# Password Authentication

Coder has password authentication enabled by default. The account created during
setup is a username/password account.

## Disable password authentication [#disable-password-authentication]

To disable password authentication, use the
[`CODER_DISABLE_PASSWORD_AUTH`](/beta-docs/reference/cli/server/#--disable-password-auth)
flag on the Coder server.

## Restore the `Owner` user [#restore-the-owner-user]

If you remove the admin user account (or forget the password), you can run the
[`coder server create-admin-user`](/beta-docs/reference/cli/server_create-admin-user/)command
on your server.

<Callout type="idea" title="Important">
  You must run this command on the same machine running the Coder server.
  If you are running Coder on Kubernetes, this means using
  [kubectl exec](https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/)
  to exec into the pod.
</Callout>

## Reset a user's password [#reset-a-users-password]

An admin must reset passwords on behalf of users. This can be done in the web UI
in the Users page or CLI:
[`coder reset-password`](/beta-docs/reference/cli/reset-password/)
