Password settings fields
Field
Description
Password strength
Select one of the password strength definitions:
Disabled - selected by default. No password strength applies.
Manual - for a manual password strength definition, fill in relevant values in the Min. number of symbols required and the Min. number of digits required fields.
Good - password length (8) and the minimum number of symbols and digits are fixed (1).
Strong - password length (10) and the minimum number of symbols and digits are fixed (1).
* 
For details on the password strength settings, see Password strength settings.
Password length
Set the length of the password:
Minimum length = 1
Maximum length = 30
Default length = 8
Both lower & upper case required
Select Yes to enforce or the use of upper and lower case in the password.
Min. number of symbols required
Select the minimum number of symbols required in the password. Select any number from 0 to 10. The default value is 1.
Min. number of digits required
Select the minimum number of digits required in the password. Select any number from 0 to 10. The default value is 1.
Enable password expiry
No is the defaultvalue: password expiry related fields are disabled and the default values are used.
Select Yes to make password expiry related fields editable.
If you subsequently try to save the changed settings, a confirmation message is displayed asking whether or not an expiration date must be set for every password.
* 
If confirmed, a new expiration date is set for all accounts, except those whose password never expires.
The expiration date is calculated based on the system date plus the number of days entered in the Password expiry field.
Password expiry
Specify the number of days a password will be valid.
Enforce password history
Specify the number of old passwords that should be retained, to make sure these passwords are not reused when setting a new password. The default value in this field is 15 and the minimum value is 1.
Lockout time (in minutes)
Specify the interval between invalid log-on attempts. The minimum for this setting is 0 minutes. The default interval is 5 minutes.
Max. failed log-on attempts
Indicate the maximum number of log-on attempts before for a user is locked out. The user account will be blocked after the maximum number of successive log-on attempts is exceeded. The minimum value for this setting is 1. The default value is 3.
Forgotten password functionality
The forgotten password functionality is deactivated by default. You can activate it for either the User name and email address or for the User name only by selecting the corresponding option.
Forgotten password template
In the language fields of this setting, upload the custom HTM(L) mail merge report(s) that must be used as template for the 'forgotten password email' to the end-users. You can configure and upload different custom templates for different languages. The system will identify the users' language from their User settings and send the email in that language.
* 
A minimum requirement for the custom template to work is that the reset token is included in the mail merge template as a mail merge code.
If you activate the Forgotten password functionality and do not upload any custom templates, the system will send a standard email with a reset token. For the procedure see: Customizing the Forgotten password email.
Reset password template
In the language fields of this setting, select the mail merge report that must be used to send an email notification to users upon the reset of their password or the creation of a new user account.
* 
•     See Setting / resetting a password (Authorization).
•     See Accounts for information on managing user accounts via User account web definition.