User Policies

With user policies, administrators can set security restrictions on passwords, account lockout policies, display options, and more.

Every user role has user policy, created automatically. User policies can be found under System Tools > System Options on the User Policies tab. Administrators can change the settings by opening the policy. The settings are grouped on the following pages:

  • Password Policy
  • Account Lockout Policy
  • Display Options

Password Policy

On the Password Policy page, the administrator can specify:

  • minimum and maximum password length

Note

The minimum and maximum values are inherited from what is set up in System Options. You can select values within the inherited range. Refer to System Options to learn more.

  • complexity requirements for passwords
  • the number of passwords to keep as history
  • when a password expires
  • when the system displays the upcoming password expiry notification
  • after how many days of inactivity the user account locks
  • whether multi-factor authentication is turned on or off for the user policy or the user policy uses the global default setting for multi-factor authentication

Note

The Enable Multi-Factor Authentication section only displays if multi-factor authentication is enabled in System Options. For more information refer to Set Up Multi-Factor Authentication.

Account Lockout Policy

On the Account Lockout Policy page, the administrator can specify:

  • the number of invalid attempts at logging onto the system a user is allowed before the system locks them out
  • the time frame for failed login attempts
  • the duration of the lockout period
  • a password reset PIN users must provide during password reset
  • that automatically generated passwords use digits only
  • when the reset expires

Display Options

On the Display Options page, the administrator can specify:

  • the main banner that displays to users
  • the company banner, the company portal, and company portal in setup mode to be displayed to users
  • the person banner and person portal that displays
  • the incorporation banner and incorporation portal to be displayed

For more information about banners and portals, refer to the Portal Customisation section in the Help Centre.