Changes

Jump to: navigation, search

Password Policy

7,167 bytes added, 23:30, 18 January 2022
no edit summary
__TOC__
 
 
 
==Overview==
'''Password PolicyPolicy ''' is used to configure the Password Policies password policies within [[SmartSimple ]] with your organizational policiesstandards. It is best practice to ensure that these policies match the other systems that are deployed by your organization. Consequently ; consequently, these policies provide allow for extensive configuration options. 
'''Password Policies include the ability to control; the length and complexity of passwords, password expiration and frequency usage, the method for sending new requested passwords, word restrictions, the number of retries allowed, the lockout time for the account if they exceed the number of retries, email alerts for invalid passwords.following:'''
* The ability to control the length and complexity of passwords
* The password expiration time period 
* The password frequency usage 
* The method for sending new requested passwords (via Email Templates) 
* Word restrictions 
* The number of retries allowed
* The lockout time for the account if they exceed retry quota 
* Email alerts for invalid passwords 
'''Multiple password policies''' can be supported by the system. This feature provides for less stringent policies for types of users that infrequently that ''infrequently ''access the system such as external - for example, [[External]] contactswho would only use the system for an application. Alternative password policies can be set for any level in the organizational [[Organization hierarchy|organization hierarchy]].  
==You can also set individual password policies for the different companies of your organization hierarchy. However, they will be able to ''edit ''the policy only, and not edit the [[Email#Email Templates for User Activation and Password Encryption=={{PasswordEncryption}}|the Activation Emails]], which can only be configured from [[Global Settings]] by a [[User|user]] with [[Global User Administrator|System Administrator]] [[User Role|privileges]]. 
: '''Note: '''In all cases of password policies, '''common words '''or '''known common passwords '''are ineligible to be used as [[SmartSimple]] passwords. ==Configuration - Essentials=====How to Access the Password Settings==Section =1: Persistent Login and Expiration . Click on the 9-square menu icon on the top right of Inactive Accounts==your page.
[[image:password: {{Icon-001Menu}} 2.pngUnder the heading '''Configuration, '''select '''[[Global Settings]]. '''
'''Persistent Login''' provides for the use use of a persistent secure cookie 3. Click on the users computer to eliminate the need to use a username and password to log into the system. tab labelled '''This feature will be deprecated in the July 2016 upgradeSecurity.'''
'''Expiration of Inactive Accounts''' provides the ability to automatically disable a user account after a predetermined period of time4. A password reset is required by Click on the user to regain access to the system. hyperlink called '''[[Disable User Account After Inactive Period|Details on configuring this section is located herePassword and Activation Policies.]]'''
==Section 2: Password Settings Section==A page displayed with numerous settings and tabs related to your system's password and activation policies will appear. On this page, you can modify the required complexities of passwords, email templates for activating users and setting passwords, disable inactive accounts, and more. 
This section :: [[File:General password activation policies.png|900px|border]] {| class="wikitable"|-||'''Tab Name'''||'''Overview of Features and Functionality'''|-||'''[[Password Policy#Password Settings|General]]'''||Provides access to modify, configure, or enable/disable general password settings, the deactivation of inactive accounts, activation settings, password reset messages, and persistent login.|-||'''[[Email#Email Templates for User Activation and Password|Activation Email Templates]]'''||Allows modification and configuration of Email Templates for the following functions: New User, Request Password, and Password Change Notification. Can also set a default language and From Address. |-||'''[[Password Policy#Intruder Lockout Settings and Intruder Email Alert|Intruder Alert Settings]]'''||Allows modification of intruder settings, including the amount of retries, the lockout duration, and the content for an email alert when there is used an intrusion.|-||'''[[Login Page#Invalid Login Audit|Invalid Login Audit]]'''||Provides a [[List View Overview|list]] of invalid logins by username, IP Address, and time for auditing and record-keeping purposes.|-||'''[[Password Policy#View Locked Users|Locked Users]]'''||Provides a list of locked users by name, Lockout Time, and the feature to directly set that user with a new password attributes|-||'''[[Disable User Account After Inactive Period|Disabled Inactive Users]]'''||Provides a list of disabled, inactive users by name and date of disabling. |}===Password Encryption===For your information, if necessary: 
[[image:password-002.png]]{{PasswordEncryption}}
===Password Settings===This section, under the first tab of the '''Maximum Password Update in 24 Hoursand Activation Policies '''labelled '''General, ''' – Sets the maximum number of password changes a user can make within a 24 hour period can be defined. This is to prevent users bypassing the password history restriction by changing their password repeatedly to return to a previously used password. This setting only pertains to set password changes by use of "Update Password" by user, not to the "Forgot Password" link or system administrators using "Set Passwordattributes." 
:: [[File:General password settings.png|400px|border]]{| class="wikitable"|-||'''Password lengthLength''' – the ||The minimum length allowed for a [[Password|password]], between ; the number inputted must be between '''6 and - 32 characters.'''|-||'''Complexity'''||Set the level of character-type complexity required for a password. The options are as follows: 
* '''Data RestrictionsNo Restriction - ''' - passwords set by users any character can be restricted so values such as first name, last name or organization name cannot used; this is the default. * '''Alpha Only - '''only letters are able to be used.* '''Alpha & Numeric - '''both letters and numbers must be used in the password. Any number * '''Alpha & Numeric & Special Characters - '''a combination of fields letters, numbers, and special characters must be used. * '''Custom Policy - '''a password policy can be selected from both the organization or the user profile; standard and custom fields are supported-defined. 
[[image:'''Disable Restriction of Common Passwords - '''Toggling on this function will then ''enable ''the user's ability to use common passwords as their password-008.png]]This is not recommended for security reasons, as common passwords are easier to guess and to enable security breaches. 
In the example above City, Country and Phone fields have been selected from the |-||'''Force Password Change'''||'''Force New Password on First Login - '''This will ensure that each individual user's organization record and first name, last name, birthplace and nickname fields have been selected will be forced to change their password from the user profilea system-generated or SysAdmin-determined password into one of their own accord. 
* '''Note: '''This first login does not count towards the Maximum Password Update in 24 Hours setting. 
'''Complexity''' – the level of complexity required in the [[Password|password]], the options are:
* '''No Restriction''' – any character can be used. This is the default.
* '''Alpha Only''' – only letters can be used.
* '''Alpha & Numeric''' – letters and numbers must be used in the password.
* '''Alpha & Numeric & Special characters''' – letters, numbers and special characters must be used.
* '''Custom Policy''' - a password policy can be custom defined.
<!--'''AlgorithmExpire All Passwords Now - ''' This is a handy button that will immediately invalidate all passwords in the algorithm system, ensuring that each user will have to reset their passwords when they next log in. A good use-case of this function might be used if you updated your password policy to require more complex passwords; by expiring all passwords, every user in your system will have to encrypt create new passwords that fall under the new passwordcriteria. The options are:* '''SHA1''' * '''SHA256'''  
If |-||'''Password Expiration'''||Each user attempts will be forced to change their password once the selected number of days has passed. Doing so every quarter or so is good security practice; however, any number of days can be set. On each login, the Algorithm then as soon as they click Save they system will be presented with an alert check how many days until the password expires and will notify the user their password is about to expire in X days.|-||'''Password History Check'''||You can set the number of previous passports (to inform them a maximum of 32) that existing passwords the system will remember for all each user. When changing their password, users will no longer not be valid if permitted to re-use a previous password that is remembered by the '''Password History '''until the specified number of unique passwords have been used. |-||'''Maximum Password Changes in 24 Hours'''||This will set the maximum number of password algorithm changes any individual user is able to make within a 24-hour period. This is changed, and providing them with to prevent users from bypassing the opportunity password history restriction by changing their password repeatedly in order to abandon the change.[[Image:AlgorithmAlertreturn to a previously used password.png|border]]
Editor* This setting only pertains to password changes by use of '''Update Password 's note: Feature removed with March 2014 upgrade. See ticket 23966 ''by the user - new password algorithm it is not relevant to the '''Forgot Password '''link nor to the [[Global User Administrator|System Administrators]] ability to '''Set Password '''for SHA-256 with salt hash and stretching users. 
|-->===Custom Policy===* The ||'''Compose Custom Password PolicyData Restriction''' table allows you to define the custom ||Configuring this setting will restrict password policy by enabling each character set desired (upper casesettings so that values such as first name, lower caselast name, numeric and/or symbols) and specifying the minimum number of characters required for that character set. * The system code used to enforce your selection will appear in the organization name ''cannot 'Custom Password Policy''' fieldbe used in the password. You Any number of fields can also write your own code and paste it into this field if desired.* The be selected from both the '''Validate PatternOrganization ''' button will open a window where you can test various passwords against the policy to see if they will pass or fail. * The value in the '''Custom Password Policy Description''' field will be displayed to users when setting/changing their password. You can use plain text or html in this field (For example, to insert a line break use ''&lt;br>the '')* 'Contact ''Note''': See also [[Custom Password Policy ExamplesProfile]][[Image:Custpwpolicy.png]] 
'''Important:Organization Field ''' When defining a - Both [[Standard Fields|standard]] and [[Custom Fields|custom password policy be sure to provide a detailed description of the policy in the '''Custom Password Policy Description''' field so that users fields]] are aware of the minimum requirement to enable them to create a valid passwordsupported. 
If you need to translate the '''Custom Password Policy DescriptionContact Field ''' message you can use - Both [[sslogicStandard Fields|standard]]. It is often easiest to use and [[System VariablesCustom Fields|custom fields]] for these. Example:<pre style="white-space: pre-wrap; white-space: -moz-pre-wrap; white-space: -pre-wrap; white-space: -o-pre-wrap; word-wrap: break-word;">&lt;!--@sslogic('@langid@'='2')-->&lt;br>@systemare supported.Password Policy - French@&lt;!--@else-->&lt;br>@system.Password Policy@&lt;!--@end--></pre> 
|}
====Disable Inactive Accounts and Activation Settings====
Scrolling down further on the '''General '''password settings page will bring you to the sections that allow you to set the criteria for disabling and activating accounts. 
[[User]] accounts can be configured to automatically become disabled after a predetermined period of inactivity. Once disabled, a [[Password Policy#Password Reset Message|password reset]] is required by the user to regain access to the system. This feature adds to the many user management options within the system.
===Hierarchical :: [[File:Password Policy==disable and activate.png|500px|border]]{| class="wikitable"|-When viewing a company in your hierarchy, select ||'''Disable user accounts after ''''Settings > Password Policydays''' to define. <br/><br/>A different password policy can be defined for each company within ||Insert the system. <br/><br/>If there are password policies defined for number of days a company then user account is inactive before it will automatically apply is disabled. In order to all subdisable this feature, simply leave the field blank.|-companies in the [[Creating_an_Organization_Chart_and_Company_Hierarchy||hierarchy]], unless those sub'''Apply Policy to All Sub-companies have defined their own password policy. <br/><br/>Companies'''||If there are no password policies defined for a company, then the system will look at the companies above it in Click this button to force-update the hierarchy, and if one of these parent companies have a password policy set then it will use these settings. <br/><br/>If there are no password policies defined for a company, or any of related to the current organization and all sub-companies above it in the hierarchy, then the password policy set in [[Global_Settings|Global Settings]] will apply. 
==New Password Settings== * '''Force New Password on First LoginNote: ''' - Ensures that the user selects This is applicable when an organization has a password of their own choosing the first time they log into [[SmartSimpleThe Root Company|root organization]], and one or more sub-companies each with its own password policies. <br />''(Does not count towards'' Maximum Password Update in 24 Hours ''setting.)''
* |-||'''Password ExpirationDisabled Inactive Account Message''' - Each user ||Write in the text that will be forced displayed when a user is attempting to access an expired account.|-||'''Enable reCAPTCHA Validation'''|||-||'''Activation link life span'''||This function works with the @activationlink@ [[Password Variables to change their Set or Reset User Passwords|password once variable]]. If the '''https://@url@@activationlink@ '''syntax is used in the '''Request Password '''section of [[Email#Email Templates for User Activation and Password|email templates]], this setting sets the duration that the activation link will be valid for the selected user in ''number of days has passed. Any number of days can be sethours. ''
* '''Password History CheckNote: ''' - You can set the number of previous passwords (Best practice is to a maximum of 32) that the system provide around 24 hours. Providing too little time will remember for each user. When changing their password, force you to continuously resend links as users will not be permitted more likely to re-use a previous password until the specified number of unique passwords have been usedforget to activate their accounts in time. 
==|-||'''Default Security Code'''||This is a hard-coded value to be entered when users request new passwords.  For example, 12345. |-||'''Challenge Questions, delimited by semi-colons'''||You can set a series of challenge questions through which all users will be prompted to select one upon next login. Their answer to that question will be stored in the system, and if they forget their password, they will be prompted to enter this answer and click the activation link in the '''Forgot Password '''[[Email#Email Templates for User Activation and Password Activation Settings==|email template]]. 
Password Activation Settings can be set * '''Note: '''The best challenge questions will have answers that are simple, memorable, not easy to add an extra layer of security to the system. These settings pertain to users who use the "Forgot Password" link on the login pageguess, and will not change over time. 
[[Image'''Example of Challenge Questions:Password-Activation-Settings.png]] '''
* : ''In what city or town was your first job?;'Default Security Code'<br />'' - A hard-coded value What is your mother's maiden name?;''<br />''What was your first pet's name?;''<br />''In what year was your father born? ''|}====Password Reset Message====Even further down at the bottom of the '''General '''page of '''Password and Activation Policies '''are features relating to be entered when users request new passwordsa '''Password Reset Message '''and '''Persistent Login.  '''
* '''Activation link life span''' - Works with the @activationlink@ :: [[File:Password Variables to Set or Reset User Passwordsreset message custom.png|800px|password variableborder]]. If  In the text field box, write the content for the '''<nowiki>http://@url@@activationlink@</nowiki>''' syntax is used in the 'Reset Password 'Request Password'' section of [[User Email Templates]], this setting sets the duration message that the activation link a user will be validsee if they need to reset their password. You may select between a default template or you may choose to make it custom. 
* ====Persistent Login====:: [[File:Persistent login.png|600px|border]] The '''Challenge Questions, delimited by semi-colonsPersistent Login''' - You can set a series functionality provides for the use of challenge questions, all users will be prompted to select a persistent secure cookie on the [[SmartSimple]] [[Challenge QuestionUser|user]] on next login's computer to eliminate the need to use a username and password to log into the system. Their answer will  Rather than having to log in to SmartSimple each time you open your web browser, a "cookie" can be stored and they installed on your computer that will be prompted automatically authenticate you, allowing you to enter bypass the login screen. (This setting can be [[System_Security_Permissions#Miscellaneous_Feature_Permission|enabled or disabled]] by your system administrator). In order for this answer if they forget feature to work, you must have the user's browser enabled to accept persistent cookies.====Rules for Password Activation Settings====When an organization has their password and click the activation link settings configured, then they will be used in the "Forgot password" email templatefull.
When an organization does not have their password settings configured, the system will go up the [[Organization hierarchy|organization hierarchy]] until it finds a parent company with password settings configured, and by default it will allow the organization to inherit those settings. '''Example: '''If only the [[Image:Challenge-question.pngThe Root Company|link=root organization]]has its password settings configured, all other organizations would inherit the same policies, as they all fall under the root organization on the organization hierarchy. 
:* '''Note: ''' An example of a good challenge question would be something organization will display informational text at the top saying that is simple, memorable, can't be guessed easily, and won't change over timeits password policies have not been configured until they are. 
{| class===Rules for Password Activation Settings==="wikitable"|-The following rules apply to the above settings ||For when users request a new passwords:user is sent their password for the first time||* If a the password activation settings have a '''default security code has been entered and code '''but no challenge questions have been entered, the user will be prompted to enter the default security code. * If a the password activation settings have a '''default security code has been entered and code '''and '''challenge questions have been entered,  '''the user will only be prompted to enter the default security code and then taken to a second screen to define an answer a to one of the challenge questions. The user can then go their [[Profile]] and access the '''Change Password '''page to view and update their stored challenge questionand answer.* If neither a default security code nor challenge questions have been entered, the The user will be presented with [[CAPTCHA]] reCAPTCHA validationin all cases.
After successful completion of Password Activation|-||For when an existing user requests a new password||* If the password activation settings have a '''default security code '''but no challenge questions, the user will be logged in and their new prompted to enter the default security code. * If the password activation settings have a '''default security ''''''code '''and '''challenge questions, '''the user will only be activeprompted to answer a challenge question.* The user will be presented with reCAPTCHA validation in all cases. 
==Intruder Lockout Settings==|}After a user has successfully completed the appropriate password activation process, they will be logged into that SmartSimple [[instance]] and their newly created password will become active. 
These settings determine ====Custom Policy====* The '''Compose Custom Password Policy''' table provides the ability to define the custom password policy that matches your organization's security standards and provides control of each character type desired (upper case, lower case, numeric and/or symbols). You can also specify the actions minimum number of characters required for that should be taken if someone attempts character type.* The character mask used to log define your selection will appear in the '''Custom Password Policy''' field. You can also write your own code and paste it into your copy of [[SmartSimple]]this field if desired.* The '''Number of AttemptsValidate Pattern''' button will open a window where you can test various passwords against the number of attempts policy to log see if they will pass or fail.* The value in with an account before the account is locked'''Custom Password Policy Description''' field will be displayed to users when setting/changing their password. You can use plain text or html in this field (For example, to insert a line break use ''&lt;br>'')* '''Note''': See also [[Custom Password Policy Examples]][[Image:Custpwpolicy.png]]
* '''Lockout DurationImportant:''' When defining a custom password policy be sure to provide a detailed description of the duration policy in the '''Custom Password Policy Description''' field so that users are aware of the account lockout. The [[User|user]] will not be able minimum requirement to log in during this period. Period can be set enable them to 5 minutes, 15 minutes, 30 minutes, 1 hour, 3 hours, 12 hours, 24 hours or forever (until unlocked by [[Administrator|administrator]])create a valid password.
* '''Lockout Message''' - a custom message to display to users when a user is locked out due to too many failed login attempts. This message will only display when a user has been locked out, and attempts If you need to log in again with translate the correct password. Therefore, no information will be divulged to users that fail their login. * The '''View Locked UsersCustom Password Policy Description''' tab will display all message you can use [[User|userssslogic]] that have had their account locked. <br> * If a user It is locked, you can click on the '''Set Password''' button on the '''View Locked Users''' tab often easiest to reactivate the account and send the use [[User|user]] a new [[Password|passwordSystem Variables]]for these.Example:
<pre style="white-space: -o-pre-wrap; word-wrap: break-word;">&lt;!--@sslogic('@langid@'='2')-->&lt;br>@system.Password Policy - French@&lt;!--@else-->&lt;br>@system.Password Policy@&lt;!--@end--></pre>
===Intruder Lockout Settings and Intruder Email Alert===
The third tab in '''Password and Activation Policies, '''called '''Intruder Alert Settings, '''will determine the actions that should be taken if someone attempts to log into your copy of [[SmartSimple]] but cannot provide accurate credentials.
* :: [[File:Intruder alert settings new.png|600px|border]]{| class="wikitable"|-||'''Number of Attempts'''||Enter a number from 1-32 that will denote the amount of times someone can ''attempt ''Once to log in with an account has been (that is, with an incorrect password) before that account is locked for exceeding the |-||'''Lockout Duration'''||Select from a number of permitted login attempts it will remain on options the "locked users" list until duration of the correct password is enteredaccount lockout. This allows Within this period, the administrator to see which users user will have been unable no ability to log in, even if the configured lockout duration has passed and the account is no longer technically lockedtheir credentials are correct.'' 
* Options: 5 minutes, 15 minutes, 20 minutes, 1 hour, 3 hours, 12 hours, 24 hours or Forever* ''When an account has been locked 'Note: '''If the '''Forever '''option is selected for exceeding the allotted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point will re-lock the account for the configured lockout duration. In other words, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevents would-be intruders from having multiple attempts have no access to guess the password each time the lockout duration has passed. login ''until ''manually unlocked by the [[Global User Administrator|System Administrator]] 
==|}The latter half of this page has the heading '''Intruder Email Alert==- '''using a default template, it allows you to customize the email alert when someone has been locked out because of intruding attempts. 
These settings define who should be informed by email if an intruder alert is detected.{| class="wikitable"|-* ||'''Email From''' – the “from” address ||The From Address for the emailalert. If you do not manually set this value, then the address: address '''supportdonotreply@smartsimple.comcom ''' will be used.* |-||'''Email To''' – select ||Select the [[Internal|internal]] people to receive the emailalert.* Click the '''Subjectbinoculars icon ''' – the subject for a full list of the email. See below for the variables that internal staff, from which you can use in the subject.* '''Body''' – the body of select who to send the email alert email. See below for the variables that you can use in the bodyto.
* '''Intruder Alert Email VariablesNote: ''' – because The Default Template will use the [[UserOrganization hierarchy#Organization Ownership|userprimary contact]] is not logged into of the system, the amount of information available is limited [[The Root Company|root organization]] to IP Address populate the '''@ip@'Email To '', the attempted username '''@username@''' and date/time '''@now@''' of the attempted loginfield. 
==|-||'''Subject'''||The subject of the email. |-||'''Body'''||'''Sample Template - '''Clicking this will populate the text window automatically with a template of what the email alert will contain. It will include [[System Variables]]. |}'''Intruder Log==Alert Email Variables''' – because the [[User|user]] is not logged into the system, the amount of information available is limited to IP Address '''@ip@''', the attempted username '''@username@''' and date/time '''@now@''' of the attempted login.
The ===Locked Users===The '''View LogLocked Users ''' tab is used to access the '''Intruder Alert''' logwill display a [[List View Overview|list]] of all users that have had their account locked. 
:: [[ImageFile:Glob13Locked user lists.png|800px|border]]If a user is locked, you can click on the '''Set Password''' button on the '''View Locked Users''' tab to reactivate the account and send the [[User|user]] a new [[Password|password]].
* The Once an account has been locked for exceeding the number of permitted login attempts, it will remain on the '''Locked Users '''list can be sorted by clicking until the column titlecorrect password is entered.* You can filter This allows the list by [[Username|username]], yearSysAdmin to see which users have been unable to log in, even if the configured lockout duration has passed and monththe account is no longer technically locked.
When an account has been locked for exceeding the number of permitted login attempts, after the lockout time has passed they are permitted only ''ONE ''attempt at the correct password. 
==View Locked Users==* A single incorrect password at this point will '''re-lock '''the account for the configured lockout duration. * This is a preventative measure so that would-be intruders do not have multiple attempts to guess the password each time the lockout duration has passed. 
The ===Disabled Inactive Users===This function is only available from '''View Locked UsersGlobal Settings > Security > Password and Activation Policies; ''' tab will display all it is not accessible from individual password policies for the different companies in your [[UserOrganization hierarchy|usersorganization hierarchy]] that have had their account locked. <br>* Once an account has been locked for exceeding the number of permitted login attempts it will remain on the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked. 
* When an account has been locked for exceeding :: [[File:Disabled inactive users.png|800px|border]] Similarly to the alloted number of attempts'''Locked Users '''tab, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point the '''Disabled Inactive ''''''Users '''tab will re-lock the account for the configured lockout durationprovide a [[List View Overview|list]] of all expired [[User|users]] in your system. In other words, once someone is on the "locked user" list they are only permitted Their accounts have expired as a single wrong attempt result of inactivity and they will a disabling that can be locked for the lockout duration again. This prevent would-be intruders from having multiple attempts to guess the password each configured after a certain amount of time the lockout duration has passed(see [[Password Policy#Disable Inactive Accounts and Activation Settings|Disable Inactive Accounts]].
* Once an account has been disabled as a result of overly long inactivity, the user will remain on this list until their password is reset. This allows the SysAdmin to see which users have had their accounts disabled because of inactivity.* If a an inactive user is lockeddisabled, you can click on the there will be a '''Set PasswordSend Password ''' button next to reactivate their name on this tab - that way, you can reactive the account and send the [[User|user]] a new [[Password|password]]with which they can log into the system.
==Single Sign-On==
Smartstaff, administrator
60
edits

Navigation menu