Changes

Jump to: navigation, search

Password Policy

3,790 bytes added, 23:30, 18 January 2022
no edit summary
__TOC__
 
 
 
==Overview==
'''Password PolicyPolicy ''' is used to configure the Password Policies password policies within [[SmartSimple ]] with your organizational policiesstandards. It is best practice to ensure that these policies match the other systems that are deployed by your organization. Consequently ; consequently, these policies provide allow for extensive configuration options. 
'''Password Policies include the ability to control; the length and complexity of passwords, password expiration and frequency usage, the method for sending new requested passwords, word restrictions, the number of retries allowed, the lockout time for the account if they exceed the number of retries, email alerts for invalid passwords.following:'''
'''Multiple * The ability to control the length and complexity of passwords* The password expiration time period * The password policies''' can be supported by the system. This feature provides frequency usage * The method for less stringent policies sending new requested passwords (via Email Templates) * Word restrictions * The number of retries allowed* The lockout time for types of users that infrequently access the system such as external contacts. Alternative password policies can be set account if they exceed retry quota * Email alerts for any level in the organizational hierarchy.invalid passwords 
There Multiple password policies can also be individual Password supported by the system. This feature provides for less stringent policies for types of users that ''infrequently ''access the different companies in your organizations hierarchy. Howeversystem - for example, they will [[External]] contacts who would only be able to edit use the policy and not the Activation Emailssystem for an application. These emails Alternative password policies can only be configured from set for any level in the [[Global SettingsOrganization hierarchy|Global settingsorganization hierarchy]]. 
You can also set individual password policies for the different companies of your organization hierarchy. However, they will be able to '''Common Words or known common passwords'edit '' cannot  be used as passwordsthe policy only, and not edit the [[Email#Email Templates for User Activation and Password|the Activation Emails]], which can only be configured from [[Global Settings]] by a [[User|user]] with [[Global User Administrator|System Administrator]] [[User Role|privileges]]. 
: '''Note: '''In all cases of password policies, '''common words '''or '''known common passwords '''are ineligible to be used as [[SmartSimple]] passwords. ==Configuration - Essentials=====How to Access the Password EncryptionSettings==={{PasswordEncryption}}1. Click on the 9-square menu icon on the top right of your page.
:: {{Icon-Menu}} 
2. Under the heading '''Configuration, '''select '''[[Global Settings]]. '''
3. Click on the tab labelled '''Security.'''
===Persistent Login 4. Click on the hyperlink called '''Password and Expiration of Inactive Accounts===[[image:password 001Activation Policies.png|border]]'''
'''Persistent Login''' provides for the use use of a persistent secure cookie on the users computer to eliminate the need to use a username A page displayed with numerous settings and password tabs related to log into the your system. '''This feature s password and activation policies will be deprecated in the July 2016 upgradeappear.''''''Disable Inactive Accounts''' provides On this page, you can modify the ability to automatically required complexities of passwords, email templates for activating users and setting passwords, disable a user account after a predetermined period of time. A password reset is required by the user to regain access to the systeminactive accounts, and more. The main options are: 
* :: [[File:General password activation policies.png|900px|border]] {| class="wikitable"|-||'''Tab Name'''||'''Overview of Features and Functionality'''|-||'Disable user accounts after ''[X[Password Policy#Password Settings|General]]'''||Provides access to modify, configure, or enable/disable general password settings, the deactivation of inactive accounts, activation settings, password reset messages, and persistent login.|-||'' days'[[Email#Email Templates for User Activation and Password|Activation Email Templates]]'' - The number '||Allows modification and configuration of days Email Templates for the following functions: New User, Request Password, and Password Change Notification. Can also set a user account is inactive before it is disabled. Leave this field blank to disable this featuredefault language and From Address. |-* ||'''Apply [[Password Policy to All Sub-Companies#Intruder Lockout Settings and Intruder Email Alert|Intruder Alert Settings]]''' - Click button to force-update ||Allows modification of intruder settings, including the password policy amount of retries, the current company lockout duration, and all subthe content for an email alert when there is an intrusion.|-companies||'''[[Login Page#Invalid Login Audit|Invalid Login Audit]]'''||Provides a [[List View Overview|list]] of invalid logins by username, IP Address, and time for auditing and record-keeping purposes. |-||'''Note:[[Password Policy#View Locked Users|Locked Users]]'''This is applicable when an organization has ||Provides a root company list of locked users by name, Lockout Time, and the feature to directly set that user with a one or more sub-companies each with it's own new password policies. * |-||'''[[Disable User Account After Inactive Period|Disabled Inactive Account MessageUsers]]''' - The text to be displayed to ||Provides a user trying to access an expired accountlist of disabled, inactive users by name and date of disabling. |}===Password Encryption===For your information, if necessary: 
===Password Settings Section===This section is used to set password attributes{{PasswordEncryption}}
[[image:===Password Settings===This section, under the first tab of the '''Password and Activation Policies '''labelled '''General, '''is used to set password-002attributes.png]] 
:: [[File:General password settings.png|400px|border]]{| class="wikitable"|-||'''Maximum Password Update in 24 HoursLength''' – Sets ||The minimum length allowed for a password; the maximum number of password changes a user can make within a 24 hour period can inputted must be definedbetween '''6 - 32 characters. This is to prevent users bypassing '''|-||'''Complexity'''||Set the password history restriction by changing their password repeatedly to return to level of character-type complexity required for a previously used password. This setting only pertains to password changes by use of "Update Password" by user, not to the "Forgot Password" link or system administrators using "Set Password."The options are as follows: 
* '''Password lengthNo Restriction - ''' any character can be used; this is the default. * '''Alpha Only - '''only letters are able to be used.* '''Alpha & Numeric - '''both letters and numbers must be used in the minimum length allowed for a [[Password|password]], between .* '''Alpha & Numeric & Special Characters - '''6 a combination of letters, numbers, and 32 special charactersmust be used. * '''Custom Policy - '''a password policy can be custom-defined. 
'''Data RestrictionsDisable Restriction of Common Passwords - '''Toggling on this function will then '' - enable ''the user's ability to use common passwords set by users can be restricted so values such as first name, last name or organization name cannot be used in the their password. Any number of fields can be selected from both the organization or the user profile; standard This is not recommended for security reasons, as common passwords are easier to guess and custom fields are supportedto enable security breaches. 
[[image:|-||'''Force Password Change'''||'''Force New Password on First Login - '''This will ensure that each individual user will be forced to change their passwordfrom a system-generated or SysAdmin-008determined password into one of their own accord.png]] 
In the example above City, Country and Phone fields have been selected from the user* '''Note: '''s organization record and This first name, last name, birthplace and nickname fields have been selected from login does not count towards the user profileMaximum Password Update in 24 Hours setting. 
'''Expire All Passwords Now - '''This is a handy button that will immediately invalidate all passwords in the system, ensuring that each user will have to reset their passwords when they next log in. A good use-case of this function might be if you updated your password policy to require more complex passwords; by expiring all passwords, every user in your system will have to create new passwords that fall under the new password criteria. 
====|-||'''Password Complexity====Expiration'''||Each user will be forced to change their password once the selected number of days has passed. Doing so every quarter or so is good security practice; however, any number of days can be set. On each login, the system will check how many days until the password expires and will notify the user their password is about to expire in X days.|-||'''ComplexityPassword History Check''' ||You can set the level number of previous passports (to a maximum of complexity required in 32) that the system will remember for each user. When changing their password, users will not be permitted to re-use a previous password that is remembered by the '''Password History '''until the [[specified number of unique passwords have been used. |-||'''Maximum PasswordChanges in 24 Hours'''||This will set the maximum number of password]], changes any individual user is able to make within a 24-hour period. This is to prevent users from bypassing the options are:password history restriction by changing their password repeatedly in order to return to a previously used password.
* '''No Restriction''' – any character can be used. This is the default.* '''Alpha Only''' – setting only letters can be used.* pertains to password changes by use of '''Alpha & NumericUpdate Password ''' – letters and numbers must be used in by the password.* user - it is not relevant to the '''Alpha & Numeric & Special charactersForgot Password ''' – letters, numbers and special characters must be used.* link nor to the [[Global User Administrator|System Administrators]] ability to '''Custom PolicySet Password ''' - a password policy can be custom definedfor users. 
====Custom Policy====|-* The ||'''Compose Custom Password PolicyData Restriction''' table provides the ability to define the custom ||Configuring this setting will restrict password policy settings so that matches your organization's security standards and provides control of each character type desired (upper casevalues such as first name, lower caselast name, numeric and/or symbols). You can also specify the minimum number of characters required for that character type.* The character mask used to define your selection will appear in the organization name ''cannot 'Custom Password Policy''' fieldbe used in the password. You Any number of fields can also write your own code and paste it into this field if desired.* The be selected from both the '''Validate PatternOrganization ''' button will open a window where you can test various passwords against the policy to see if they will pass or fail.* The value in the '''Custom Password Policy Description''' field will be displayed to users when setting/changing their password. You can use plain text or html in this field (For example, to insert a line break use ''<br>'the ')* ''Contact 'Note''': See also [[Custom Password Policy ExamplesProfile]][[Image:Custpwpolicy.png]] 
'''Important:Organization Field ''' When defining a - Both [[Standard Fields|standard]] and [[Custom Fields|custom password policy be sure to provide a detailed description of the policy in the '''Custom Password Policy Description''' field so that users fields]] are aware of the minimum requirement to enable them to create a valid passwordsupported. 
If you need to translate the '''Custom Password Policy DescriptionContact Field ''' message you can use - Both [[sslogicStandard Fields|standard]]. It is often easiest to use and [[System VariablesCustom Fields|custom fields]] for theseare supported. Example: 
<pre style|}="white-space: -o-pre-wrap; word-wrap: break-word;">&lt;!--@sslogic(===Disable Inactive Accounts and Activation Settings====Scrolling down further on the '@langid@'='2General ''')-->&lt;br>@system.Password Policy - French@&lt;!--@else-->&lt;br>@systempassword settings page will bring you to the sections that allow you to set the criteria for disabling and activating accounts.Password Policy@&lt;!--@end--></pre> 
[[User]] accounts can be configured to automatically become disabled after a predetermined period of inactivity. Once disabled, a [[Password Policy#Password Reset Message|password reset]] is required by the user to regain access to the system. This feature adds to the many user management options within the system.
===New Password Settings===:: [[imageFile:password003Password disable and activate.png|500px|border]]{| class="wikitable"|-||'''Disable user accounts after ''X ''days'''||Insert the number of days a user account is inactive before it is disabled. In order to disable this feature, simply leave the field blank.|-||'''Apply Policy to All Sub-Companies'''||Click this button to force-update the password policy related to the current organization and all sub-companies. 
* '''Force Password ChangeNote: ''' This is applicable when an organization has a [[The Root Company|root organization]], and one or more sub- Appears companies each with button marked '''Expire All Passwords Now'''. Ensures that all users will be forced to rest their its own password when they next log inpolicies.
* |-||'''First LoginDisabled Inactive Account Message''' - Ensures ||Write in the text that the will be displayed when a user selects a password of their own choosing is attempting to access an expired account.|-||'''Enable reCAPTCHA Validation'''|||-||'''Activation link life span'''||This function works with the first time they log into @activationlink@ [[SmartSimplePassword Variables to Set or Reset User Passwords|password variable]]. <br If the '''https:/>/@url@@activationlink@ ''(Does not count towards'syntax is used in the ' Maximum ''Request Password '''section of [[Email#Email Templates for User Activation and Password Update in 24 Hours |email templates]], this setting sets the duration that the activation link will be valid for the user in ''settingnumber of hours.) ''
* '''Password ExpirationNote: ''' - Each user Best practice is to provide around 24 hours. Providing too little time will force you to continuously resend links as users will be forced more likely to change forget to activate their password once the selected number of days has passed. Any number of days can be setaccounts in time. 
* |-||'''Default Security Code''Password History Check'||This is a hard-coded value to be entered when users request new passwords.  For example, 12345. |-||''' Challenge Questions, delimited by semi- colons'''||You can set the number a series of previous passwords (challenge questions through which all users will be prompted to select one upon next login. Their answer to a maximum of 32) that question will be stored in the system will remember for each user. When changing , and if they forget their password, users they will not be permitted prompted to re-use a previous password until enter this answer and click the specified number of unique passwords have been usedactivation link in the '''Forgot Password '''[[Email#Email Templates for User Activation and Password|email template]]. 
* '''Note: '''The best challenge questions will have answers that are simple, memorable, not easy to guess, and will not change over time. 
'''Example of Challenge Questions: '''
: ''In what city or town was your first job?;''<br />''What is your mother's maiden name?;''<br />''What was your first pet's name?;''<br />''In what year was your father born? ''|}====Password Activation SettingsReset Message====Even further down at the bottom of the '''General '''page of '''Password and Activation Settings can be set to add an extra layer of security to the system. These settings pertain Policies '''are features relating to users who use the "Forgot a '''Password" link on the login pageReset Message '''and '''Persistent Login. '''
:: [[ImageFile:Password-Activation-Settingsreset message custom.png|800px|border]] In the text field box, write the content for the '''Reset Password '''message that a user will see if they need to reset their password. You may select between a default template or you may choose to make it custom. 
* ====Persistent Login====:: [[File:Persistent login.png|600px|border]] The '''Default Security CodePersistent Login''' - A hard-coded value functionality provides for the use of a persistent secure cookie on the [[SmartSimple]] [[User|user]]'s computer to eliminate the need to use a username and password to log into the system. Rather than having to log in to SmartSimple each time you open your web browser, a "cookie" can be installed on your computer that will automatically authenticate you, allowing you to bypass the login screen. (This setting can be [[System_Security_Permissions#Miscellaneous_Feature_Permission|enabled or disabled]] by your system administrator). In order for this feature to work, you must have the user's browser enabled to accept persistent cookies.====Rules for Password Activation Settings====When an organization has their password settings configured, then they will be entered when users request new passwordsused in full.
* '''Activation link life span''' - Works with When an organization does not have their password settings configured, the system will go up the @activationlink@ [[Password Variables to Set or Reset User PasswordsOrganization hierarchy|password variableorganization hierarchy]]until it finds a parent company with password settings configured, and by default it will allow the organization to inherit those settings. If the  '''<nowiki>httpsExample://@url@@activationlink@</nowiki> ''' syntax is used in If only the ''Request Password'' section of [[User Email TemplatesThe Root Company|root organization]]has its password settings configured, this setting sets all other organizations would inherit the duration that same policies, as they all fall under the activation link will be validroot organization on the organization hierarchy. 
* '''Challenge Questions, delimited by semi-colonsNote: ''' - You can set a series of challenge questions, all users An organization will be prompted to select a [[Challenge Question]] on next login. Their answer will be stored and they will be prompted to enter this answer if they forget their password and click the activation link in display informational text at the "Forgot top saying that its password" email templatepolicies have not been configured until they are. 
: [[Image:Challenge{| class="wikitable"|-question.png||For when a new user is sent their password for the first time||link=]]: * If the password activation settings have a '''Note:default security code ''' An example of a good but no challenge question would questions, the user will be something that is simpleprompted to enter the default security code. * If the password activation settings have a '''default security code '''and '''challenge questions, memorable, can '''t the user will be guessed easily, prompted to enter the default security code and then taken to a second screen to define an answer to one of the challenge questions. The user can then go their [[Profile]] and wonaccess the '''Change Password '''t change over timepage to view and update their stored challenge question and answer.===Rules for Password Activation Settings===When a company has password settings configured, then these * The user will be used presented with reCAPTCHA validation in fullall cases.
When |-||For when an existing user requests a company does not new password||* If the password activation settings have a '''default security code '''but no challenge questions, the user will be prompted to enter the default security code. * If the password activation settings configuredhave a '''default security ''''''code '''and '''challenge questions,  '''the system user will go up the Organizational hierarchy until it finds only be prompted to answer a parent company challenge question.* The user will be presented with password settings configured and then use these settingsreCAPTCHA validation in all cases. 
NOTE: When |}After a company does not have user has successfully completed the appropriate password activation process, they will be logged into that SmartSimple [[instance]] and their newly created password settings configure it will display informational text at the top saying it has not been configuredbecome active. 
====Custom Policy====
* The '''Compose Custom Password Policy''' table provides the ability to define the custom password policy that matches your organization's security standards and provides control of each character type desired (upper case, lower case, numeric and/or symbols). You can also specify the minimum number of characters required for that character type.
* The character mask used to define your selection will appear in the '''Custom Password Policy''' field. You can also write your own code and paste it into this field if desired.
* The '''Validate Pattern''' button will open a window where you can test various passwords against the policy to see if they will pass or fail.
* The value in the '''Custom Password Policy Description''' field will be displayed to users when setting/changing their password. You can use plain text or html in this field (For example, to insert a line break use ''&lt;br>'')
* '''Note''': See also [[Custom Password Policy Examples]]
[[Image:Custpwpolicy.png]]
The following rules apply '''Important:''' When defining a custom password policy be sure to provide a detailed description of the policy in the above settings when a '''new user is sent their password for the first timeCustom Password Policy Description''':field so that users are aware of the minimum requirement to enable them to create a valid password.
* If the Activation settings have a default security code but no challenge questions, the user will be prompted you need to enter translate the default security code'''Custom Password Policy Description''' message you can use [[sslogic]].* If the Activation settings have a default security code and a challenge questions, the user will be prompted It is often easiest to enter the default security code and then taken to second screen to define an answer to one of the the Challenge questions. The user can then go User Profile and access the Change Password page to view and update their stored challenge question and answer.* The user will be presented with use [[CAPTCHASystem Variables]] validation in all casesfor these.Example:
<pre style="white-space: -o-pre-wrap; word-wrap: break-word;">&lt;!--@sslogic('@langid@'='2')-->&lt;br>@system.Password Policy - French@&lt;!--@else-->&lt;br>@system.Password Policy@&lt;!--@end--></pre>
===Intruder Lockout Settings and Intruder Email Alert===
The third tab in '''Password and Activation Policies, '''called '''Intruder Alert Settings, '''will determine the actions that should be taken if someone attempts to log into your copy of [[SmartSimple]] but cannot provide accurate credentials.
The following rules apply to the above settings when an '''existing user requests a new password'''* If a default security code has been entered and no challenge questions have been entered, the user will be prompted to enter the default security code.* If a default security code has been entered and challenge questions have been entered, the user will only be prompted to answer a challenge question.* The user will be presented with : [[CAPTCHA]] validation in all cases. After successful completion of Password Activation, the user will be logged in and their File:Intruder alert settings new password will be active. ===Intruder Lockout Settings===[[image:password-006.png|600px|border]]{| class="wikitable"These settings determine the actions that should be taken if someone attempts to log into your copy of [[SmartSimple]].|- * ||'''Number of Attempts''' ||Enter a number from 1-32 that will denote the number amount of attempts to log in with an account before the account is locked. * ''times someone can 'Lockout Duration'attempt '' – the duration of the account lockout. The [[User|user]] will not be able to log in during this period. Period can be set to 5 minutes, 15 minutes, 30 minutes, 1 hour, 3 hours, 12 hours, 24 hours or forever with an account (until unlocked by [[Administrator|administrator]]). * '''Lockout Message''' - a custom message to display to users when a user that is locked out due to too many failed login attempts. This message will only display when a user has been locked out, and attempts to log in again with the correct an incorrect password. Therefore, no information will be divulged to users that fail their login. * The '''View Locked Users''' tab will display all [[User|users]] ) before that have had their account is locked. |-* If a user is locked, you can click on the ||'''Set PasswordLockout Duration''' button on the '''View Locked Users''' tab to reactivate the account and send the [[User|user]] a new [[Password|password]].  * ''Once an account has been locked for exceeding the Select from a number of permitted login attempts it will remain on options the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and of the account is no longer technically locked.'' * ''When an account has been locked for exceeding the allotted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at Within this point will re-lock the account for the configured lockout duration. In other wordsperiod, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevents would-be intruders from having multiple attempts to guess the password each time the lockout duration has passed. '' ===Password Reset Message===[[image:password-005.png]] This feature provides the have no ability to overwrite the standard Password Reset message with a custom message for your organization.   ===Intruder Email Alert===These settings define who should be informed by email if an intruder alert is detected. A default emial template is used and contains the following values: [[File:10-12-2016 1-15-24 PM.png]] The Default template uses the primary contact on the root company record to populate the '''Email To'''.  You can save the default template and then modify ifrequired. * '''Email From''' – the “from” address for the email. If you do not set this value, the address: '''donotreply@smartsimple.com''' will be used.* '''Email To''' – select the [[Internal|internal]] people to receive the email.* '''Subject''' – the subject of the email. See below for the variables that you can use in the subject.* '''Body''' – the body of the alert email. See below for the variables that you can use in the body. '''Intruder Alert Email Variables''' – because the [[User|user]] is not logged into the system, the amount of information available is limited to IP Address '''@ip@''', the attempted username '''@username@''' and date/time '''@now@''' of the attempted login.   ===Intruder Log===The '''View Log''' tab is used to access the '''Intruder Alert''' log. [[Image:Glob13.png]] * The list can be sorted by clicking the column title.* You can filter the list by [[Username|username]], year, and month.  ===Hierarchical Password Policy===When viewing a company in your hierarchy, select '''Settings > Password Policy''' to define. <br/><br/> A different password policy can be defined for each company within the system. <br/><br/> If there are password policies defined for a company then it will automatically apply to all sub-companies in the [[Creating_an_Organization_Chart_and_Company_Hierarchy|hierarchy]], unless those sub-companies have defined even if their own password policy. <br/><br/> If there credentials are no password policies defined for a company, then the system will look at the companies above it in the hierarchy, and if one of these parent companies have a password policy set then it will use these settings. <br/><br/> If there are no password policies defined for a company, or any of the companies above it in the hierarchy, then the password policy set in [[Global_Settings|Global Settings]] will applycorrect.<br/><br/> 
* Options: 5 minutes, 15 minutes, 20 minutes, 1 hour, 3 hours, 12 hours, 24 hours or Forever* ''NOTE'Note: '''If the ''' There are Forever '''option is selected for the lockout duration, the user will have no settings stored in the database for a company until someone actually opens access to login ''until ''manually unlocked by the Password Policy page for that company and clicks Save.[[Global User Administrator|System Administrator]] 
==View Locked Users==|}This option is only available from the Password Policy on the [[Category:Global Settings|Global settings]]. It cannot be accessed for The latter half of this page has the individual Password policies for heading '''Intruder Email Alert - '''using a default template, it allows you to customize the different companies in your organizations hierarchyemail alert when someone has been locked out because of intruding attempts. 
{| class="wikitable"|-||'''Email From'''||The From Address for the email alert. If you do not manually set this value, then the address '''donotreply@smartsimple.com '''will be used.|-||'''Email To'''||Select the [[Image:ViewLockedUsers.png|1000pxInternal]]people to receive the email alert. Click the '''binoculars icon '''for a full list of internal staff, from which you can select who to send the email alert to.
The * '''View Locked UsersNote: ''' tab The Default Template will display all use the [[Organization hierarchy#Organization Ownership|primary contact]] of the [[UserThe Root Company|usersroot organization]] that have had their account lockedto populate the '''Email To '''field. 
* Once an account has been locked for exceeding |-||'''Subject'''||The subject of the email. |-||'''Body'''||'''Sample Template - '''Clicking this will populate the number text window automatically with a template of permitted login attempts it what the email alert will contain. It will remain on include [[System Variables]]. |}'''Intruder Alert Email Variables''' – because the [[User|user]] is not logged into the "locked users" list until system, the correct password amount of information available is entered. This allows the administrator to see which users have been unable limited to log inIP Address '''@ip@''', even if the configured lockout duration has passed and attempted username '''@username@''' and date/time '''@now@''' of the account is no longer technically lockedattempted login.
* When an account has been locked for exceeding the alloted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point ===Locked Users===The '''Locked Users '''tab will re-lock the display a [[List View Overview|list]] of all users that have had their account for the configured lockout duration. In other words, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevent would-be intruders from having multiple attempts to guess the password each time the lockout duration has passed. 
* :: [[File:Locked user lists.png|800px|border]]If a user is locked, you can click on the the '''Set Password''' button  button on the '''View Locked Users''' tab to reactivate the account and send the the [[User|user]] a new  a new [[Password|password]].
Once an account has been locked for exceeding the number of permitted login attempts, it will remain on the '''Locked Users '''list until the correct password is entered. This allows the SysAdmin to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.
==View Expired Users==This option is only available from When an account has been locked for exceeding the Password Policy on number of permitted login attempts, after the [[Category:Global Settings|Global settings]]. It can not be accessed for the individual Password policies for lockout time has passed they are permitted only ''ONE ''attempt at the different companies in your organizations hierarchycorrect password. 
[[Image:ViewExpiredUsers* A single incorrect password at this point will '''re-lock '''the account for the configured lockout duration.png|1000px]] * This is a preventative measure so that would-be intruders do not have multiple attempts to guess the password each time the lockout duration has passed. 
* The ===Disabled Inactive Users===This function is only available from '''View Expired UsersGlobal Settings > Security > Password and Activation Policies; ''' tab will display all it is not accessible from individual password policies for the different companies in your [[UserOrganization hierarchy|usersorganization hierarchy]] that had their accounts disabled due to [[Password_Policy#Section_1:_Persistent_Login_and_Expiration_of_Inactive_Accounts|inactivity]]. There will be page navigation options if there is an overly long list. 
* Once an account has been expired for having been :: [[File:Disabled inactive for longer that users.png|800px|border]] Similarly to the permitted number '''Locked Users '''tab, the '''Disabled Inactive ''''''Users '''tab will provide a [[List View Overview|list]] of days it will remain on the "all expired [[User|users" list until their password is reset]] in your system. This allows the administrator to see which users Their accounts have been expiredas a result of inactivity and a disabling that can be configured after a certain amount of time (see [[Password Policy#Disable Inactive Accounts and Activation Settings|Disable Inactive Accounts]].
* Once an account has been disabled as a result of overly long inactivity, the user will remain on this list until their password is reset. This allows the SysAdmin to see which users have had their accounts disabled because of inactivity.* If a an inactive user is expireddisabled, you can click on the there will be a '''Send PasswordPassword ''' button next to reactivate their name on this tab - that way, you can reactive the account and send the [[User|user]] a new [[Password|password]]with which they can log into the system.
==Single Sign-On==
Smartstaff, administrator
60
edits

Navigation menu