Use administrator recovery only when no usable system-administrator account can sign in. It is a host-authorised emergency procedure, not a normal password reset.
Before recovery
- Confirm that ordinary password reset and another named administrator are unavailable.
- Assign an authorised host administrator and application security owner.
- Schedule a maintenance window because active users may be signed out.
- Confirm the database and OneView services are healthy.
- Record the target administrator email without including credentials in the change record.
Perform recovery
Use the administrator-recovery command provided by the installed OneView operational tooling or the approved support runbook for that exact installed version. Do not copy commands from another installation, edit database records, reuse setup credentials, or place a temporary password in shell history, an environment variable, a ticket, or chat.
Recovery applies only to an existing system administrator. It does not create a new administrator, change a role, reactivate a deleted account, or reset initial setup.
If the installed tooling cannot authorize or complete recovery, stop and use Installation diagnostics & repair or the Disaster-recovery runbook. Do not bypass the supported workflow.
Validate and contain
After recovery completes:
- Confirm existing sessions were ended as reported.
- Sign in at the approved OneView URL with the temporary password.
- Replace it immediately when prompted.
- Review Settings → Security and revoke unexpected sessions.
- Review Settings → Activity logs for the recovery event.
- Investigate why normal access was lost.
- Rotate other credentials only when evidence indicates they may be affected.
Do not include passwords, setup or recovery values, database configuration, application credentials, or unrestricted host output in the incident record.