We want new users to change the temporary password on first login, in combination with TOTP?
This is our setup and we set a random temporary password:
The user is able to login, but is not forced to set a new password after the 2-step authentication process.
We noticed that the password setting in IAM automatically changed standard policy.
What did we do wrong?