Set Up Your Organization's Password Policy

Change the password requirements and options for Users in your organization.

Last Updated: July 28, 2022

What's in this article?

Password Policy

You can choose from a variety of options when it comes to your User's passwords. Policies can easily be changed in the Workflows section of the Settings view. Let's learn how!

Your ability to change password policies depends on your Role & Permissions.


  1. Click on your avatar at the top right, then click on Settings.
    c6e6c74a99d9be8c8eedfab41d4b879a.jpg
  2. Click on Workflows under Customization. 
    7ac7606be12cae5bdeca893828e2e7ee.jpg
  3. Scroll down and click the Edit Additional Settings button.
    1e52513c4f6498100a1758a8c4137586.jpg
  4. Choose a Password Policy from the picklist. When you are done, click the Save button.

    Policy Options

    Here is a list of all of the available policy options and their settings:

    Options that include "External Identity Provider" in the name should only be chosen if passwords are being stored on an external database.


    NamePatternLockoutExpirationRotationIdle LogoutSession Termination
    Standard Security ProtocolsRequires a minimum of 8 characters including at least 1 uppercase, 1 digit and 1 symbolAccount locks after 5 failed login attempts.Password will never expire.New password can match old password.Users are logged out after 01:00:00 of inactivity.Sessions are terminated after 48 hours regardless of inactivity.
    Standard Security Protocols Or External Identity ProviderRequires a minimum of 8 characters including at least 1 uppercase, 1 digit and 1 symbolAccount locks after 5 failed login attempts.Password will never expire.New password can match old password.Users are logged out after 01:00:00 of inactivity.Sessions are terminated after 48 hours regardless of inactivity.
    PCI Compliant Security ProtocolsRequires a minimum of 8 characters including at least 1 uppercase, 1 digit and 1 symbolAccount locks after 3 failed login attempts.Password will expire after 90 days.New password cannot match previously used 12 passwords. Users are logged out after 00:15:00 of inactivity.Sessions are terminated after 24 hours regardless of inactivity.
    PCI Compliant Security Protocols Or External Identity ProviderRequires a minimum of 8 characters including at least 1 uppercase, 1 digit and 1 symbolAccount locks after 3 failed login attempts.Password will expire after 90 days.New password cannot match previously used 12 passwords. Users are logged out after 00:15:00 of inactivity.Sessions are terminated after 24 hours regardless of inactivity.
    External Identity ProviderRequires a minimum of 8 characters including at least 1 uppercase, 1 digit and 1 symbolAccount locks after 5 failed login attempts.Password will never expire.New password can match old password.Users are logged out after 01:00:00 of inactivity.Sessions are terminated after 48 hours regardless of inactivity.
    PCI Compliant External Identity ProviderRequires a minimum of 8 characters including at least 1 uppercase, 1 digit and 1 symbolAccount locks after 5 failed login attempts.Password will never expire.New password can match old password.Users are logged out after 00:15:00 of inactivity.Sessions are terminated after 24 hours regardless of inactivity.
    PCI Compliant Security Protocols, 15 Char Min PasswordRequires a minimum of 15 characters including at least 1 uppercase, 1 digit and 1 symbolAccount locks after 3 failed login attempts.Password will expire after 90 days.New password cannot match previously used 12 passwords. Users are logged out after 00:15:00 of inactivity.Sessions are terminated after 24 hours regardless of inactivity.
    PCI Compliant Security Protocols, 15 Char Min Password Or External Identity ProviderRequires a minimum of 15 characters including at least 1 uppercase, 1 digit and 1 symbolAccount locks after 3 failed login attempts.Password will expire after 90 days.New password cannot match previously used 12 passwords. Users are logged out after 00:15:00 of inactivity.Sessions are terminated after 24 hours regardless of inactivity.


    a8c5fc6bbbd24eb601fc503c8a7c8471.jpg



  5. Your organization's password policy has been updated!
Help us improve. Was this article helpful?


Can't find what you're looking for? Submit an Article Request.