User Security, User Policies, Password Policy
|

This page refers to the fields available on the User Security, User Policies, Password Policy.

Below the image of the page, you will find itemised descriptions of the fields and a basic guide of what is required.

User Policies, Password Policy

Pause after receiving invalid login credentials

Delay (secs)

Specify the amount of time to wait before the finPOWER business layer will allow another login attempt. This setting is to stop automated hacking attempts, and even a 0.1 second delay will automated password breaking routines ineffective.

Login attempts

Specify the number of failed login attempts allowed before the User is Locked out.

Timespan (mins)

Specify the timespan over which the failed login attempts must occur for the User to be locked out.

Lockout (mins)

Specify the length of time the User is locked out for.

A setting of "0" minutes means that the user will be locked out indefinitely.

Min Length

Specify the minimum length of a Password.

Force strong passwords

Tick to force the user to enter a strong password. A strong Password must contain Upper case letters, Lower case letters, numbers, and cannot contain the User Id.

Expiry Days

Set the number of days that a password will be valid for - a setting of 0 days means the password will never expire.

History Length

Set the number of months to keep a history of previously used passwords; any new passwords cannot be the same as a previous password used within this period. The Maximum history length is 24 months.

A setting of 0 will not keep any history, meaning that Passwords can be re-used at any time.

If a user resets their password where the Expiry Days = 30 and the History Length = 10, the user will only be able to enter a previous password once the 10 months has elapsed.