I’m working on improving our security practices and ensuring our systems remain well‑protected. I’m interested in learning how the broader ESRI community manages their IAA and PSA accounts, particularly in situations where an administrator leaves or when a password change is required to maintain tighter security.
If I decide to update the IAA password, I know I need to update it across all scripts that reference it, including the Portal Admin PostgreSQL endpoint, the WebGISDR script, and the built‑in Portal admin account. Are there any other locations where this password must be updated to ensure that we won’t be prompted for the previous password during an upgrade?
I would also appreciate feedback on whether your organizations use the same password for the IAA and PSA accounts. This seems convenient from an administrative standpoint, but also potentially risky from a security perspective.
Thank you in advance for any insights or recommendations.