Hide profile existence

You can hide the existence of profiles as part of your Attack protection policy. By selecting this option, it ensures that a successful response is sent after every password reset request, whether the profile exists or not.

Why is this helpful?

This feature helps to mitigate the impact of attacks by hiding profiles. The successful response is sent no matter what which essentially hides the status of a profile from the attacker(s).

Hiding profile existence from the console

You can hide the profile existence with a simple operation from your ReachFive Console.

Prerequisites

  • You must have access to the ReachFive Console.

  • You must have a Developer, Manager, or Administrator role.

Instructions

  1. Go to Settings  Security  Attack protection policy.

  2. Enable the Hide profile existence option by toggling the slider to green.

  3. Don’t forget to Save your input.

    hide profile existence