- 17 Mar 2022
- 1 Minute To Read
-
Print
-
DarkLight
-
PDF
Enforcing Password Policies
- Updated On 17 Mar 2022
- 1 Minute To Read
-
Print
-
DarkLight
-
PDF
Whatfix follows industry best practices to assure customer account safety & compliance. The default password policy enforces a minimum of 8 characters. However, we also support those businesses who wish to implement a password policy that is more aligned to their organization's security standards. In this section, we have explained the different password policies you can configure:
-
Policies are enforced through all login touch points (dashboard, website, and editor)
-
Password Length:
- Min/Max - 1/100 characters
-
Password Composition:
-
Alphanumeric indicators:
- Upper Case
- Lower Case
- Number
- Any Special Character
-
-
Password Expiry:
-
No notifications are sent to the user prior to the expiry of the password.
-
Once the password expires, a password expiry message along with information about a password reset link will be sent by email.
-
Min/Max - 90/365 days
-
-
Password Retention:
- Min/Max - 3/10
-
Login Failure:
- Once you cross the login failure threshold, the account is LOCKED.
- Once locked, you receive an email with instructions to unlock your account. For more information, see How can I unlock my account when locked?