Password Security and Account Locking
Required Feature Flags
The following permissions are required to use this feature:
Required Permissions:
Manage security settings (
admin.security.settings) β to configure password policy and account lockingAdd & edit users (User Management) β to unlock locked accounts
Introduction
evaluagent lets you define security rules tailored to your business's requirements. Using the security settings, you can configure:
Password Expiration: Define how often you want to force users to reset their passwords.
Minimum Password Length: Set a minimum password length that users must adhere to. Optionally, you can set a different minimum password length for anyone who is an admin.
Password Reuse: Force users to enter a different password and stop them from reusing a password they may have used in a recent change.
By default, the only rule that cannot be turned off is the minimum password length. This is set to 8 characters by default, but you may change this as required.
Getting There
Go to Settings > Security settings > click the Password restrictions tab.
Here you can configure rules associated with:
Password Expiry
Password Reuse
Password Length
Password Attempts
Password Expiry
By default, passwords are configured not to expire. If you activate this feature, you'll be prompted to enter how often users are required to change their passwords. The minimum refresh period is 30 days.
_Please note: When you first activate this feature, all users will be prompted to reset their password on their next login._
Password Reuse
This rule prevents users from reusing a recently used password. You configure how many previous passwords you want evaluagent to remember, and if a password is in that list, the system will not allow the user to change their password to that former password.
Password Length
The default minimum password length is 8 characters, but you can increase it.
You can also assign users with the Administrator role a different password length requirement. For example, non-Admin users may have a password length of 9, while users assigned the Admin role must have a password length of 12.
Password Attempts
This rule lets you lock a user's account after a specified number of incorrect login attempts.
How to Unlock Accounts
When a user account is locked, they see a message when they try to log in indicating the account is locked.
To unlock a locked account:
Go to User Management > Add & edit users.
Select the relevant user.
Click Unlock account and confirm.
