Storefronts that allow multiple customer accounts to share a single email address can now direct a password reset to the exact account intended. Storefronts with usernames enabled gain a username and keyphrase self-service reset flow, and administrators can generate a one-time, account-specific reset link from the customer record. A new setting controls whether the self-service reset page is available, and an optional notification email can be sent whenever a password changes.
Problem
When several accounts shared one email address, the previous forgot password flow looked up only the email address and always resolved to the earliest-created account, both when the reset was requested and when the emailed link was opened. There was no way to target a specific account, so self-service resets were unreliable on shared-email storefronts.
Environment
Applies to storefronts with usernames enabled. Storefronts without usernames enabled are unaffected and keep the existing email-based self-service reset.
Configuration
Step 1: Open the Customer settings page
Log in to the Admin portal and go to Configuration > Settings > Customer Settings. This is where the new Enable forgot password page setting lives alongside the existing username and login controls.

Step 2: Review the new Enable forgot password page setting
Find the Enable forgot password page setting, which sits just under the 'Usernames' enabled setting. It is enabled by default. Leave it enabled to keep the self-service reset request page available. Clear it to hide the self-service page so that passwords can only be reset using an admin-generated link. This setting gates only the self-service request page — an already-issued reset link keeps working even when the setting is disabled.

Step 3: Confirm the 'Usernames' enabled prerequisite
The username and keyphrase self-service reset flow only applies when 'Usernames' enabled is turned on, on this same Customer settings page. When usernames are enabled, the forgot password page asks for a username and a keyphrase (a value chosen by the customer, at least 5 characters, embedded in the reset link and re-entered before the password can be changed). Storefronts without usernames enabled are unaffected and keep the existing email-based self-service reset.

Step 4: Generate an account-specific reset link from the customer record
To reset the password for a specific account, go to Customer management, open the customer record, and use the Generate link button in the Password reset link panel. The link is minted for that one account, auto-copied to your clipboard, and stored against the account (similar to MFA). Share it privately through a trusted channel as the system does not send it automatically. The link is valid for one day, and generating a new link for the same account invalidates any earlier one. This action is available to any role with the edit-customer permission.


Step 5: Optionally enable the Password Changed email template
A Password Changed email template is available, but disabled by default. To notify customers whenever their password changes by any means, go to Email Message Templates, open the Password Changed template, and enable it.
Settings Added or Changed
Enable forgot password page (Configuration → Settings → Customer Settings): controls whether the self-service password reset request page is accessible. Default: enabled. When disabled, the page is hidden and only admin-generated links can be used.
Password Changed email template (Email Message Templates): added automatically on deployment, disabled by default. Enable it to notify customers when a password changes by any means.
An activity log entry type for admin reset-link generation is added automatically on deployment.