2,299
edits
Changes
no edit summary
{{Banner-UnderConstruction}}
||'''Overview of Features and Functionality'''
|-
||'''[[Password Policy#Password Settings|General]]'''
||Provides access to modify, configure, or enable/disable general password settings, the deactivation of inactive accounts, activation settings, password reset messages, and persistent login.
|-
||'''[[Email#Email Templates for User Activation and Password|Activation Email Templates]]'''
||Allows modification and configuration of Email Templates for the following functions: New User, Request Password, and Password Change Notification. Can also set a default language and From Address.
|-
||'''[[Password Policy#Intruder Lockout Settings and Intruder Email Alert|Intruder Alert Settings]]'''
||Allows modification of intruder settings, including the amount of retries, the lockout duration, and the content for an email alert when there is an intrusion.
|-
||'''[[Login Page#Invalid Login Audit|Invalid Login Audit]]'''
||Provides a [[List View Overview|list]] of invalid logins by username, IP Address, and time for auditing and record-keeping purposes.
|-
||'''[[Password Policy#View Locked Users|Locked Users]]'''
||Provides a list of locked users by name, Lockout Time, and the feature to directly set that user with a new password.
|-
||'''[[Disable User Account After Inactive Period|Disabled Inactive Users Users]]'''
||Provides a list of disabled, inactive users by name and date of disabling.
|}
{{PasswordEncryption}}
===General Password Settings===
This section, under the first tab of the '''Password and Activation Policies '''labelled '''General, '''is used to set password attributes.
|-
||'''Password Length'''
||The minimum length allowed for a password; the number inputted must be between '''6 - 32 characters.'''
|-
||'''Complexity'''
||
Set the level of character-type complexity required for a password. The options are as follows:
* '''No Restriction - '''any character can be used; this is the default.
* '''Alpha Only - '''only letters are able to be used.
* '''Alpha & Numeric - '''both letters and numbers must be used in the password.
* '''Alpha & Numeric & Special Characters - '''a combination of letters, numbers, and special characters must be used.
* '''Custom Policy - '''a password policy can be custom-defined.
'''Disable Restriction of Common Passwords- '''Toggling on this function will then ''enable ''the user's ability to use common passwords as their password. This is not recommended for security reasons, as common passwords are easier to guess and to enable security breaches.
|-
||'''Force Password Change'''
||'''Force New Password on First Login- '''This will ensure that each individual user will be forced to change their password from a system-generated or SysAdmin-determined password into one of their own accord. * '''Note: '''This first login does not count towards the Maximum Password Update in 24 Hours setting. '''Expire All Passwords Now - '''This is a handy button that will immediately invalidate all passwords in the system, ensuring that each user will have to reset their passwords when they next log in. A good use-case of this function might be if you updated your password policy to require more complex passwords; by expiring all passwords, every user in your system will have to create new passwords that fall under the new password criteria.
|-
||'''Password Expiration'''
||Each user will be forced to change their password once the selected number of days has passed. Doing so every quarter or so is good security practice; however, any number of days can be set. On each login, the system will check how many days until the password expires and will notify the user their password is about to expire in X days.
|-
||'''Password History Check'''
||You can set the number of previous passports (to a maximum of 32) that the system will remember for each user. When changing their password, users will not be permitted to re-use a previous password that is remembered by the '''Password History '''until the specified number of unique passwords have been used.
|-
||'''Maximum Password Changes in 24 Hours'''
||
This will set the maximum number of password changes any individual user is able to make within a 24-hour period. This is to prevent users from bypassing the password history restriction by changing their password repeatedly in order to return to a previously used password.
* This setting only pertains to password changes by use of '''Update Password '''by the user - it is not relevant to the '''Forgot Password '''link nor to the [[Global User Administrator|System Administrators]] ability to '''Set Password '''for users.
|-
||'''Password Data Restriction'''
||
Configuring this setting will restrict password settings so that values such as first name, last name, or organization name ''cannot ''be used in the password. Any number of fields can be selected from both the '''Organization '''or the '''Contact '''[[Profile]]. '''Organization FieldField '''- Both [[Standard Fields|standard]] and [[Custom Fields|custom fields]] are supported.
'''Contact FieldField '''- Both [[Standard Fields|standard]] and [[Custom Fields|custom fields]] are supported.
|}
====Disable Inactive Accounts and Activation Settings====
Scrolling down further on the '''General '''password settings page will bring you to the sections that allow you to set the criteria for disabling and activating accounts.
[[User]] accounts can be configured to automatically become disabled after a predetermined period of inactivity. Once disabled, a [[Password Policy#Password Reset Message|password reset]] is required by the user to regain access to the system. This feature adds to the many user management options within the system.
:: [[File:Password disable and activate.png|500px|border]]
{| class="wikitable"
|-
||'''Disable user accountsafter ''X ''days'''||Insert the number of days a user account is inactive before it is disabled. In order to disable this feature, simply leave the field blank.
|-
||'''Apply Policy to All Sub-Companies'''
||
Click this button to force-update the password policy related to the current organization and all sub-companies.
'''Note: '''This is applicable when an organization has a [[The Root Company|root organization]], and one or more sub-companies each with its own password policies.
|-
||'''Disabled Inactive Account Message'''
||Write in the text that will be displayed when a user is attempting to access an expired account.
|-
||'''Enable reCAPTCHA Validation'''
||'''Activation link life span'''
||
This function works with the @activationlink@ [[Password Variables to Set or Reset User Passwords|password variable]]. If the '''https://@url@@activationlink@ '''syntax is used in the '''Request Password '''section of [[Email#Email Templates for User Activation and Password|email templates]], this setting sets the duration that the activation link will be valid for the user in ''number of hours. ''
* '''Note: '''Best practice is to provide around 24 hours. Providing too little time will force you to continuously resend links as users will be more likely to forget to activate their accounts in time.
|-
||'''Default Security Code'''
||This is a hard-coded value to be entered when users request new passwords. For example, 12345.
|-
||'''Challenge Questions, delimited by semi-colons'''
||
You can set a series of challenge questions through which all users will be prompted to select one upon next login. Their answer to that question will be stored in the system, and if they forget their password, they will be prompted to enter this answer and click the activation link in the '''Forgot Password '''[[Email#Email Templates for User Activation and Password|email template]].
* '''Note: '''The best challenge questions will have answers that are simple, memorable, not easy to guess, and will not change over time.
'''Example of Challenge Questions: '''
: ''In what city or town was your first job?;''<br />''What is your mother's maiden name?;''<br />''What was your first pet's name?;''<br />''In what year was your father born? ''
|}
====Password Reset Message====
Even further down at the bottom of the '''General '''page of '''Password and Activation Policies '''are features relating to a '''Password Reset Message '''and '''Persistent Login. '''
====Persistent Login====
:: [[File:Persistent login.png|600px|border]]
* '''Disable user accounts after ''[X]'' days''' - The number of days a user account is inactive before it is disabled. Leave this field blank to disable this feature.* '''Apply Policy to All Sub-Companies''' - Click button to force-update the password policy of the current company and all sub-companies. '''Note: '''This is applicable when an An organization has a root company and a one or more sub-companies each with it's own will display informational text at the top saying that its password policieshave not been configured until they are.* '''Disabled Inactive Account Message''' - The text to be displayed to a user trying to access an expired account.
{| class===Password Settings Section==="wikitable"|-This section ||For when a new user is used sent their password for the first time||* If the password activation settings have a '''default security code '''but no challenge questions, the user will be prompted to set enter the default security code. * If the password attributesactivation settings have a '''default security code '''and '''challenge questions, '''the user will be prompted to enter the default security code and then taken to a second screen to define an answer to one of the challenge questions. The user can then go their [[Profile]] and access the '''Change Password '''page to view and update their stored challenge question and answer.* The user will be presented with reCAPTCHA validation in all cases.
====Custom Policy====
<pre style="white-space: -o-pre-wrap; word-wrap: break-word;"><!--@sslogic('@langid@'='2')--><br>@system.Password Policy - French@<!--@else--><br>@system.Password Policy@<!--@end--></pre>
===Intruder Lockout Settings and Intruder Email Alert===
The third tab in '''Password and Activation Policies, '''called '''Intruder Alert Settings, '''will determine the actions that should be taken if someone attempts to log into your copy of [[SmartSimple]] but cannot provide accurate credentials.
* Options: 5 minutes, 15 minutes, 20 minutes, 1 hour, 3 hours, 12 hours, 24 hours or Forever* '''Force Password ChangeNote: ''' - Appears with button marked If the '''Expire All Passwords NowForever '''. Ensures that all users option is selected for the lockout duration, the user will be forced have no access to rest their password when they next log in.login ''until ''manually unlocked by the [[Global User Administrator|System Administrator]]
* '''Password History CheckNote: ''' - You can set The Default Template will use the number of previous passwords (to a maximum [[Organization hierarchy#Organization Ownership|primary contact]] of 32) that the system will remember for each user. When changing their password, users will not be permitted [[The Root Company|root organization]] to re-use a previous password until the specified number of unique passwords have been usedpopulate the '''Email To '''field.
|-
||'''Subject'''
||The subject of the email.
|-
||'''Body'''
||'''Sample Template - '''Clicking this will populate the text window automatically with a template of what the email alert will contain. It will include [[System Variables]].
|}
'''Intruder Alert Email Variables''' – because the [[User|user]] is not logged into the system, the amount of information available is limited to IP Address '''@ip@''', the attempted username '''@username@''' and date/time '''@now@''' of the attempted login.
===Locked Users===
The '''Locked Users '''tab will display a [[List View Overview|list]] of all users that have had their account locked.
Once an account has been locked for exceeding the number of permitted login attempts, it will remain on the '''Locked Users '''list until the correct password is entered. This allows the SysAdmin to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.
* Once an account has been disabled as a result of overly long inactivity, the user will remain on this list until their password is reset. This allows the SysAdmin to see which users have had their accounts disabled because of inactivity.* If a an inactive user is expireddisabled, you can click on the there will be a '''Send PasswordPassword ''' button next to reactivate their name on this tab - that way, you can reactive the account and send the [[User|user]] a new [[Password|password]]with which they can log into the system.
==Single Sign-On==