It would be great if users could reset their password via a self service e.g. by answering predefined security questions, for example if they have forgotten their password.
It should also be possible to specify length and complexity of the password.