Password Change


This page contains recommendations for the implementation of password change functionality.


  • Limit the number of attempts to change the password for a certain period, see the Vulnerability Mitigation: Brute-force page.

  • Ask for a second factor when a user changes a password, if a multi-factor authentication is enabled.

Last updated