Print      Open PDF Version of Online Help


Previous Topic

Next Topic

About Sign-In and Password Policies

Siebel CRM On Demand provides the highest levels of security for your company. Security constraints have been built in to ensure that only authorized users have access to your data.

Additionally you can enforce certain sign-in, password, and authentication policies to raise the level of security within your company. For example, you can set the sign-in timeout to 15 minutes to better adhere to your corporate security policies. And if any of your users forget their password, they can receive a new one by simply answering a set of validation questions.

Security Considerations

  • Before you set up your sign-in and password controls, you need to carefully consider your security needs. Some of the questions you should answer are:
  • What type of user ID do you want to use?
  • How long do you want a user's system-generated temporary password to be valid for?
  • What will be the maximum number of sign-in attempts that is allowed before a user is locked out of the application?
  • How long will the sign-in lockout be for? How often do you want users to change their passwords?
  • Do new passwords have to be different from old passwords?
  • What is the minimum password length?
  • How many security questions must be completed by each user to enable the Forgot Password feature?
  • How many security questions must be answered correctly before the application automatically resets a user's password?
  • Do you want to allow users to change their user IDs or email addresses?

When you have defined your sign-in and password policies, you can implement them in the Company Administration pages in the application.

Password Setting Changes

If you make changes to the password settings, the system does not enforce the changes until the current passwords expire. For example, if you change the minimum password length from seven characters to 10 and a user already has a seven character password, the user can use the seven character password until it expires. At that time, the user will have to create a new password of at least 10 characters.

It is best to set the internal policy and select the settings before adding new users to the system. If, however, you must make a change to your security policy immediately, you have the ability to reset all user passwords. This action generates an email to all the users in your company providing them with a new temporary password. You must have the Reset Passwords privilege to do this.

Forgot Your Password Feature

You must define the minimum number of security questions and answers that users must provide to have their passwords reset. Each user must complete the setup of this feature by selecting the required number of security questions and entering the answers to the questions. When this feature is set up, users are able to reset their own CRM On Demand passwords without the company administrator intervening.


Published May 2008