Skip to main content

Manage password blocklist

The password blocklist contains words and strings that users cannot include in their passwords.

Use a blocklist to prevent easy-to-guess values such as company names, product names, or common weak patterns.

Add password blocklist entries

  1. Click > Configuration > Password Blocklist. The Password Blocklist page appears.

  2. Click Add. The Password Blocklist dialog box appears.

  3. In the text box, enter the Password Blocklist Values.

    note

    You cannot add duplicate words or strings in the Password Blocklist Values list. For example, if you add password to the blocklist, users cannot use password anywhere in their password.

  4. Press <return> to enter each new blocklisted password on a new line.

  5. When done, click Add to return to the Password Blocklist page.

  6. Click Save.

Validate your changes

After you save, verify the following:

  1. The new values appear in the Password Blocklist list.
  2. A test password that contains a blocklisted value is rejected.
  3. A test password that does not contain a blocklisted value can be accepted if all other password policy rules are met.
note

To delete a password blocklist, click beside the blocklist.