9/3/2026
Reset passwords and unlock accounts with secure self-service
When users forget their password, lose their usual sign-in method or find that their account has been locked, IT support often needs to intervene manually. This creates delays, increases support costs and reduces productivity.
With Fortified ID Password Reset, organizations can provide secure self-service for password resets and account recovery in Microsoft Active Directory, Microsoft Entra ID and Google. The solution can also write to multiple data sources in the same flow, which is valuable in hybrid environments where user accounts span several platforms.
Challenge
AD, Entra ID and Google are often used side by side to manage user accounts and access to computers, cloud services and business systems. If a user forgets their password or their account is locked, large parts of their digital workplace can become unavailable.
Traditionally, the user must contact the service desk, which then needs to verify their identity, reset the password or unlock the account, and document the action manually. The process takes time, adds to the support workload and can be particularly costly outside normal working hours.
Solution
Fortified ID Password Reset lets users restore access themselves. Before any change is made, the user’s identity is verified using an authentication method approved by the organization, such as:
- BankID
- Freja eID
- SITHS eID
- EFOS
- A European eID through eIDAS
- A certificate or security key
- A one-time password
- An existing authentication service or Identity Provider
After successful verification, the solution can reset the password and, depending on the target platform and configuration, unlock the account. The new password is checked against the organization’s centrally defined password policy.
One shared flow across multiple platforms
Fortified ID Password Reset can be used in on-premises, cloud-based and hybrid identity environments:
- Microsoft Active Directory: Reset passwords and unlock locked AD accounts.
- Microsoft Entra ID: Restore access to the user’s cloud account and connected Microsoft services.
- Google: Reset passwords for users in services such as Google Workspace and Google for Education.
- Hybrid environments: Update passwords in multiple data sources as part of the same recovery process.
This allows the organization to offer a consistent self-service flow even when users are spread across different directories or platforms.
How it works
-
The user opens the self-service portal
The user chooses to reset their password or restore access to their account. -
The identity is verified
The user identifies themselves with an approved eID or another strong authentication method. -
The correct account is identified
The identifier from the authentication method is matched to a selected attribute in AD, Entra ID or Google. -
The account is recovered
The solution unlocks the account where applicable and allows the user to create a new password. -
The password policy is checked
The user immediately sees whether the new password meets the organization’s requirements. -
The data sources are updated
The new password is written to the connected platform or platforms, and the user can return to work.
In one municipal use case, we describe how an eID is linked to the user’s account through an AD lookup and how the integration with the authentication service can be based on SAML 2.0. Read about password resets with eID for employees at a Swedish municipality.
A straightforward alternative to Specops Password Reset
For organizations that use Specops Password Reset, or plan to replace it, Fortified ID Password Reset can be a straightforward alternative.
Both solutions address self-service password resets in AD and Entra ID environments. Fortified ID also makes it possible to create a broader, unified flow for AD, Entra ID and Google, using strong authentication methods that are well established in Swedish organizations.
When moving to a new solution, the organization’s existing recovery flows, identity mappings, password policies and data sources can be mapped and transferred to a new self-service flow. This provides an opportunity to consolidate the solution and reduce the number of separate components in the identity environment. The exact migration approach is adapted to the Specops features and client components the organization currently uses.
Contact us for a competitive upgrade.
Results and benefits
- Reduced service desk workload
- Shorter interruptions for users
- Strong identity verification before recovery
- One shared self-service flow for AD, Entra ID and Google
- Support for the organization’s existing password policies
- The ability to update multiple data sources
- Customizable branding and language
- Logging, monitoring and traceability
- A modern alternative for organizations that want to replace Specops Password Reset
Would you like to replace your current solution or introduce self-service for the first time? Contact Fortified ID and we will help you design a secure recovery flow for AD, Entra ID and Google.