Picture of Reset the right password when accounts share an email address

Reset the right password when accounts share an email address

Storefronts that allow multiple customer accounts to share a single email address can now direct a password reset to the exact account intended. Storefronts with usernames enabled gain a username and keyphrase self-service reset flow, and administrators can generate a one-time, account-specific reset link from the customer record. A new setting controls whether the self-service reset page is available, and an optional notification email can be sent whenever a password changes.

Problem

When several accounts shared one email address, the previous forgot password flow looked up only the email address and always resolved to the earliest-created account, both when the reset was requested and when the emailed link was opened. There was no way to target a specific account, so self-service resets were unreliable on shared-email storefronts.


Environment

Applies to storefronts with usernames enabled. Storefronts without usernames enabled are unaffected and keep the existing email-based self-service reset.

  • Prerequisite: Usernames enabled must be turned on for the username and keyphrase reset flow.

Configuration


Step 1: Open the Customer settings page

Log in to the Admin portal and go to Configuration > Settings > Customer Settings. This is where the new Enable forgot password page setting lives alongside the existing username and login controls.

AC-481_customer_settings_toggles.jpg

Step 2: Review the new Enable forgot password page setting

Find the Enable forgot password page setting, which sits just under the 'Usernames' enabled setting. It is enabled by default. Leave it enabled to keep the self-service reset request page available. Clear it to hide the self-service page so that passwords can only be reset using an admin-generated link. This setting gates only the self-service request page — an already-issued reset link keeps working even when the setting is disabled.

AC-481_enable_forgot_password_setting.jpg

Step 3: Confirm the 'Usernames' enabled prerequisite

The username and keyphrase self-service reset flow only applies when 'Usernames' enabled is turned on, on this same Customer settings page. When usernames are enabled, the forgot password page asks for a username and a keyphrase (a value chosen by the customer, at least 5 characters, embedded in the reset link and re-entered before the password can be changed). Storefronts without usernames enabled are unaffected and keep the existing email-based self-service reset.

AC-481_storefront_forgot_password_username_keyphrase.jpg

Step 4: Generate an account-specific reset link from the customer record

To reset the password for a specific account, go to Customer management, open the customer record, and use the Generate link button in the Password reset link panel. The link is minted for that one account, auto-copied to your clipboard, and stored against the account (similar to MFA). Share it privately through a trusted channel as the system does not send it automatically. The link is valid for one day, and generating a new link for the same account invalidates any earlier one. This action is available to any role with the edit-customer permission.

AC-481_admin_generate_reset_link.jpgAC-481_reset_password_page.jpg

Step 5: Optionally enable the Password Changed email template

A Password Changed email template is available, but disabled by default. To notify customers whenever their password changes by any means, go to Email Message Templates, open the Password Changed template, and enable it.

Settings Added or Changed

  • Enable forgot password page (Configuration → Settings → Customer Settings): controls whether the self-service password reset request page is accessible. Default: enabled. When disabled, the page is hidden and only admin-generated links can be used.

  • Password Changed email template (Email Message Templates): added automatically on deployment, disabled by default. Enable it to notify customers when a password changes by any means.

  • An activity log entry type for admin reset-link generation is added automatically on deployment.

Incomplete
Alternate Search Terms

forgot password reset password shared email username keyphrase reset generate password reset link enable forgot password page