Hi everyone, does anyone know why Microsoft Business Central Credential Type: NavUserPassword is allowing the use of the same password during the password reset procedure?
I tried different versions from 26 to 28; the issue/system behavior is quite consistent. Just wondering what the reason is Microsoft doesn't enforce a password uniqueness policy for the current password vs. the new password.
I do appreciate anyone knowing the issue who can provide input or direct me to any Microsoft official documentation for the official statement.
As I checked from the code, it's coded with "ValidateNewPasswordUniqueness," but it's just unknown what the reason is that it doesn't fire the event or if it's an intended behavior.

Report
All responses (
Answers (