Changes

Jump to: navigation, search

Password Policy

51 bytes added, 12:21, 17 August 2018
No summary
There can also be individual Password policies for the different companies in your organizations hierarchy. However, they will only be able to edit the policy and not the Activation Emails. These emails can only be configured from [[Global Settings|Global settings]].
'''Common Words or known common passwords''' cannot  be used as passwords.
 
==Settings==
===Password Encryption===
{{PasswordEncryption}}
: [[Image:Challenge-question.png|link=]]
: '''Note:''' An example of a good challenge question would be something that is simple, memorable, can't be guessed easily, and won't change over time.
 
===Rules for Password Activation Settings===
When a company has password settings configured, then these will be used in full.
When a company has does not have password settings configured, the system will go up the Organizational hierarchy until it finds a parent company with password settings configured and then use these will be used in fullsettings.
NOTE: When a company does not have password settings configured, the system configure it will go up display informational text at the Organizational hierarchy until top saying it finds a parent company with password settings has not been configured and then use these settings.
NOTE: When a company does not have password settings configure it will display informational text at the top saying it has not been configured.
The following rules apply to the above settings when a '''new user is sent their password for the first time''':
The following rules apply to the above settings when a '''new user is sent their password for the first time''':
* If the Activation settings have a default security code but no challenge questions, the user will be prompted to enter the default security code.
* If the Activation settings have a default security code and a challenge questions, the user will be prompted to enter the default security code and then taken to second screen to define an answer to one of the the Challenge questions. The user can then go User Profile and access the Change Password page to view and update their stored challenge question and answer.
* The user will be presented with [[CAPTCHA]] validation in all cases.
* '''Lockout Message''' - a custom message to display to users when a user is locked out due to too many failed login attempts. This message will only display when a user has been locked out, and attempts to log in again with the correct password. Therefore, no information will be divulged to users that fail their login.
* The '''View Locked Users''' tab will display all [[User|users]] that have had their account locked.
* If a user is locked, you can click on the '''Set Password''' button on the '''View Locked Users''' tab to reactivate the account and send the [[User|user]] a new [[Password|password]].
 
[[Image:ViewLockedUsers.png|1000px]]
The '''View Locked Users''' tab will display all [[User|users]] that have had their account locked.
* Once an account has been locked for exceeding the number of permitted login attempts it will remain on the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.
* If a user is locked, you can click on the '''Set Password''' button to reactivate the account and send the [[User|user]] a new [[Password|password]].
 
Smartstaff
311
edits

Navigation menu