Password Policy

Enforce strong password requirements and security system-wide

Password Policy
Security
Compliance
Password Strength

Overview

The auth_password_policy module allows configuring password strength, expiration and history requirements.

Helps comply with security regulations and reduce account breach risk.


Key Features

Key points

  • Minimum length - Require passwords of 8-16 characters minimum

  • Complexity - Enforce uppercase, lowercase, numbers, special characters

  • Password expiration - Force password change after 30-90 days

  • Password history - Prevent reuse of last 5-10 passwords

  • Weak password check - Reject common passwords (123456, password)

  • Expiration notifications - Email reminders before password expires


Configure Password Policy

Steps

  • 1. Go to Settings → General Settings → Security

  • 2. Password Policy section, configure parameters

  • 3. Minimum password length: 8-16 characters (recommend 12)

  • 4. Password must contain: Uppercase, lowercase, numbers, special chars

  • 5. Password expiration: 30-90 days (recommend 60)

  • 6. Password history: 5-10 passwords (recommend 5)

  • 7. Click Save


Recommended Configuration

By Security Level

LevelLengthComplexityExpirationHistory
Basic8 charsLetters + numbers90 days3 passwords
Medium10 charsUpper + lower + numbers60 days5 passwords
High12 charsUpper + lower + numbers + special30 days10 passwords

Change Password

Steps

  • 1. Go to My Profile → Account Security

  • 2. Password tab, click Change Password

  • 3. Enter current password

  • 4. Enter new password (must meet policy)

  • 5. Confirm new password

  • 6. Click Save