Changes

Jump to: navigation, search

Password Policy

667 bytes added, 23:30, 18 January 2022
no edit summary
{{Banner-UnderConstruction}}
 
 
 
==Overview==
'''Password Policy '''is used to configure the password policies within [[SmartSimple]] with your organizational standards. It is best practice to ensure that these policies match the other systems deployed by your organization; consequently, these policies allow for extensive configuration options. 
||Allows modification of intruder settings, including the amount of retries, the lockout duration, and the content for an email alert when there is an intrusion.
|-
||'''[[Login Page#Invalid Login Audit|Invalid Login Audit]]'''
||Provides a [[List View Overview|list]] of invalid logins by username, IP Address, and time for auditing and record-keeping purposes.
|-
||Provides a list of locked users by name, Lockout Time, and the feature to directly set that user with a new password. 
|-
||'''[[Disable User Account After Inactive Period|Disabled Inactive Users Users]]'''
||Provides a list of disabled, inactive users by name and date of disabling. 
|}
|-
||'''Password Expiration'''
||Each user will be forced to change their password once the selected number of days has passed. Doing so every quarter or so is good security practice; however, any number of days can be set.  On each login, the system will check how many days until the password expires and will notify the user their password is about to expire in X days.
|-
||'''Password History Check'''
====Disable Inactive Accounts and Activation Settings====
Scrolling down further on the '''General '''password settings page will bring you to the sections that allow you to set the criteria for disabling and activating accounts. 
 
[[User]] accounts can be configured to automatically become disabled after a predetermined period of inactivity. Once disabled, a [[Password Policy#Password Reset Message|password reset]] is required by the user to regain access to the system. This feature adds to the many user management options within the system.
:: [[File:Password disable and activate.png|500px|border]]
|}
* The '''Locked Users '''tab will display a [[List View Overview|list]] of all users that have had their account locked. 
 
:: [[File:Locked user lists.png|800px|border]]
 
* If a user is locked, you can click on the '''Set Password''' button on the '''View Locked Users''' tab to reactivate the account and send the [[User|user]] a new [[Password|password]].
** Once an account has been locked for exceeding the number of permitted login attempts it will remain on the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.
** When an account has been locked for exceeding the allotted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point will re-lock the account for the configured lockout duration. In other words, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevents would-be intruders from having multiple attempts to guess the password each time the lockout duration has passed.
 
The latter half of this page has the heading '''Intruder Email Alert - '''using a default template, it allows you to customize the email alert when someone has been locked out because of intruding attempts. 
'''Intruder Alert Email Variables''' – because the [[User|user]] is not logged into the system, the amount of information available is limited to IP Address '''@ip@''', the attempted username '''@username@''' and date/time '''@now@''' of the attempted login.
==View Expired =Locked Users===The '''Locked Users '''tab will display a [[List View Overview|list]] of all users that have had their account locked.  :: [[File:Locked user lists.png|800px|border]]This option If a user is only available from the locked, you can click on the '''Set Password Policy ''' button on the '''View Locked Users''' tab to reactivate the account and send the [[Category:Global SettingsUser|user]] a new [[Password|Global settingspassword]]. It can not be accessed  Once an account has been locked for exceeding the number of permitted login attempts, it will remain on the '''Locked Users '''list until the correct password is entered. This allows the individual Password policies SysAdmin to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked. When an account has been locked for exceeding the different companies in your organizations hierarchynumber of permitted login attempts, after the lockout time has passed they are permitted only ''ONE ''attempt at the correct password. 
[[Image:ViewExpiredUsers* A single incorrect password at this point will '''re-lock '''the account for the configured lockout duration.png|1000px]] * This is a preventative measure so that would-be intruders do not have multiple attempts to guess the password each time the lockout duration has passed. 
* The ===Disabled Inactive Users===This function is only available from '''View Expired UsersGlobal Settings > Security > Password and Activation Policies; ''' tab will display all it is not accessible from individual password policies for the different companies in your [[UserOrganization hierarchy|usersorganization hierarchy]] that had their accounts disabled due to [[Password_Policy#Section_1:_Persistent_Login_and_Expiration_of_Inactive_Accounts|inactivity]]. There will be page navigation options if there is an overly long list. 
* Once an account has been expired for having been :: [[File:Disabled inactive for longer that users.png|800px|border]] Similarly to the permitted number '''Locked Users '''tab, the '''Disabled Inactive ''''''Users '''tab will provide a [[List View Overview|list]] of days it will remain on the "all expired [[User|users" list until their password is reset]] in your system. This allows the administrator to see which users Their accounts have been expiredas a result of inactivity and a disabling that can be configured after a certain amount of time (see [[Password Policy#Disable Inactive Accounts and Activation Settings|Disable Inactive Accounts]].
* Once an account has been disabled as a result of overly long inactivity, the user will remain on this list until their password is reset. This allows the SysAdmin to see which users have had their accounts disabled because of inactivity.* If a an inactive user is expireddisabled, you can click on the there will be a '''Send PasswordPassword ''' button next to reactivate their name on this tab - that way, you can reactive the account and send the [[User|user]] a new [[Password|password]]with which they can log into the system.
==Single Sign-On==
Smartstaff, administrator
60
edits

Navigation menu