provisioning and normal use. Administrators use it to complete a secure handoff: the account becomes usable only after the user establishes a private password that is not shared with the administrator.

In directory environments, the setting is part of the broader identity lifecycle, not a standalone protection. It works alongside reset workflows, onboarding controls, and account recovery procedures to ensure the first interactive login ends the temporary credential period.

Security value and common failure modes

Its security value is strongest when the initial password is temporary, has been communicated through a controlled channel, and is intended for one-time use. If that password is left in place, the account may remain exposed to reuse, disclosure, or unauthorized access after a reset.

The setting is easy to misunderstand because it does not make a password strong by itself. It only changes when the user must replace it, so the surrounding reset process, password quality rules, and verification of the requester still matter.

Change Password At Logon is not the same as forcing periodic password expiration. Expiration concerns when a password later becomes invalid; this setting concerns the very next sign-in after a reset or first assignment.

It is also distinct from password history, complexity, or minimum age controls. Those controls shape what the new password must look like and how often it can be changed, while this setting determines whether the user must set a new password immediately.

Risk and Threat Considerations

Leaving a temporary password active creates an obvious exposure window, especially after help desk resets, shared onboarding processes, or bulk account setup. If the first-login change is skipped or misconfigured, the account can remain usable by anyone who learned the issued password.

Failure mechanism: the temporary credential remains valid beyond its intended handoff point, so the account never transitions from administrator-known access to user-controlled access.

Impact: unauthorized access, account takeover, or continued reuse of a reset password can follow, particularly when the initial password was delivered through a channel with limited confidentiality.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCovers issuing, changing, and expiring authenticators used in password reset flows.
IA-2 — Identification and Authentication (Organizational Users)Applies because the setting governs how a user completes initial authentication after a reset.
AC-2 — Account ManagementApplies because forcing a change at logon is part of secure account provisioning and reset handling.
Recommendation — Use IA-5 to require immediate replacement of temporary passwords and manage authenticator lifecycle. Use IA-2 to ensure users must authenticate with their own credentials after first logon. Use AC-2 to align account provisioning and reset procedures with first-logon password change requirements.
ISO/IEC 27001:2022A.5.15 — Access controlSupports policy and rule-setting for how accounts transition from temporary to user-owned access.
Recommendation — Define access-control rules that require password replacement after reset or first assignment.

Practitioner Guidance

Governance implication: treat this setting as part of the reset and onboarding control chain, not as an optional usability toggle. Where administrators routinely issue temporary passwords, make sure the directory policy and the operational runbook both assume the first sign-in is the moment the user must own the credential.

What to watch for: reset workflows that create accounts, send a temporary password, but do not reliably force an immediate change. That pattern usually signals a process gap, not just a policy issue.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org