July 12, 2024 - Remove the ability to explicitly set a password for a device user

Change Header


Change Type: Announcement
Product area: Platform services
Component: Authentication
Deployed at: eu.latest.cumulocity.com, apj.cumulocity.com, jp.cumulocity.com, cumulocity.com, us.cumulocity.com, emea.cumulocity.com

Technical details

Build artifact: cumulocity (10.20.438.0)
Internal ID: MTM-57937

Change Description


To improve security, user administrators can no longer explicitly set passwords for device users. This change prevents an attacker from having access to all device users, in case the administrator account is compromised. In case of losing the device password, the device must be registered again.