Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Go to Settings -> Options -> Security Policypolicy (1-2).
  2. Set the minimum password length (3).
  3. Set the number of most recent passwords for each user to be stored (4). 0 – do not store password history. If this value is non-zero, passwords stored in history may not be reused.
  4. Set password expiration time interval in days (5). After the time interval expires, the user will be prompted to set a new password. 0 – the password never expires.
  5. Select positions to meet complexity requirements: nothing, password only, user name and password (6).
    The requirements:
    1. user name:
      1. must contain no less than 6 characters and at least 2 digits;
      2. must not include common role names, such as: admin, administrator, administrator1, root, super, superuser, supervisor.
    2. The password has to contain at least 8 characters, which must meet at least 3 requirements listed below:
      1. at least 1 capital letter;
      2. at least 2 lowercase letters;
      3. at least 3 digits;
      4. at least 4 special characters, such as:    !\"#$%&'()*+,-./:;<=>?@[\\]^_`{|}~
  6. If you need to limit the number of sessions per user to one, check the corresponding box (7). This requirement also applies to web and mobile Clients.
  7. Set the number of failed login attempts to lock a user's account (8). 0 – no account locking on incorrect passwords.

    Note
    titleAttention!

    When unblocked, the user is offered only one authentication attempt. A successful authentication will reset the failed attempts counter to zero, otherwise the user account will be blocked again.


  8. Set the duration of user account locking on failed login attempts, in minutes (9). 0 – the account can be unlocked by the administrator only.
  9. Click Apply.

...