The reset password link emailed to users expires within 10 minutes, though the policy specifies 1 hour. This could be a misconfigured token expiry setting on the backend.