Print      Open PDF Version of Online Help


Previous Topic

Next Topic

Defining Your Company's Password Controls

You can define the application's password policy. For example, you can set the application's password policy to conform to your company's protocols about how long passwords should be and how often they should expire.

Highly Recommended: Enable the Forgot Your Password feature by setting up the number of security questions and answers that users will be must provide to have their passwords reset.

To define your company password controls

  1. In the upper right corner of any page, click the Admin global link.
  2. In the Company Administration section, click the Company Administration link.
  3. In the Company Profile section, click the Sign In and Password Control link.
  4. On the Company Sign In and Password Control page, fill in the information, and then save the settings.

    The following table describes the settings.

    NOTE: Only users whose roles include the Change Password privilege can use the Forgot Your Password feature. The users must also have security questions and answers set up in the system.

    Setting

    Possible Values

    Usage

    Sign-in Policy Information

    Default User ID Type

    Email address

    Company domain\user ID

    User ID

    Determines how the default user ID for a new user is formatted.

    Email Address: The user ID field is set to the value entered in the user's Email field.

    Company Sign-in ID: The user ID field is set to the value specified in the Company Domain Name field, followed by a back slash (\). The company administrator can then add the user's User ID to this text.

    User ID: The user ID field is blank and the company administrator must enter a value.

    Company Sign-in ID

    Text box

    Is a unique identifier for your company. When creating new users this identifier will be the first portion of the User Sign In Id (Company Sign-in ID) for the user. When new users are created and the Default User ID Type is Company Sign-in ID, the Company Domain part of the user ID is prepopulated with this value. This setting can also be accessed from the Company Profile page.

    Maximum Number of Sign In Attempts

    3, 5, or 10 attempts

    The maximum number of failed sign-in attempts that are allowed before the user's account is locked.

    Sign In Lockout Duration

    15, 30, 60 minutes or Forever

    The length of time that the user's account is locked.

    Password Control Information

    Expire User Passwords In

    30, 60, 90 days, one year, or never expires

    The length of time that a user's password is valid. After this period has elapsed, the user is forced to change the password.

    Minimum Password Length

    Number between 6 and 10

    The minimum number of characters that can be used for a password.

    Maximum Number of Password Changes

    Number between 1 and 20

    The maximum number of times that a user's password can be changed as specified in the Password Change Limit Window setting. If a user attempts to change a password more than the specified number of times, the change is not allowed.

    Password Change Limit Window

    Number of days (from 1 to 7)

    The period during which the Maximum Number of Password Changes setting applies.

    Your New Password Must Be Different Than Your Old Password

    Check box

    Applies when a user changes his or her password.

    Authentication Information

    Number Of Security Questions To Be Completed

    Number between 0 and 8

    To enable the feature, Forgot Your Password?, for your company, this setting must have a value greater than zero (0). After the value is set, a user who wants to use the Forgot Your Password feature must select and answer the specified number of security questions.The user's questions and answers are stored for future use. To enable the feature, Forgot Your Password?, click the My Setup global link on any page and click Personal Profile.

    Number Of Security Questions To Be Answered

    Number between 0 and 8

    This setting applies if the Forgot Your Password feature is enabled for your company, and if the user has set up questions and answers. When the user clicks the link, Forgot Your Password?, on the Sign In page, the user must answer the specified number of questions before an email with temporary sign in information is dispatched. You can set a larger number of questions to be completed than are required to be answered. A random selection of the completed questions is displayed to authenticate a user.

    Number Of Days Temporary Sign In Is Valid

    Number of days (1 to 14)

    This setting determines the number of days that a temporary sign-in password is valid. An email with temporary sign-in information is typically sent when a new user is added, or when the company administrator or Customer Care resets the user's password.

    Number Of Temporary Password Sign In Attempts

    Number of attempts (1 to 14)

    The total number of sign-in attempts allowed using a temporary sign-in password. If this value is exceeded, the user's temporary sign in information becomes invalid, and the user must have the password reset again.

    Additional Information

    Allow Users To Change User ID

    Check box

    If the check box is selected, users who edit their User Profile can change their User ID. If the feature is not enabled, only the company administrator can change the user IDs.

    Allow Users To Change Email Address

    Check box

    If this check box is selected, users who edit their user profile can change their email address. If this feature is not enabled, only the company administrator can change the email addresses.

    TIP: If authentication is set up after users have already been using Siebel CRM On Demand, distribute a company-wide alert instructing employees to set up their security questions.


Published 05/11/2007