> For the complete documentation index, see [llms.txt](https://enterprise.hideez.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://enterprise.hideez.com/hideez-server-integration/microsoft-entra-id/import/administrator-initiated-manual-password-changes.md).

# Administrator-Initiated Manual Password Changes

### Overview

This guide describes how administrators can manually change or generate a new password for a domain user in Hideez Enterprise Server.

Manual password management is required when automatic password updates are not configured, or when immediate, one-time intervention is needed.

### Prerequisites

Before manually changing a user's password, ensure the following conditions are met:

1. [You are logged in as a user with administrator rights in Hideez Enterprise Server.](https://enterprise.hideez.com/hideez-server-integration/microsoft-entra-id)
2. [Integration with Entra ID is properly configured in Hideez Enterprise Server.](https://enterprise.hideez.com/hideez-server-integration/microsoft-entra-id)
3. The user must have a Hideez Key with one of the following statuses: [`"Ready"`](/hideez-enterprise-server/keys-management/keys-statuses.md#ready), [`"Active"`](/hideez-enterprise-server/keys-management/keys-statuses.md#active), or [`"Reserved"`](/hideez-enterprise-server/keys-management/keys-statuses.md#reserved).
4. [The workstation is joined to the Entra ID.](https://learn.microsoft.com/en-us/entra/identity/devices/device-join-out-of-box)
5. [The Hideez Client is installed on the user’s workstation.](https://enterprise.hideez.com/hideez-client-app/windows-deployment/set-up-hideez-client-app)
6. [The workstation is approved in the Hideez Enterprise Server (see the *Workstations* section).](https://enterprise.hideez.com/hideez-enterprise-server/workstations/how-to-add-and-approve-workstations)

### Use Case: Resetting a Forgotten Password for a Domain User

An employee contacts IT support after being locked out of their domain account due to a forgotten password.\
The administrator needs to manually reset the password in Hideez Enterprise Server to restore access.

### Flow:

* The administrator opens the **Employees** section, finds the user, and clicks **Edit Password**.
* A temporary password is manually set or a new strong random password is generated.
* The new password is updated in the user's Active Directory account.
* When the Hideez Key is connected to the workstation, the new password is securely written to the key.
* The user logs in using the Hideez Key and can change their domain password through the Hideez Client interface.

{% hint style="info" %}
**Important:**\
After changing the password manually, neither the user nor the administrator will be able to view or retrieve the new password.
{% endhint %}

### Steps for Manual Password Change

**Step 1: Open the user profile**

* Navigate to the **Employees** section in Hideez Enterprise Server.
* Select the target user and click **Edit Password**.

<figure><img src="/files/xa5trkQ0lUunSrDnYis2" alt="" width="563"><figcaption></figcaption></figure>

**Step 2: Edit the account password**

Click **Edit password**, type the new password, confirm it, and then click **Save**.

<figure><img src="/files/KVDFpFIC8u4hUGGuvep4" alt="" width="563"><figcaption></figcaption></figure>
