The *base* role will now set the password for the *root* user, if the `root_password_hash` variable is defined. This ensures that there is a way to log into machines directly, even if other authentication mechanisms like Active Directory are unavailable.