Print      Open PDF Version of Online Help


Previous Topic

Next Topic

Defining Your Company's Password Controls

You can define the application's password policy. For example, you can set the application's password policy to conform to your company's protocols about how long passwords should be and how often they should expire.

To define your company password controls

  1. In the upper right corner of any page, click the Admin global link.
  2. In the Company Administration section, click the Company Administration link.
  3. In the Company Profile section, click the Sign In and Password Control link.
  4. On the Company Sign In and Password Control page, fill in the information, and then save the settings.

    The following table describes the settings.

    NOTE: Only users whose roles include the Change Password privilege can use the Forgot Your Password feature. The users must also have security questions and answers set up in the system.

    Setting

    Possible Values

    Usage

    Sign-in Policy Information

    Company Sign-in ID

    Text box

    Is a unique identifier for your company. When creating new users this identifier will be the first portion of the User Sign In Id (Company Sign-in ID) for the user. When new users are created and the Default User ID Type is Company Sign-in ID, the Company Domain part of the user ID is prepopulated with this value. This setting can also be accessed from the Company Profile page.

    Maximum Number of Sign In Attempts

    3, 5, or 10 attempts

    The maximum number of failed sign-in attempts that are allowed before the user's account is locked.

    Sign In Lockout Duration

    15, 30, 60 minutes or Forever

    The length of time that the user's account is locked.

    Password Control Information

    Expire User Passwords In

    30, 60, 90 days, one year, or never expires

    The length of time that a user's password is valid. After this period has elapsed, the user is forced to change the password.

    Minimum Password Length

    Number between 6 and 10

    The minimum number of characters that can be used for a password.

    Maximum Number of Password Changes

    Number between 1 and 20

    The maximum number of times that a user's password can be changed as specified in the Password Change Limit Window setting. If a user attempts to change a password more than the specified number of times, the change is not allowed.

    Password Change Limit Window

    Number of days (from 1 to 7)

    The period during which the Maximum Number of Password Changes setting applies.

    Your New Password Must Be Different Than Your Old Password

    Check box

    Applies when a user changes his or her password.

    Authentication Information

    Number Of Security Questions To Be Completed

    Number between 1 and 8

    To use the Forgot Your Password feature, a user must select and answer the specified number of security questions.The user's questions and answers are stored for future use.

    Number Of Security Questions To Be Answered

    Number between 1 and 8

    This setting applies to the number of questions and answers the user has set up for the Forgot Your Password feature. When the user clicks the link, Forgot Your Password?, on the Sign In page, the user receives an email, shortly afterwards, with a link to a temporary page. On the temporary page, the user must answer the number of security questions based on this value before the password can be reset. You can set a larger number of questions to be completed than are required to be answered. A random selection of the completed questions is displayed to authenticate a user.

    Number Of Days Temporary Sign In Is Valid

    Number of days (1 to 14)

    This setting determines the number of days that a temporary sign-in password is valid. An email with temporary sign-in information is typically sent when a new user is added, or when the company administrator or Customer Care resets the user's password.

    Number Of Temporary Password Sign In Attempts

    Number of attempts (1 to 14)

    The total number of sign-in attempts allowed using a temporary sign-in password. If this value is exceeded, the user's temporary sign in information becomes invalid, and the user must have the password reset again.

    Additional Information

    Allow Users To Change User ID

    Check box

    If the check box is selected, users who edit their User Profile can change their User ID. If the feature is not enabled, only the company administrator can change the user IDs.

    Allow Users To Change Email Address

    Check box

    If this check box is selected, users who edit their user profile can change their email address. If this feature is not enabled, only the company administrator can change the email addresses.


Published May 2008