







يوفر SSPR حلاً آمنًا وسهل الاستخدام يمكّن الموظفين من إعادة تعيين أو استعادة كلمات المرور الخاصة بهم بشكل مستقل، في أي وقت ومن أي مكان. ومن خلال منح المستخدمين القدرة على إدارة بيانات اعتمادهم بأنفسهم، يمكن للمؤسسات تقليل طلبات الدعم الفني، وتعزيز الإنتاجية، وتحسين مستوى الأمان.
نتائج قابلة للقياس من مؤسسات تُولي الأولوية لأمن الهوية والتحكم في الوصول.
اكتشف كيف تحقق حلولنا نتائج قابلة للقياس في بيئات حقيقية









تجارب حقيقية من الشركات التي تستخدم حلول الأمن السيبراني من Cerebra.



















































































































يمنح المستخدمين القدرة على إعادة تعيين كلمات المرور بأنفسهم، مما يقلل المهام الروتينية ويخفض تكاليف الدعم الفني.

يتيح إعادة تعيين كلمات المرور بسرعة، مما يقلل تعطل الأعمال ويعزز الكفاءة التشغيلية.

يؤمّن عمليات إعادة تعيين كلمات المرور عبر التحقق من هوية المستخدم لمنع الوصول غير المصرح به.

يوائم عمليات إعادة تعيين كلمات المرور مع المتطلبات التنظيمية ويوفر سجلات تدقيق ومتابعة شاملة.

يبسّط إدارة كلمات المرور، مما يعزز تجربة المستخدم ويساعد الموظفين على إنجاز أعمالهم بكفاءة أكبر.


تجارب حقيقية من الشركات التي تستخدم حلول الأمن السيبراني من Cerebra.


يعزز أمان الوصول بطبقة إضافية من المصادقة تتجاوز كلمات المرور.


يمنع إساءة استخدام الحساب حتى عند اختراق بيانات الاعتماد.


يدعم الامتثال لمعايير الأمن الإقليمية والعالمية.


يوفر وصولاً آمنًا دون إضافة احتكاك إلى عمليات تسجيل دخول المستخدم.











Everything IT and security teams ask before rolling out self-service password reset with mPass SSPR.
Self-service password reset lets employees regain access to their accounts without calling the IT helpdesk. With mPass SSPR, a user who forgets their password opens a secure portal, confirms their identity through a verified method such as SMS, email, an authenticator push, or Nafath, and then sets a new password themselves. The reset only completes after identity is confirmed, so it never trades security for convenience. Every reset is logged for audit purposes, and administrators can enforce password complexity and reuse rules automatically. The result is fewer login interruptions for staff and far fewer routine tickets for the IT team.
mPass SSPR never resets a password on trust alone — it requires proof of identity first. Depending on how your organization configures it, users can verify themselves through SMS one-time codes, email confirmation, an authenticator app push, pre-set security questions, or Nafath for Saudi national ID verification. Administrators choose which methods are acceptable and can require more than one for higher-risk accounts. This multi-factor check closes the gap that plain "email me a reset link" flows leave open, since a compromised inbox alone isn't enough to take over an account. Every verification attempt, successful or failed, is recorded in the audit log.
Password resets are consistently one of the top drivers of helpdesk tickets in most organizations, and Cerebra's enterprise deployments show mPass SSPR cutting that volume by roughly 70%. The saving comes from letting employees resolve lockouts themselves, at any hour, instead of waiting for a technician to verify their identity manually and issue a temporary password. That frees IT staff to focus on higher-value work instead of repetitive resets, while employees get back to work faster. Because every self-service reset is still identity-verified and logged, the reduction in tickets doesn't come at the cost of weaker security or lost visibility.
Yes. mPass SSPR connects directly to Active Directory so password changes made through self-service sync immediately with your existing directory — no separate user database to maintain and no synchronization lag. Beyond AD, it's built to integrate with the other systems already in your identity stack, including HR platforms, single sign-on, and third-party applications, so password policies stay consistent everywhere a user logs in. Because SSPR is part of Cerebra's mPass identity and access management suite, it also works alongside mPass MFA and SSO, giving you one coherent authentication and credential-management layer instead of several disconnected tools.
Yes, mPass SSPR is built with Saudi compliance requirements in mind, aligning with NCA essential cybersecurity controls, the SAMA cybersecurity framework, and ISO 27001. Every password reset generates an audit-ready log entry that records who reset what, when, and through which verification method — exactly the kind of evidence regulators and auditors ask for. Because Cerebra is a 100% Saudi, Saudi-Tech-registered company, the platform is also designed for organizations that need on-premise or air-gapped deployment to keep sensitive identity data inside the Kingdom rather than routed through foreign cloud infrastructure.
mPass SSPR is available both on-premise and in the cloud, so the choice depends on your organization's security and compliance posture rather than a limitation of the product. Banks, government entities, and other regulated organizations often choose on-premise or even air-gapped deployment to keep identity data fully within their own infrastructure, while other organizations prefer the lower maintenance overhead of a cloud rollout. Either way, the feature set, MFA-verified identity checks, and audit logging stay the same — you're choosing where it runs, not compromising on how it protects your users.
Administrators can configure more than one verification path per user, so a lost phone doesn't automatically mean a locked-out employee. If SMS or an authenticator app isn't available, mPass SSPR can fall back to alternatives such as email verification, security questions, or Nafath, depending on how your policy is set up. For cases where none of the self-service options apply, an IT administrator can still step in and manually verify the user through the admin console. Because policies are configurable per group or role, you can balance convenience for regular staff against stricter fallback rules for privileged accounts.
A typical "forgot password" email link relies on one thing: whoever controls that inbox. If an attacker has compromised the email account, they can reset the password too — a well-known weak point. mPass SSPR closes it by requiring genuine identity verification, such as MFA, Nafath, or security questions, before any reset is allowed, and by giving administrators control over which methods count as acceptable proof. It also logs every attempt for audits, applies your organization's password policies automatically, and integrates with Active Directory so the change takes effect everywhere at once — something a simple email link was never designed to do.