2,299
edits
Changes
no edit summary
<pre style="white-space: -o-pre-wrap; word-wrap: break-word;"><!--@sslogic('@langid@'='2')--><br>@system.Password Policy - French@<!--@else--><br>@system.Password Policy@<!--@end--></pre>
===Intruder Lockout Settings and Intruder Email Alert ===
The third tab in '''Password and Activation Policies, '''called '''Intruder Alert Settings, '''will determine the actions that should be taken if someone attempts to log into your copy of [[SmartSimple]] but cannot provide accurate credentials.
:: [[File:Intruder alert settings new.png|600px|border]]{| class==="wikitable"|-||'''Number of Attempts'''||Enter a number from 1-32 that will denote the amount of times someone can ''attempt ''to log in with an account (that is, with an incorrect password) before that account is locked. ====== ===|-||'''Lockout Duration'''===Rules for Password Activation Settings===||When Select from a company has password settings configurednumber of options the duration of the account lockout. Within this period, then these the user will be used have no ability to log in full, even if their credentials are correct.
{| class="wikitable"
|-
||'''Email From'''
||The From Address for the email alert. If you do not manually set this value, then the address '''donotreply@smartsimple.com '''will be used.
|-
||'''Email To'''
||
Select the [[Internal]] people to receive the email alert. Click the '''binoculars icon '''for a full list of internal staff, from which you can select who to send the email alert to.
* '''Note: '''The following rules apply Default Template will use the [[Organization hierarchy#Organization Ownership|primary contact]] of the [[The Root Company|root organization]] to the above settings when a populate the '''new user is sent their password for the first timeEmail To ''':field.
* '''Lockout Message''' - a custom message to display to users when a user is locked out due to too many failed login attempts. This message will only display when a user has been locked out, and attempts to log in again with the correct password. Therefore, no information will be divulged to users that fail their login.
* If a user is locked, you can click on the '''Set Password''' button on the '''View Locked Users''' tab to reactivate the account and send the [[User|user]] a new [[Password|password]].
* ''Once an account has been locked for exceeding the number of permitted login attempts it will remain on the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.''
* ''When an account has been locked for exceeding the allotted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point will re-lock the account for the configured lockout duration. In other words, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevents would-be intruders from having multiple attempts to guess the password each time the lockout duration has passed. '' ===Password Reset Message===[[image:password-005.png]] This feature provides the ability to overwrite the standard Password Reset message with a custom message for your organization.
===Intruder Email Alert===
These settings define who should be informed by email if an intruder alert is detected. A default emial template is used and contains the following values:
The Default template uses the primary contact on the root company record to populate the '''Email To'''.