Start here Guide ready 11 min guide

Set up, reset, and change a password

Create a first password, replace a temporary credential, change your own password, recover from failed attempts, and complete authorized administrator resets safely.

Use this guide to choose the correct password workflow, complete it without exposing a credential, and verify that the account returns to the intended organization and least-privilege workspace.

01 / Choose

Choose the correct password workflow

The safest path depends on whether the user has a valid session, knows the current password, received an invitation, or needs an authorized administrator.

Situation Correct workflow Who acts
New account received a Create password email Open the newest one-time setup link and create the first password Invited user
New or reset account received a temporary password Sign in, complete Create your password, then sign in again User
Signed-in user knows the current password Open My Profile or Settings, then Security, and change it User
User forgot the password or is persistently blocked Use an authorized administrator reset or send a new approved setup flow Authorized administrator
Organization owner needs recovery Platform administrator sends the owner password-setup email DentalXpand platform administrator
User sees another organization or unexpected records Stop, sign out, and report a tenant-context incident User and security administrator

Review sign-in and account access before changing credentials

02 / Create

Create a secure password

DentalXpand currently requires at least eight characters in the supported setup and reset workflows. Treat eight as a technical minimum, not a recommendation for a weak password.

Use

  • A unique password used only for DentalXpand.
  • A long passphrase or password-manager-generated value.
  • Your organization’s stronger length or complexity policy when one applies.
  • An approved password manager on a private or managed device.
  • A different value from the temporary or current password.

Avoid

  • Names, birthdays, practice names, phone numbers, or email fragments.
  • Reusing an email, banking, social, PMS, or another workplace password.
  • Predictable changes such as adding a number to an old password.
  • Saving credentials in notes, spreadsheets, screenshots, or task comments.
  • Typing a real password into a training or support screen.

04 / Replace

Replace a temporary password before workspace access

Fictional DentalXpand required temporary password change screen
Figure 2. Source-accurate fictional training state. A pending-password-change membership is routed here before the workspace opens.
  1. Enter Temporary password.Use the one-time value supplied through the approved onboarding or reset channel.
  2. Enter New password.Use a different value with at least eight characters and follow any stronger organization policy.
  3. Confirm new password.The confirmation must match exactly, including capitalization and symbols.
  4. Select Set password once.Wait for the result instead of submitting repeatedly.
  5. Sign in again.Successful change activates the membership, clears the required-change flag, signs the current account out, and expects the new password.

05 / Self-service

Change your own password while signed in

Use this path only when you can sign in and know the current password. DentalXpand verifies the current credential and prevents this endpoint from changing a different user’s account.

Fictional DentalXpand Settings Security tab with change password form
Figure 3. Source-accurate fictional Settings Security view. My Profile also provides an equivalent security form.
  1. Open My Profile or Settings.Select the Security area available to your account.
  2. Enter Current Password.This is verified against the authenticated account email.
  3. Enter New Password.Use at least eight characters and a value not used elsewhere.
  4. Enter Confirm New Password.Correct any mismatch before submission.
  5. Select Update Password.A wrong current password is rejected. A successful change clears local authentication state.
  6. Sign in again.Use the new password and verify the correct organization, role, and permitted destination.

Open the configured DentalXpand application

06 / Session

Understand sign-out and account status changes

1Credential is verifiedThe current or temporary password must belong to the signed-in account.
2Authentication password updatesThe secure auth identity receives the new password.
3Required-change state clearsThe application user and organization membership become active when applicable.
4Sessions endDentalXpand clears local authentication and requests global sign-out where supported.
5Fresh sign-in verifies accessThe account reloads organization, practice, role, permission, and status context.

07 / Admin create

Create a user with the correct onboarding method

Only administrators with User Accounts creation permission should initialize identities. Creating a login, granting pages, assigning a role, and assigning practice scope are separate decisions.

Fictional DentalXpand administrator account onboarding and access control screen
Figure 4. Source-accurate fictional Access Initialization state with onboarding method, practice scope, and least-privilege permissions.
Method Use when Result
Temporary password An approved administrator will securely deliver a one-time credential Account is pending password change; user must replace the credential at next sign-in
Email invitation The user controls the invited inbox and should create the first password directly A one-time setup email is sent; no temporary password is displayed

Administrator checklist

  • Confirm first name, last name, and the exact individual email.
  • Search for an existing application or authentication account before creating a duplicate.
  • Select the correct organization role without using a role as a shortcut for broad permissions.
  • For provider, client, or external accounts, assign at least one valid practice.
  • Grant only required pages and actions, then review the permission matrix.
  • Select the onboarding method and initialize the account once.
  • Verify the resulting status, practice scope, and user destination.

Review roles, permissions, and access boundaries

08 / Deliver

Deliver a one-time credential safely

When a temporary password is generated, DentalXpand displays it once. It is not retained for later display. Record and deliver it only through the organization’s approved secure onboarding procedure.

1Verify the recipient

Confirm the intended person and exact account email through an approved identity check.

2Use an approved channel

Use the organization’s secure credential-delivery method, not a task, comment, normal chat, or screenshot.

3Separate context when required

Do not place the account address, temporary password, and application link together in an unprotected message.

4Require immediate replacement

Ask the user to complete Create your password and confirm successful sign-in.

5Dispose of the temporary value

Remove local notes or messages according to policy after activation.

6Reset if exposure is suspected

Do not reuse a viewed, forwarded, misplaced, or uncertain temporary credential.

09 / Admin reset

Reset an organization user’s password

The administrator must have User Accounts password-reset permission. DentalXpand verifies that the target belongs to the same organization and prevents tenant administrators from resetting the organization owner.

Fictional DentalXpand Security Override password reset modal
Figure 5. Source-accurate fictional Security Override state. The resulting access key is temporary and forces a new password at next sign-in.
  1. Verify the request.Confirm the user’s identity, organization, account email, and reason without asking for the old password.
  2. Open User Accounts.Find the existing user in the current organization and select the reset action.
  3. Confirm the selected account.Check name, email, role, and organization before entering a new security key.
  4. Create a temporary value.Use at least eight characters and treat it as a one-time credential.
  5. Commit the override once.The authentication password updates, membership becomes pending password change, and the action is audited.
  6. Deliver it securely.Use the approved identity and credential channel.
  7. Verify activation.The user replaces the temporary value, signs in again, and reaches only the expected workspace.

Continue to the complete user account lifecycle guide

10 / Account types

Handle employee, provider, external, and owner accounts correctly

Account Authorized path Important boundary
Employee with an existing login Employee account reset permission or User Accounts reset permission Use at least eight characters even if an older employee dialog displays a shorter placeholder
Employee without a login Create the login from Employee or User Accounts with approved account-create permission Creating the account does not justify additional feature permissions
Provider, client, or external user Create or reset through the tenant user workflow At least one valid practice is required at creation; a reset must not alter practice scope
Organization administrator A different authorized same-organization administrator can reset the account The requester still needs explicit reset permission
Organization owner Platform administrator sends the owner a password-setup email Tenant administrators cannot edit or reset owner access
Platform administrator Use the platform’s approved identity-security procedure Do not use tenant impersonation or client support sessions as a password workaround

Review organization provisioning and owner access

11 / Recover

Recover from failed sign-in attempts

Current password is incorrect

Stop and verify the intended account. Do not keep testing variations.

Too many failed attempts

Wait for the complete countdown, currently shown as a short timed pause, before any approved retry.

Persistent local block

Contact an authorized administrator for a reset rather than clearing browser security state or creating a duplicate user.

Expired setup link

Request one new invitation and discard every older link.

Inactive account

Password change is not an activation shortcut. An administrator must resolve account or membership status.

Wrong organization

Stop immediately, sign out, and report the tenant mismatch without opening or changing records.

Correct response

  • Read the exact message.
  • Check email spelling and keyboard state once.
  • Wait for the full pause.
  • Use one approved reset path.
  • Verify fresh sign-in and organization context.

Do not

  • Try repeated password guesses.
  • Use another person’s account.
  • Bypass the pause with storage or browser changes.
  • Create a duplicate identity.
  • Share the error with credentials or setup URLs visible.

12 / Secure

Apply security, least-privilege, and audit controls

User responsibilities

  • Use an individual account and unique password.
  • Protect password-manager, device, and email access.
  • Sign out of shared or reassigned devices.
  • Report suspected exposure, unexpected resets, or wrong-organization access immediately.
  • Never approve an unsolicited password request by email, phone, or chat.

Administrator responsibilities

  • Require explicit create or reset permission and confirm the current organization.
  • Verify the target identity and reason through an approved process.
  • Never retrieve, request, log, or retain a user’s current password.
  • Keep reset audit entries free of credentials and sensitive records.
  • Confirm owner operations remain platform-managed.
  • Review roles, pages, actions, and practice scope independently from password state.
  • Escalate suspicious activity according to the organization’s security and incident procedure.

Review organization, practice, and tenant context

13 / Troubleshoot

Troubleshoot password setup, change, and reset

What you see Likely cause Correct action
Password must be at least 8 characters New or temporary value is too short Create a longer unique password; follow any stronger organization policy
New passwords do not match New and confirmation fields differ Clear both fields and enter the same value carefully
Choose a different password New value equals the temporary or current password Create a new unique value
Current password is incorrect Self-service verification failed Stop guessing; use administrator-assisted reset if the current value is unknown
Link expired Invitation is old, used, incomplete, timed out, or session-mismatched Request and open only one new setup email
Authentication account already exists Administrator attempted a duplicate user creation Locate the existing user and use update or reset
Permission denied for reset Requester lacks the reset action Use an authorized administrator; do not broaden access casually
Owner can only be managed by the platform Tenant administrator selected the organization owner Use the audited platform owner setup-email workflow
Account is inactive User or membership status blocks access Resolve status through authorized account administration
Password changed but sign-in fails Old password, wrong email, stale page, or wrong application address Close old recovery tabs, open approved sign-in, and use the exact email and new password once
Unexpected workspace after success Organization, practice, role, or tenant context is wrong Stop, sign out, and report immediately

For support, include the date, time and time zone, application address, account email, expected organization, exact non-sensitive message, and completed steps. Never include credentials, setup URLs, tokens, PHI, or unredacted records. Contact support@xpand.dental.

14 / Verify

Verify that the password workflow is complete

User verification

  • I used the correct invitation, temporary-password, or self-service workflow.
  • I created a unique password and did not disclose it.
  • I can sign in with the exact account email and new password.
  • The old or temporary password no longer provides expected access.
  • I reach the correct organization, practice scope, role, and permitted destination.
  • I know how to report failed attempts or unexpected access safely.

Administrator verification

  • The target was the intended same-organization user and the requester had explicit authority.
  • The reset did not change permissions, practice assignments, or tenant scope.
  • The user replaced any temporary credential at first sign-in.
  • The reset or setup action is auditable without containing a password.
  • Any suspected exposure or tenant mismatch was escalated.

Need workflow support?

Bring the question and the exact step where you are blocked.

Contact support

Ask about this guide

Tell us where the workflow needs more clarity.

Share the guide, step, or expected result you are reviewing. Product, sales, and support inquiries are routed to the appropriate DentalXpand inbox.

Keep patient information out of this form.

Do not include patient names, dates of birth, member IDs, clinical details, or any other protected health information.

Required fields are marked with an asterisk.