We are on Confluence version 6.6.1. Our users authenticate with a SAML plugin but their user accounts are in the internal directory. However, we want them always to login with the SAML authentication. Since they don't use the internal directory Confluence password, we have set them all to long random passwords for safety.
I have hidden the Forgot password link on our wiki.net/login.action?nosso page using CSS but if they know the url - wiki.net/forgotuserpassword.action, they could still go and reset their password.
So, my question is, what would be the impact if we removed the forgotuserpassword.action page from our Confluence build? Does that have the possibility of breaking something else?
Thanks!