Password policy settings
Who is this article for?Users who want to configure Password policy settings
Elevated permissions are required.
This article outlines the configurable options for Password policy settings within Users and Languages.
1. Minimum length
This section allows the user to specify the minimum length of password that users are required to enter when logging into Internal Audit.
- Enter a value by typing directly into the field or using the up and down arrows
Note:Please note, the default length is a minimum of 5 characters, with no maximum length.
Select Submit changes to save the settings
2. Required complexity
This section allows the user to set a percentage value for the password strength.
- The higher the value set, the more elements a password must include to be valid. For example, upper/lower case, special characters and numbers
- Specify the value that the password strength must be. The values the user can choose from is a range from 0 – 100
- The system examines the password for various characteristics, and then provides a percentage value of the numbers of the features present
- The exact calculation is as follows (starting with a counter set to zero)
- Add 2 if the length is over zero characters
- Add 2 if the length is over 6 characters
- Add 3 if the length is over 9 characters
- Add 4 if the length is over 13 characters
- Add 2 if the length is over 18 characters
- Add 1 for each numeric character, up to a maximum of 3
- Add 1 for each non-alpha numeric character, up to a maximum of 3
- Add 3 if mixed case characters are used
- This produces a complexity value which is then divided by 22 (the sum of all above tests)
- 22 is derived using the maximum of 3 for numeric and non-alpha numeric characters, to give a percentage
- The colour spectrum on the right indicates the strength of the value chosen, Red being the strongest, Green being the weakest
- Select Submit changes to save the settings.
- The user must log out of Internal Audit and log back in for the settings to be applied
3. Old password re-use
This section allows the user to determine the number of password changes a user must have before they can start to reuse old passwords.
- Select a value for the number of password changes (from a range of 0 – 100) before an old password can be reused.
- Select Submit changes to save the settings
- The user must log out of Internal Audit and log back in for the settings to be applied
4. Change interval
This section allows the user to determine how long a password can be active before it expires.
- The user can specify the number of months (maximum 999) or number of days (maximum 999)
- Select Submit changes to save the settings
- The user must log out of Internal Audit and log back in for the settings to be applied