WHM can require selected cPanel users to choose a new password at their next cPanel login. This is useful after handing over an account or reviewing a password that may have been shared too widely.
IN THIS ARTICLE
What you need before you begin
Confirm the usernames to target and tell affected customers what to expect through your normal trusted communication channel. A forced-change prompt is not a complete response to a compromised account; compromised applications, tokens, SSH keys and mailboxes need their own review.
01 Require a cPanel user to change their password
- Open Account Functions > Force Password Change in WHM.
- Select the Forced? checkbox for each intended cPanel user. Check the account names carefully before using any select-all control.
- Submit the change and review the result.
- Ask the customer to sign in through their verified cPanel login address and complete the password-change form. They should create a unique password and store it in a password manager.
- Review the forced-change list later. The selected state remains until the user completes the required password change.
How do I confirm the password-change requirement is active?
Before the customer completes the change, confirm that the intended username is selected in the forced-change list. After the customer sets a new password, confirm they can access cPanel and that the requirement has cleared. They may also need to update authorized software using the same account credential. Separate database-user and mailbox credentials are managed separately.
Troubleshoot unexpected results
If a customer cannot sign in at all, use the authorized password-reset or support recovery process instead of repeatedly setting the prompt. For an active compromise, coordinate containment and credential rotation; waiting for the next legitimate login may leave other access paths open. Never ask a customer to send their new password in plain-text email.