Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.


For more information on products and upcoming events around #dominoforever, please visit: HCL Domino Page


Status Needs Review
Workspace Domino
Created by Guest
Created on May 20, 2026

ID Vault: Allow administrators to bypass "Allow password authentication" policy for vault admin operations

When the security settings policy "Allow password authentication with the ID vault" is set to No, this setting blocks not only end-user password authentication against the vault, but also administrative operations performed by authorized Domino/vault administrators (authenticated via their Notes ID (Notes/Admin client)) — specifically extracting an ID file or resetting a user password in the vault.

This behavior has been confirmed by HCL development (case CS1445660) as intentional, but it is not documented anywhere. The setting name ("Allow password authentication") strongly implies it is intended to restrict end-user authentication only, not administrator operations.

As a result, administrators are forced to temporarily change the policy to Yes, perform the required vault operation, and then revert it back to No. This creates unnecessary security risk (the policy is briefly relaxed for all users) and operational overhead.

Please implement a mechanism that allows authorized Domino or vault administrators to perform ID Vault administrative operations (extract ID file, reset password) regardless of the "Allow password authentication with the ID vault" policy setting — for example by checking the administrator's role/privileges rather than the policy, or by adding a separate policy control for administrative operations.

At minimum, please document the current behavior clearly in the Domino documentation.

  • Attach files