First login over the service path succeeds, and the system immediately requires a new admin password before allowing anything else. Why does this credential step come first in the access workflow?
Select an answer to reveal the explanation.
Short Explanation
The factory password is a door that ships with a label on every box, so the first login is about changing the lock. The system won't let you skip it on purpose — anything you configure under the default credential is sitting on an open front door. Set a strong, dedicated password first, then build everything else behind it.
Full Explanation
The factory admin credential is a shared, open door, which is why replacing it is the mandatory first action rather than a wizard nicety. A default credential is by definition identical on every shipped unit and widely known, so until it is replaced with a dedicated strong password, any network-reachable login attempt targets a half-known credential pair — and configuration performed under it is performed through that open door. Forcing the change at first login closes the window before the system accumulates anything worth stealing. Blocking certificate generation until password length fails by inventing a dependency: HTTPS certificates are produced independently of credential choice. Deferring the password to batch with account creation fails on exposure duration — the entire bring-up would run on the default credential, the exact risk the enforced sequence exists to eliminate. Automatic creation of named accounts from a password change fails by mechanism: setting a password changes one credential; accountability requires the separate, later step of creating individual users. Exam caveat: first-login credential enforcement is a required step in the documented access workflow, not a suggestion. Operational check: verify the default credential no longer authenticates, confirm the new password meets platform complexity rules, and only then proceed to network configuration.