Changes

Password Policy

831 bytes removed, 19:41, 26 June 2019
no edit summary
|-
||'''Password Length'''
||The minimum length allowed for a password; the number inputted must be between '''6 - 32 characters.'''
|-
||'''Complexity'''
||
Set the level of character-type complexity required for a password. The options are as follows: 
* '''No Restriction - '''any character can be used; this is the default. 
<pre style="white-space: -o-pre-wrap; word-wrap: break-word;">&lt;!--@sslogic('@langid@'='2')-->&lt;br>@system.Password Policy - French@&lt;!--@else-->&lt;br>@system.Password Policy@&lt;!--@end--></pre>
===Intruder Lockout Settings and Intruder Email Alert Alert===
The third tab in '''Password and Activation Policies, '''called '''Intruder Alert Settings, '''will determine the actions that should be taken if someone attempts to log into your copy of [[SmartSimple]] but cannot provide accurate credentials.
|}
* The '''Locked Users '''tab will display a [[List View Overview|list]] of all users that have had their account locked.
* If a user is locked, you can click on the '''Set Password''' button on the '''View Locked Users''' tab to reactivate the account and send the [[User|user]] a new [[Password|password]]
** ''Once an account has been locked for exceeding the number of permitted login attempts it will remain on the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.''
** ''When an account has been locked for exceeding the allotted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point will re-lock the account for the configured lockout duration. In other words, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevents would-be intruders from having multiple attempts to guess the password each time the lockout duration has passed.''
 
The latter half of this page has the heading '''Intruder Email Alert - '''using a default template, it allows you to customize the email alert when someone has been locked out because of intruding attempts. 
|-
||'''Subject'''
||The subject of the email. See  
|-
||'''Body'''
||'''Sample Template - '''Clicking this will populate the text window automatically with a template of what the email alert will contain. It will include [[System Variables]]. 
|}
'''Intruder Alert Email Variables''' – because the [[User|user]] is not logged into the system, the amount of information available is limited to IP Address '''@ip@''', the attempted username '''@username@''' and date/time '''@now@''' of the attempted login.
* '''Lockout Message''' - a custom message to display to users when a user is locked out due to too many failed login attempts. This message will only display when a user has been locked out, and attempts to log in again with the correct password. Therefore, no information will be divulged to users that fail their login.
 
* The '''View Locked Users''' tab will display all [[User|users]] that have had their account locked.
 
* If a user is locked, you can click on the '''Set Password''' button on the '''View Locked Users''' tab to reactivate the account and send the [[User|user]] a new [[Password|password]].
 
 
 
* ''Once an account has been locked for exceeding the number of permitted login attempts it will remain on the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.''
 
* ''When an account has been locked for exceeding the allotted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point will re-lock the account for the configured lockout duration. In other words, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevents would-be intruders from having multiple attempts to guess the password each time the lockout duration has passed.''
 
===Intruder Email Alert===
These settings define who should be informed by email if an intruder alert is detected. A default emial template is used and contains the following values:
 
The Default template uses the primary contact on the root company record to populate the '''Email To'''.
 
 
You can save the default template and then modify ifrequired.
 
* '''Email From''' – the “from” address for the email. If you do not set this value, the address: '''donotreply@smartsimple.com''' will be used.
* '''Email To''' – select the [[Internal|internal]] people to receive the email.
* '''Subject''' – the subject of the email. See below for the variables that you can use in the subject.
* '''Body''' – the body of the alert email. See below for the variables that you can use in the body.
 
'''Intruder Alert Email Variables''' – because the [[User|user]] is not logged into the system, the amount of information available is limited to IP Address '''@ip@''', the attempted username '''@username@''' and date/time '''@now@''' of the attempted login.
 
 
 
===Intruder Log===
The '''View Log''' tab is used to access the '''Intruder Alert''' log.
 
[[Image:Glob13.png]]
 
* The list can be sorted by clicking the column title.
* You can filter the list by [[Username|username]], year, and month.
 
===Hierarchical Password Policy===
2,299
edits