How to force cPanel users to change their passwords using WHM?
You can force cPanel users to change their passwords by enabling the Force Password Change option in WHM for specific accounts. Users must then reset their password before they can access full cPanel functionality. You can also remove the requirement or change a password directly if needed.
In WHM, go to Account Functions » Force Password Change, tick the Forced? box for each cPanel account you want to require a reset for, then click Submit. On their next cPanel login the user must change their password and cannot access full functionality until they do.
Before you start
- You need WHM access as root or as a reseller with the privilege enabled. If you are a Hostworld reseller and cannot see it, please open a support ticket.
- This applies to cPanel account logins only. Individual email mailboxes are not affected.
- After a user changes their cPanel password, any saved FTP or SFTP logins that use the main cPanel account will need updating.
Step 1: Force password changes in WHM
- Log in to WHM as root or as a reseller with the required privilege.
- Open Account Functions » Force Password Change.
- Tick the Forced? checkbox beside each cPanel account you want to require a change for. Use Select All or Deselect All if you need to work in bulk.
- Click Submit. The Forced? column stays ticked for each selected account until that user changes their password.
- If you want to stop users choosing a weak password when they reset, set the minimum password strength in WHM's Security Center first, so the requirement is in place before anyone logs in.
Step 2: Undo or adjust
- To remove the requirement for an account you flagged by mistake: return to Account Functions » Force Password Change, untick Forced? for that account, then click Submit.
- If you need to set a new password yourself instead of forcing a reset: go to WHM » Account Functions » Password Modification, select the account, enter or generate a password, then click Change Password.
If it does not work
- You cannot find Force Password Change in WHM: your reseller privileges may not include it. Your upstream can enable it in WHM » Resellers » Edit Reseller Nameservers and Privileges. If you are with Hostworld, open a support ticket and we will check your privileges.
- The user is not being prompted: confirm the correct account is ticked in WHM and that Forced? is still set. Ask the user to log in to cPanel itself, not Webmail. If you need to move now or they cannot log in, change the password for them via WHM » Account Functions » Password Modification.
- A user cannot set the password they want: your minimum password strength setting in WHM's Security Center may be rejecting it. Either ask them to choose a stronger one or review the setting.
- You are testing in demo mode: cPanel 134 prevents demo-mode accounts from setting or clearing the force-password-change flag. Test with a normal account.
What next
If you want us to confirm your reseller privileges or review your password strength settings, please open a support ticket and we will check the account for you.
Common questions
What happens when I force a cPanel user to change their password?
On their next cPanel login, the user will be required to change their password and cannot access full cPanel functionality until they do. The requirement stays active until they complete the password change.
Do I need specific privileges to use Force Password Change in WHM?
Yes, you need WHM access as root or as a reseller with the Force Password Change privilege enabled. If you cannot see the option, your reseller privileges may need updating by your upstream provider.
Will forcing a password change affect email mailboxes?
No, this feature applies to cPanel account logins only. Individual email mailbox passwords are not affected.
What happens to saved FTP or SFTP logins after a password change?
Any saved FTP or SFTP logins that use the main cPanel account will need updating with the new password.
Can I remove the forced password change requirement?
Yes, you can return to Account Functions » Force Password Change, untick the Forced? checkbox for that account, and click Submit.
Was this article helpful?
0 people found this helpful