Recover access to the Web Console
Reset a forgotten Web Console password on a self-hosted deployment directly in the database.
Recover access to the Web Console
Self-hosted only: This guide applies to self-hosted deployments. On cloud, you have no host or database access — contact NetLock RMM support to regain access to your Console.
Use this guide when you forgot your Console password and no other account can reset it for you. You set the account's password to a known temporary value directly in the database and mark it for a forced password change. At the next sign-in, the Console asks you for a new password.
Before you start
Tip: If another account with
users_editcan still sign in, it can reset your password in the Console instead:Users → User Settings → Reset Password(see Reset Password). You do not need this guide then.
You need:
-
Shell access with
sudoon the host that runs the NetLock RMM containers. -
The username of the account. The Console signs you in by username, not by email address.
-
The database credentials. The Console's
appsettings.jsonis stored encrypted, so read them from the Docker setup instead. Option A reads them from the container automatically. For Option B, print them with:sudo grep -E 'MYSQL_(ROOT_PASSWORD|DATABASE)' /home/netlock/docker-compose.ymlMYSQL_ROOT_PASSWORDis the password of the database userroot, andMYSQL_DATABASEis the NetLock RMM database.
Note: The root password from the compose file only applies when the database is first created. If someone changed the root password later, use the current one. Installs from the guided installer also have a dedicated database user; its name and password are in
/home/netlock/mysql/init/01_create_app_user.sql.
The temporary password hash used below is the BCrypt hash of the password admin:
$2a$11$KIDo.90Gv0jaEOi8ZH.JYuQzrD3YXlptkL0hIKABtxB5UqcNZbNWyOption A — Command line
This is the shortest path. It opens no port and restarts nothing.
-
Open a MySQL prompt inside the database container:
sudo docker exec -it mysql-container sh -c 'mysql -u root -p"$MYSQL_ROOT_PASSWORD" "$MYSQL_DATABASE"'If your container has a different name, list the names with
sudo docker ps --format '{{.Names}}'. -
List the accounts and note the username and state of yours:
SELECT id, username, mail, auth_mode, enabled, two_factor_enabled FROM accounts; -
Set the temporary password and the forced reset. Replace
your-usernamewith the username from step 2:UPDATE accounts SET password = '$2a$11$KIDo.90Gv0jaEOi8ZH.JYuQzrD3YXlptkL0hIKABtxB5UqcNZbNWy', reset_password = 1 WHERE username = 'your-username'; EXIT;
Note: Type the statement at the MySQL prompt. Do not pass it on the command line with
mysql -e "...": inside double quotes the shell replaces$2aand$11, and the stored hash no longer matchesadmin.
Continue with Sign in and set a new password.
Option B — Graphical tool (HeidiSQL)
Use this option if you prefer a graphical database tool such as HeidiSQL. The steps use HeidiSQL; DBeaver or MySQL Workbench work the same way. The database port is published on the host's loopback address only, and you reach it through SSH.
-
Open the compose file:
sudo nano /home/netlock/docker-compose.ymlUnder the
mysql:service, add the following block, indented likevolumes::ports: - '127.0.0.1:3306:3306'Warning: Bind the port to
127.0.0.1only. A plain'3306:3306'publishes the database on every network interface, and Docker's published ports bypass host firewalls such asufw. Your database would then be reachable from the internet.Note: Installs set up with the installer's external MySQL access option already publish port 3306 under
mysql:. In that case, skip this step, step 2 and step 5. -
Restart the stack:
sudo docker compose -f /home/netlock/docker-compose.yml down && sudo docker compose -f /home/netlock/docker-compose.yml up -dOn hosts with the standalone binary, use
docker-composeinstead ofdocker compose. -
Connect through SSH. In HeidiSQL, create a session with the network type
MariaDB or MySQL (SSH tunnel):- On the
SSH tunneltab: the server address, your SSH user and your SSH key or password. - On the
Settingstab: host127.0.0.1, port3306, userrootand theMYSQL_ROOT_PASSWORDvalue.
For any other tool, open the tunnel yourself with
ssh -L 3307:127.0.0.1:3306 your-ssh-user@your-serverand connect the tool to127.0.0.1, port3307. - On the
-
Open the NetLock RMM database (the
MYSQL_DATABASEvalue), then theaccountstable, and find the row with your username:- Set
passwordto the hash from Before you start. - Set
reset_passwordto1. - Save the row.
- Set
-
After you have set a new password (next section), remove the two
ports:lines from the compose file again and run the restart command from step 2.
Sign in and set a new password
Warning: Until you finish this step, the account accepts the publicly known password
admin. Sign in right after the database change, and do not chooseadminor another weak password as the new one — the Console does not stop you.
- Open the Console and sign in with your username and the password
admin. - The Console shows
Choose your new password. Enter a strong new password twice and confirm.
You are then signed in. All other sessions of the account end, and the Audit log records Password reset (forced).
If the sign-in still fails
The password reset does not change any other sign-in requirement. Check the SELECT output from Option A, or the account row in Option B, and run the matching statement the same way as the UPDATE above. Replace your-username with your username.
| State | Effect | Fix |
|---|---|---|
auth_mode is SSO | Password sign-in is refused with Incorrect user name or password. | UPDATE accounts SET auth_mode = 'Password & SSO' WHERE username = 'your-username'; |
enabled is 0 | The account is suspended; sign-in is refused with the same message. | UPDATE accounts SET enabled = 1 WHERE username = 'your-username'; |
| 2FA is on and the authenticator is lost | The Console asks for the 2FA code before the password change. | UPDATE accounts SET two_factor_account_secret_key = '', two_factor_secret_encrypted = 0, two_factor_last_step = 0 WHERE username = 'your-username'; — 2FA stays on, and you enrol a new authenticator at the next sign-in. |
| The account has a passkey that is lost | The Console asks for the passkey after the password. | DELETE FROM account_passkeys WHERE account_id = 42; — replace 42 with the id of your account. |
Too many failed attempts | Sign-in is blocked temporarily. | Wait 60 minutes, or restart the Web Console with sudo docker restart netlock-rmm-web-console. The Option B restart clears it as well. |
Note: On older versions, some of these columns do not exist yet, and MySQL reports
Unknown column. Skip that fix.
Clean up
- Option B: the
ports:lines are removed again and the stack is restarted. - If you cleared 2FA, the account has enrolled a new authenticator.
- The
Auditlog shows thePassword reset (forced)entry for your account.
Related
- Chapter 14 — Users & Roles — resetting passwords and 2FA in the Console.
- A.4 — Security: IP whitelist, rate limiting & SSO — sign-in protection and SSO configuration.
- Install the NetLock RMM server with Docker — the compose file and containers this guide refers to.
- Upgrade NetLock RMM — the compose commands used on the host.
Install the NetLock RMM server with Docker
Deploy the NetLock RMM server and Web Console on your own infrastructure with Docker, using the guided installer or a manual Docker Compose setup.
Monitor a device with SNMP
Register an SNMP device, build an SNMP sensor, and route it to a polling agent so NetLock RMM monitors switches, NAS units, and other SNMP-capable hardware.