__TOC__
==Overview==
'''Password PolicyPolicy ''' is used to configure the Password Policies password policies within [[SmartSimple ]] with your organizational policiesstandards. It is best practice to ensure that these policies match the other systems that are deployed by your organization. Consequently ; consequently, these policies provide allow for extensive configuration options.
'''Password Policies include the ability to control; the length and complexity of passwords, password expiration and frequency usage, the method for sending new requested passwords, word restrictions, the number of retries allowed, the lockout time for the account if they exceed the number of retries, email alerts for invalid passwords.following:'''
'''Multiple * The ability to control the length and complexity of passwords* The password expiration time period * The password policies''' can be supported by the system. This feature provides frequency usage * The method for less stringent policies sending new requested passwords (via Email Templates) * Word restrictions * The number of retries allowed* The lockout time for types of users that infrequently access the system such as external contacts. Alternative password policies can be set account if they exceed retry quota * Email alerts for any level in the organizational hierarchy. invalid passwords
==Password Encryption=={{PasswordEncryption}}Multiple password policies can be supported by the system. This feature provides for less stringent policies for types of users that ''infrequently ''access the system - for example, [[External]] contacts who would only use the system for an application. Alternative password policies can be set for any level in the [[Organization hierarchy|organization hierarchy]].
==Section 1: Persistent Login You can also set individual password policies for the different companies of your organization hierarchy. However, they will be able to ''edit ''the policy only, and Expiration of Inactive Accounts==not edit the [[Email#Email Templates for User Activation and Password|the Activation Emails]], which can only be configured from [[Global Settings]] by a [[User|user]] with [[Global User Administrator|System Administrator]] [[User Role|privileges]].
: '''Note: '''In all cases of password policies, '''common words '''or '''known common passwords '''are ineligible to be used as [[image:passwordSmartSimple]] passwords. ==Configuration - Essentials=====How to Access the Password Settings===1. Click on the 9-001square menu icon on the top right of your page.png]]
:: {{Icon-Menu}} 2. Under the heading '''Persistent LoginConfiguration, ''' provides for the use use of a persistent secure cookie on the users computer to eliminate the need to use a username and password to log into the system. select '''This feature will be deprecated in the July 2016 upgrade[[Global Settings]]. '''
'''Expiration of Inactive Accounts''' provides the ability to automatically disable a user account after a predetermined period of time3. A password reset is required by Click on the user to regain access to the system. The main options are: * tab labelled '''Disable user accounts after ''[X]'' days''' - The number of days a user account is inactive before it is disabled. Leave this field blank to disable this featureSecurity.* '''Cascade to sub-company password policies''' - Add a check mark to this field to force-update the password policy of all sub-companies. '''Note:'''This is applicable when an organization has a root company and a one or more sub-companies each with it's own password policies.* '''Expiry Message''' - The text to be displayed to a user trying to access an expired account.
==Section 2: 4. Click on the hyperlink called '''Password Settings Section==and Activation Policies.'''
This section is used A page displayed with numerous settings and tabs related to set your system's password attributesand activation policies will appear. On this page, you can modify the required complexities of passwords, email templates for activating users and setting passwords, disable inactive accounts, and more.
:: [[imageFile:General password activation policies.png|900px|border]] {| class="wikitable"|-||'''Tab Name'''||'''Overview of Features and Functionality'''|-||'''[[Password Policy#Password Settings|General]]'''||Provides access to modify, configure, or enable/disable general password settings, the deactivation of inactive accounts, activation settings, passwordreset messages, and persistent login.|-002||'''[[Email#Email Templates for User Activation and Password|Activation Email Templates]]'''||Allows modification and configuration of Email Templates for the following functions: New User, Request Password, and Password Change Notification.pngCan also set a default language and From Address. |-||'''[[Password Policy#Intruder Lockout Settings and Intruder Email Alert|Intruder Alert Settings]]'''||Allows modification of intruder settings, including the amount of retries, the lockout duration, and the content for an email alert when there is an intrusion.|-||'''[[Login Page#Invalid Login Audit|Invalid Login Audit]]'''||Provides a [[List View Overview|list]] of invalid logins by username, IP Address, and time for auditing and record-keeping purposes.|-||'''[[Password Policy#View Locked Users|Locked Users]]'''||Provides a list of locked users by name, Lockout Time, and the feature to directly set that user with a new password. |-||'''[[Disable User Account After Inactive Period|Disabled Inactive Users]]'''||Provides a list of disabled, inactive users by name and date of disabling. |}===Password Encryption===For your information, if necessary:
'''Maximum Password Update in 24 Hours''' – Sets the maximum number of password changes a user can make within a 24 hour period can be defined. This is to prevent users bypassing the password history restriction by changing their password repeatedly to return to a previously used password. This setting only pertains to password changes by use of "Update Password" by user, not to the "Forgot Password" link or system administrators using "Set Password."{{PasswordEncryption}}
===Password Settings===This section, under the first tab of the '''Password lengthand Activation Policies ''' – the minimum length allowed for a [[Password|password]], between labelled '''6 and 32 charactersGeneral, '''is used to set password attributes.
:: [[File:General password settings.png|400px|border]]{| class="wikitable"|-||'''Password Length'''||The minimum length allowed for a password; the number inputted must be between '''Data Restrictions6 - 32 characters.''' |- passwords set by users can be restricted so values such as first name, last name or organization name cannot be used in ||'''Complexity'''||Set the level of character-type complexity required for a password. Any number of fields can be selected from both the organization or the user profile; standard and custom fields The options are supported.as follows:
[[image:* '''No Restriction - '''any character can be used; this is the default. * '''Alpha Only - '''only letters are able to be used.* '''Alpha & Numeric - '''both letters and numbers must be used in the password.* '''Alpha & Numeric & Special Characters - '''a combination of letters, numbers, and special characters must be used. * '''Custom Policy - '''a passwordpolicy can be custom-008defined.png]]
In the example above City, Country and Phone fields have been selected from '''Disable Restriction of Common Passwords - '''Toggling on this function will then ''enable ''the user's organization record and first name, last nameability to use common passwords as their password. This is not recommended for security reasons, birthplace as common passwords are easier to guess and nickname fields have been selected from the user profileto enable security breaches.
===|-||'''Force Password Complexity===Change'''||'''Force New Password on First Login - '''This will ensure that each individual user will be forced to change their password from a system-generated or SysAdmin-determined password into one of their own accord.
* '''Complexity''' – the level of complexity required in the [[Password|password]], the options areNote:* '''No Restriction ''' – any character can be used. This is first login does not count towards the default.* '''Alpha Only''' – only letters can be used.* '''Alpha & Numeric''' – letters and numbers must be used Maximum Password Update in the password.* '''Alpha & Numeric & Special characters''' – letters, numbers and special characters must be used.* '''Custom Policy''' - a password policy can be custom defined24 Hours setting.
===Custom Policy===
* The '''Compose Custom Password PolicyExpire All Passwords Now - ''' table provides This is a handy button that will immediately invalidate all passwords in the ability to define the custom password policy system, ensuring that matches your organization's security standards and provides control of each character type desired (upper case, lower case, numeric and/or symbols). You can also specify the minimum number of characters required for that character type. * The character mask used user will have to define your selection will appear reset their passwords when they next log in the '''Custom Password Policy''' field. You can also write your own code and paste it into A good use-case of this field function might be if desired.* The '''Validate Pattern''' button will open a window where you can test various passwords against the updated your password policy to see if they will pass or fail. * The value require more complex passwords; by expiring all passwords, every user in the '''Custom Password Policy Description''' field your system will be displayed have to users when setting/changing their create new passwords that fall under the new passwordcriteria. You can use plain text or html in this field (For example, to insert a line break use ''<br>'')* '''Note''': See also [[Custom Password Policy Examples]][[Image:Custpwpolicy.png]]
|-||'''Important:Password Expiration''' When defining a custom ||Each user will be forced to change their password policy once the selected number of days has passed. Doing so every quarter or so is good security practice; however, any number of days can be sure set. On each login, the system will check how many days until the password expires and will notify the user their password is about to expire in X days.|-||'''Password History Check'''||You can set the number of previous passports (to provide a detailed description maximum of 32) that the policy in system will remember for each user. When changing their password, users will not be permitted to re-use a previous password that is remembered by the '''Password History '''until the specified number of unique passwords have been used. |-||'''Custom Maximum Password Policy DescriptionChanges in 24 Hours''' field so that ||This will set the maximum number of password changes any individual user is able to make within a 24-hour period. This is to prevent users are aware of from bypassing the minimum requirement password history restriction by changing their password repeatedly in order to enable them return to create a valid previously used password.
If you need * This setting only pertains to translate password changes by use of '''Update Password '''by the user - it is not relevant to the '''Custom Password Policy DescriptionForgot Password ''' message you can use [[sslogic]]. It is often easiest link nor to use the [[Global User Administrator|System VariablesAdministrators]] for these. Example:<pre style="white-space: pre-wrap; white-space: -moz-pre-wrap; white-space: -pre-wrap; white-space: -o-pre-wrap; word-wrap: break-word;"><!--@sslogic(ability to '''@langid@Set Password '='2')--><br>@systemfor users.Password Policy - French@<!--@else--><br>@system.Password Policy@<!--@end--></pre>
===Hierarchical Password Policy===|-When viewing a company in your hierarchy, select ||'''Settings > Password PolicyData Restriction''' to define. <br/><br/>A different password policy can be defined for each company within the system. <br/><br/>If there are password policies defined for a company then it will automatically apply to all sub-companies in the [[Creating_an_Organization_Chart_and_Company_Hierarchy|hierarchy]], unless those sub-companies have defined their own password policy. <br/><br/>|If there are no password policies defined for a company, then the system Configuring this setting will look at the companies above it in the hierarchy, and if one of these parent companies have a restrict password policy set then it will use these settings. <br/><br/>If there are no password policies defined for a companyso that values such as first name, last name, or any of the companies above it organization name ''cannot ''be used in the hierarchy, then the password policy set in [[Global_Settings|Global Settings]] will apply.<br/><br/>Any number of fields can be selected from both the '''Organization '''or the '''Contact 'NOTE:'' There are no settings stored in the database for a company until someone actually opens the Password Policy page for that company and clicks Save[[Profile]].
==New Password Settings=='''Organization Field '''- Both [[Standard Fields|standard]] and [[Custom Fields|custom fields]] are supported.
[[image:password-003.png]] * '''Force New Password on First LoginContact Field ''' - Ensures that the user selects a password of their own choosing the first time they log into Both [[SmartSimpleStandard Fields|standard]]and [[Custom Fields|custom fields]] are supported. <br />''(Does not count towards'' Maximum Password Update in 24 Hours ''setting.)''
* |}====Disable Inactive Accounts and Activation Settings====Scrolling down further on the '''Password ExpirationGeneral ''' - Each user password settings page will be forced bring you to change their password once the selected number of days has passed. Any number of days can be sections that allow you to setthe criteria for disabling and activating accounts.
* '''Password History Check''' - You [[User]] accounts can set the number of previous passwords (be configured to automatically become disabled after a maximum predetermined period of 32) that inactivity. Once disabled, a [[Password Policy#Password Reset Message|password reset]] is required by the user to regain access to the system will remember for each user. When changing their password, users will not be permitted This feature adds to re-use a previous password until the specified number of unique passwords have been usedmany user management options within the system.
==:: [[File:Password Activation Settings=disable and activate.png|500px|border]]{| class="wikitable"|-||'''Disable user accounts after ''X ''days'''||Insert the number of days a user account is inactive before it is disabled. In order to disable this feature, simply leave the field blank.|-||'''Apply Policy to All Sub-Companies'''||Click this button to force-update the password policy related to the current organization and all sub-companies.
Password Activation Settings can be set to add '''Note: '''This is applicable when an extra layer of security to the system. These settings pertain to users who use the "Forgot Password" link on the login pageorganization has a [[The Root Company|root organization]], and one or more sub-companies each with its own password policies.
|-||'''Disabled Inactive Account Message'''||Write in the text that will be displayed when a user is attempting to access an expired account.|-||'''Enable reCAPTCHA Validation'''|||-||'''Activation link life span'''||This function works with the @activationlink@ [[ImagePassword Variables to Set or Reset User Passwords|password variable]]. If the '''https://@url@@activationlink@ '''syntax is used in the '''Request Password '''section of [[Email#Email Templates for User Activation and Password-Activation-Settings.png|email templates]], this setting sets the duration that the activation link will be valid for the user in ''number of hours. ''
* '''Default Security CodeNote: ''' - A hard-coded value Best practice is to provide around 24 hours. Providing too little time will force you to continuously resend links as users will be entered when users request new passwordsmore likely to forget to activate their accounts in time.
* |-||'''Activation link life spanDefault Security Code''' ||This is a hard- Works with the @activationlink@ [[Password Variables coded value to Set or Reset User Passwordsbe entered when users request new passwords. For example, 12345. |-||password variable]]. If the '''<nowiki>http://@url@@activationlink@</nowiki>Challenge Questions, delimited by semi-colons''' syntax is used ||You can set a series of challenge questions through which all users will be prompted to select one upon next login. Their answer to that question will be stored in the system, and if they forget their password, they will be prompted to enter this answer and click the activation link in the '''Request PasswordForgot Password ''' section of [[User Email#Email Templatesfor User Activation and Password|email template]], this setting sets the duration that the activation link will be valid.
* '''Challenge Questions, delimited by semi-colonsNote: ''' - You can set a series of The best challenge questionswill have answers that are simple, all users will be prompted memorable, not easy to select a [[Challenge Question]] on next login. Their answer will be stored guess, and they will be prompted to enter this answer if they forget their password and click the activation link in the "Forgot password" email templatenot change over time.
'''Example of Challenge Questions:[[Image:Challenge-question.png|link=]] '''
:''In what city or town was your first job?;'Note:'<br />'' An example What is your mother's maiden name?;''<br />''What was your first pet's name?;''<br />''In what year was your father born? ''|}====Password Reset Message====Even further down at the bottom of a good challenge question would be something that is simple, memorable, canthe '''General '''page of '''t be guessed easily, Password and wonActivation Policies '''are features relating to a '''Password Reset Message 't change over time''and '''Persistent Login. '''
===Rules for :: [[File:Password Activation Settings===reset message custom.png|800px|border]] The following rules apply to In the above settings when users request new passwords:* If a default security code has been entered and no challenge questions have been enteredtext field box, write the content for the '''Reset Password '''message that a user will be prompted see if they need to enter the default security codereset their password.* If You may select between a default security code has been entered and challenge questions have been entered, the user will only be prompted template or you may choose to answer a challenge question.* If neither a default security code nor challenge questions have been entered, the user will be presented with [[CAPTCHA]] validationmake it custom.
After successful completion ====Persistent Login====:: [[File:Persistent login.png|600px|border]] The '''Persistent Login''' functionality provides for the use of Password Activationa persistent secure cookie on the [[SmartSimple]] [[User|user]]'s computer to eliminate the need to use a username and password to log into the system. Rather than having to log in to SmartSimple each time you open your web browser, a "cookie" can be installed on your computer that will automatically authenticate you, allowing you to bypass the login screen. (This setting can be [[System_Security_Permissions#Miscellaneous_Feature_Permission|enabled or disabled]] by your system administrator). In order for this feature to work, you must have the user will be logged in and 's browser enabled to accept persistent cookies.====Rules for Password Activation Settings====When an organization has their new password settings configured, then they will be activeused in full.
==Intruder Lockout Settings==When an organization does not have their password settings configured, the system will go up the [[Organization hierarchy|organization hierarchy]] until it finds a parent company with password settings configured, and by default it will allow the organization to inherit those settings. '''Example: '''If only the [[The Root Company|root organization]] has its password settings configured, all other organizations would inherit the same policies, as they all fall under the root organization on the organization hierarchy.
[[image* '''Note: '''An organization will display informational text at the top saying that its password-006policies have not been configured until they are.png]]
These {| class="wikitable"|-||For when a new user is sent their password for the first time||* If the password activation settings determine have a '''default security code '''but no challenge questions, the actions that should user will be prompted to enter the default security code. * If the password activation settings have a '''default security code '''and '''challenge questions, '''the user will be prompted to enter the default security code and then taken if someone attempts to log into your copy a second screen to define an answer to one of the challenge questions. The user can then go their [[SmartSimpleProfile]].* and access the '''Number of AttemptsChange Password ''' – the number of attempts page to log view and update their stored challenge question and answer.* The user will be presented with reCAPTCHA validation in with an account before the account is lockedall cases.
|-||For when an existing user requests a new password||* If the password activation settings have a '''Lockout Durationdefault security code ''' – but no challenge questions, the duration of user will be prompted to enter the account lockoutdefault security code. The [[User| * If the password activation settings have a '''default security ''''''code '''and '''challenge questions, '''the user]] will not only be able prompted to log in during this periodanswer a challenge question. Period can * The user will be set to 5 minutes, 15 minutes, 30 minutes, 1 hour, 3 hours, 12 hours, 24 hours or forever (until unlocked by [[Administrator|administrator]])presented with reCAPTCHA validation in all cases.
* '''Lockout Message''' - a custom message to display to users when a user is locked out due to too many failed login attempts. This message will only display when |}After a user has been locked out, and attempts to log in again with successfully completed the correct appropriate password. Thereforeactivation process, no information they will be divulged to users logged into that fail SmartSimple [[instance]] and their loginnewly created password will become active.
====Custom Policy====* The '''View Locked UsersCompose Custom Password Policy''' tab table provides the ability to define the custom password policy that matches your organization's security standards and provides control of each character type desired (upper case, lower case, numeric and/or symbols). You can also specify the minimum number of characters required for that character type.* The character mask used to define your selection will appear in the '''Custom Password Policy''' field. You can also write your own code and paste it into this field if desired.* The '''Validate Pattern''' button will open a window where you can test various passwords against the policy to see if they will pass or fail.* The value in the '''Custom Password Policy Description''' field will display all be displayed to users when setting/changing their password. You can use plain text or html in this field (For example, to insert a line break use ''<br>'')* '''Note''': See also [[User|usersCustom Password Policy Examples]] that have had their account locked[[Image:Custpwpolicy. <br>png]]
* If a user is locked, you can click on the '''Set PasswordImportant:''' button on When defining a custom password policy be sure to provide a detailed description of the policy in the '''View Locked UsersCustom Password Policy Description''' tab field so that users are aware of the minimum requirement to reactivate the account and send the [[User|user]] enable them to create a new [[Password|valid password]].
If you need to translate the '''Custom Password Policy Description''' message you can use [[sslogic]]. It is often easiest to use [[System Variables]] for these. Example:
* ''Once an account has been locked for exceeding the number of permitted login attempts it will remain on the <pre style="locked userswhite-space: -o-pre-wrap; word-wrap: break-word;" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.><!--@sslogic('@langid@' * ='2'When an account has been locked for exceeding the allotted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point will re)-lock the account for the configured lockout duration. In other words, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevents would-be intruders from having multiple attempts to guess the password each time the lockout duration has passed><br>@system. '' ==Password Reset Message== [[image:passwordPolicy - French@<!--@else--005><br>@system.png]] This feature provides the ability to overwrite the standard Password Reset message with a custom message for your organization.Policy@<!--@end--></pre>===Intruder Lockout Settings and Intruder Email Alert=== These settings define who should be informed by email if an intruder alert is detected.* The third tab in '''Email FromPassword and Activation Policies, ''' – the “from” address for the email. If you do not set this value, the address: called '''support@smartsimple.comIntruder Alert Settings, ''' will determine the actions that should be used.* '''Email To''' – select the [[Internal|internal]] people taken if someone attempts to receive the email.* '''Subject''' – the subject log into your copy of the email. See below for the variables that you can use in the subject.* '''Body''' – the body of the alert email. See below for the variables that you can use in the body. '''Intruder Alert Email Variables''' – because the [[User|userSmartSimple]] is not logged into the system, the amount of information available is limited to IP Address '''@ip@''', the attempted username '''@username@''' and date/time '''@now@''' of the attempted loginbut cannot provide accurate credentials.
==:: [[File:Intruder Log=alert settings new.png|600px|border]]{| class="wikitable"|-||'''Number of Attempts'''||Enter a number from 1-32 that will denote the amount of times someone can ''attempt ''to log in with an account (that is, with an incorrect password) before that account is locked. |-||'''Lockout Duration'''||Select from a number of options the duration of the account lockout. Within this period, the user will have no ability to log in, even if their credentials are correct.
The * Options: 5 minutes, 15 minutes, 20 minutes, 1 hour, 3 hours, 12 hours, 24 hours or Forever* '''View LogNote: ''' tab If the '''Forever '''option is used selected for the lockout duration, the user will have no access to access the login ''until 'Intruder Alert''' log.manually unlocked by the [[Global User Administrator|System Administrator]]
[[Image:Glob13|}The latter half of this page has the heading '''Intruder Email Alert - '''using a default template, it allows you to customize the email alert when someone has been locked out because of intruding attempts.png]]
* {| class="wikitable"|-||'''Email From'''||The list can From Address for the email alert. If you do not manually set this value, then the address '''donotreply@smartsimple.com '''will be sorted by clicking the column titleused.* You can filter |-||'''Email To'''||Select the list by [[Username|usernameInternal]]people to receive the email alert. Click the '''binoculars icon '''for a full list of internal staff, year, and monthfrom which you can select who to send the email alert to.
* '''Note: '''The Default Template will use the [[Organization hierarchy#Organization Ownership|primary contact]] of the [[The Root Company|root organization]] to populate the '''Email To '''field.
==View Locked Users==|-||'''Subject'''||The subject of the email. |-||'''Body'''||'''Sample Template - '''Clicking this will populate the text window automatically with a template of what the email alert will contain. It will include [[System Variables]]. |}'''Intruder Alert Email Variables''' – because the [[User|user]] is not logged into the system, the amount of information available is limited to IP Address '''@ip@''', the attempted username '''@username@''' and date/time '''@now@''' of the attempted login.
The ===Locked Users===The '''View Locked UsersUsers ''' tab will display all a [[UserList View Overview|userslist]] of all users that have had their account locked. <br>* Once an account has been locked for exceeding the number of permitted login attempts it will remain on the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.
* When an account has been :: [[File:Locked user lists.png|800px|border]]If a user is locked for exceeding the alloted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point will re-lock you can click on the '''Set Password''' button on the '''View Locked Users''' tab to reactivate the account for the configured lockout duration. In other words, once someone is on the "locked and send the [[User|user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevent would-be intruders from having multiple attempts to guess the ]] a new [[Password|password each time the lockout duration has passed]].
* If a user is Once an account has been lockedfor exceeding the number of permitted login attempts, you can click it will remain on the the '''Set PasswordLocked Users ''' button list until the correct password is entered. This allows the SysAdmin to reactivate see which users have been unable to log in, even if the account configured lockout duration has passed and send the [[User|user]] a new [[Password|password]]account is no longer technically locked.
When an account has been locked for exceeding the number of permitted login attempts, after the lockout time has passed they are permitted only ''ONE ''attempt at the correct password.
==View Expired Users==* A single incorrect password at this point will '''re-lock '''the account for the configured lockout duration. [[Image:ViewExpiredUsers* This is a preventative measure so that would-be intruders do not have multiple attempts to guess the password each time the lockout duration has passed.png|1000px]]
* The ===Disabled Inactive Users===This function is only available from '''View Expired UsersGlobal Settings > Security > Password and Activation Policies; ''' tab will display all it is not accessible from individual password policies for the different companies in your [[UserOrganization hierarchy|usersorganization hierarchy]] that had their accounts disabled due to [[Password_Policy#Section_1:_Persistent_Login_and_Expiration_of_Inactive_Accounts|inactivity]]. There will be page navigation options if there is an overly long list.
* Once an account has been expired for having been :: [[File:Disabled inactive for longer that users.png|800px|border]] Similarly to the permitted number '''Locked Users '''tab, the '''Disabled Inactive ''''''Users '''tab will provide a [[List View Overview|list]] of days it will remain on the "all expired [[User|users" list until their password is reset]] in your system. This allows the administrator to see which users Their accounts have been expiredas a result of inactivity and a disabling that can be configured after a certain amount of time (see [[Password Policy#Disable Inactive Accounts and Activation Settings|Disable Inactive Accounts]].
* Once an account has been disabled as a result of overly long inactivity, the user will remain on this list until their password is reset. This allows the SysAdmin to see which users have had their accounts disabled because of inactivity.* If a an inactive user is expireddisabled, you can click on the there will be a '''Send PasswordPassword ''' button next to reactivate their name on this tab - that way, you can reactive the account and send the [[User|user]] a new [[Password|password]]with which they can log into the system.
==Single Sign-On==