How to customize the Password policy?
Know how to customize the password policy.
Recognizing the critical importance of privacy and security, iMocha has established a comprehensive password policy to ensure the utmost safety and integrity of the information systems and data. We offer the ability to customize this policy, including session expiration, password history restrictions, and password expiry prompts. It allows you to tailor these settings according to your organization's specific requirements.
Note: Only the Super Admin have the control over the security and user-experience settings.
The table below displays the available password setting options:
|
Policy |
Policy settings |
Limit |
|
Enforce Password History |
Previous six passwords are retained in memory. |
Minimum - 1 Default- 2 Maximum- 6 |
|
Maximum Password Age |
30 Days |
Minimum- 10 days Default- 30 days Maximum- 120 days |
|
Reset Password Notification |
Begin prompting “5” days before Maximum Password validity remove option to configure sending email days Via Email - every “2” day
|
Default - 5 |
|
Lock Account |
After 10 failed attempts to log in the account is closed for 5 mins |
|
|
Enforce Password change on first login |
Enabled by default |
|
|
End Session After |
After 15 Mins of inactivity |
Minimum- 10mins Default- 120mins Maximum- 360mins |
To customize password policies:
- Go to Settings->Global Settings.
- Click Group Policy Settings.
Customize the values of each setting according to your organization's standards and requirements.
Enforce Password History: Recording past passwords to prevent reusing them during password resets, enhancing security. It ensures users choose different and more secure passwords over time, reducing the risk of unauthorized access to their accounts.
The default limit is set to the past two passwords, you can set it up to the past six passwords.
Maximum Password Age: The maximum duration a user's password is valid before it expires and requires renewal. This security measure is used to enforce regular password changes, reducing the risk of unauthorized access and enhancing overall account security. When the maximum password age reaches, users are prompted to change their passwords to maintain strong and up-to-date credentials.
You can configure the system to display the Reset password notification before the specified number of days here and schedule reminder emails at specified intervals.
Lock Account: Restricting access after the specified number of unsuccessful login attempts, enhancing security against unauthorized access.
The default setting locks the account for 5 minutes after ten consecutive failed login attempts.
Enforce password change on first login: Requires new users to change their temporary password during their initial login, promoting stronger security measures and reducing the risk of unauthorized access.
End Session After: By default, the system automatically logs out users after 10 minutes of inactivity, ensuring security and protecting sensitive data from unauthorized access. - Click Save.
Customizing the policy settings empowers you to tailor your organization's security measures and operational procedures to suit its unique needs. By configuring settings in accordance with your specific requirements, organizations can enhance data protection, improve user experiences, and strengthen overall cybersecurity, ensuring a robust and tailored approach.
For any queries mail us at support@imocha.io