Skip to main content

Configure password authenticator settings

Password authenticator settings determine the requirements for IDaaS passwords, including password reset.

Modify password authenticator settings

  1. Click > Policies > Authenticators. The Authenticators page appears.

  2. Select Password. The Password settings appear.

  3. The Named Passwords field includes a Default password. The default password is the IDaaS-managed password for users unsynchronized with an AD or LDAP directory. To add a Named Password:

    1. Click Add Named Password. The Add Named Password dialog box appears.
    2. Enter the Name and click OK.
    3. Click to enable the Named Password.

      The Named Password must be enabled to configure the policies and assign it to users.

    4. Follow the next steps on this page to configure the policy and click Save.
    5. Repeat these steps to add more Named Passwords.
  4. Set Minimum Length to the minimum number of characters a password must contain. The maximum password length is 255 characters.

  5. Set Maximum Length to the maximum number of characters a password can contain. The maximum password length is 255 characters.

  6. Set Lifetime Days to the number of days a password is valid.

    This setting defines the value of the Default Password Lifetime set for a user's password authenticator (see Assign a password authenticator). A value of 0 sets the password to never expire. The default password lifetime is 90 days. The maximum is 36,500 days.

    The value cannot be less than the setting for the Minimum Lifetime.

  7. Set Minimum Lifetime to the number of days a user must wait between creating and changing their password.

  8. Set Password Kept in History to the number of previous passwords stored in the account password history. This setting prevents users from reusing recent passwords.

    The maximum number of passwords is 255. Enter a value of 0 to disable the password history.

  9. Select the Minimum Password Strength from the drop-down list. A number of factors, such as common passwords, names, phrases, and character repetition determine the strength of a password. The default setting is Good.

  10. Select Compromised Password Detection to verify password changes against lists of passwords compromised in breaches of external sites. The default is true.

  11. Set the Compromised Password Response to configure how IDaaS responds when a user attempts to authenticate with a password that has been found in data breaches. This policy applies only when Compromised Password Detection is enabled.

  12. Optional: Select Active Directory Complexity Requirements to require that any password entered during a password reset or password change meets the password requirements included in the user's Active Directory.

    info

    The Active Directory password must contain characters from three of the following categories:

    • Uppercase
    • Lowercase
    • Number
    • Special character
    • Unicode (permitted for on-premise directories only)

    To use the Password Reset feature for Active Directory users, you must align the IDaaS password settings with the password rules defined in the AD Global Policy. If you do not align the settings, Active Directory could reject the password.

Mapping of AD password settings to IDaaS password settings

AD PasswordIDaaS Password
Minimum password lengthMinimum length
Maximum password ageLifetime Days
Minimum password ageMinimum Lifetime
Enforce password historyNumber of passwords kept in the History List
Password must meet complexity requirementsThere is no direct mapping of AD complexity requirements to IDaaS.
note

The Active Directory settings enforce the Lifetime Days, Maximum Lifetime, and Passwords Kept in History setting values. The Active Directory Password complexity requirements are also enforced when resetting an Active Directory password.

  1. If you selected Active Directory Complexity Requirements, continue to step 15. If you did not select this feature, complete the following steps:

    1. Set Protection Type to either Hashed or Encrypted (Supports CHAP/MSCHAP authentication). You must select Encrypted (Supports CHAP/MSCHAP authentication) to use a CHAP/MSCHAP authentication protocol.

      note

      This setting only applies to new passwords. The password must be changed on IDaaS for changes to the Protection Type to be applied to the password.

    2. From the Include Number drop-down list, select the number of requirements.

      tip

      Tip: To create a password that is all numerals, such as for ATM access, set this option to Required, and set the options for letters and special characters to Not allowed.

    3. Set Number of Numeric Characters if Required to the minimum number of numerals the password must contain when Required is set for Include Number. The Required value cannot exceed 255.

    4. From the Include Uppercase Letter drop-down list, select the uppercase letter requirements.

    5. Set Number of Uppercase Characters if Required to the minimum number of uppercase letters the password must contain when Required is set for Include Uppercase Letter. The Required value cannot exceed 255.

    6. From the Include Lowercase Letter drop-down list, select the lowercase letter requirements.

    7. Set Number of Lowercase Characters if Required to the minimum number of lowercase letters the password must contain when REQUIRED is set for Include Lowercase Letter. The REQUIRED value cannot exceed 255.

    8. From the Include Nonalphanumeric Character drop-down list, select the nonalphanumeric requirements. Permitted special characters are: ! @ # $ % ^ & * + ? / < >

  2. Set Number of Nonalphanumeric Characters if Required to the minimum number of nonalphanumeric characters the password must contain when Required is set for Include Nonalphanumeric Character. The Required value cannot exceed 255.

  3. Set Maximum Repeated Characters to the maximum number of times a character can appear in the password.

  4. Set Maximum Change Time (Minutes) to the amount of time, in minutes, that a password change must be made.

    When IDaaS flags a password for change, you can define how long the user has to complete that change. If the time limit expires, the password change attempt fails and an administrator must reset the password. Enter a positive integer value in minutes.

    note

    Setting Maximum Change Time (Minutes) to 0 does not cause any already-expired passwords to be unexpired.

  5. Optional. Set password expiry notifications as follows:

    1. Select Password Expiry Notifications to automatically send users a message when their passwords are to expire.
    2. Select the Notification Type (Email, SMS, mobile or all three options). If you select more than one option, notifications are sent top-down until a successful message has been delivered.
    3. Set the Notification Days separated by commas. For example, to send a notification five days before expiry and on the day of expiry, enter 0,5.
  6. Click Save to save your changes. The changes apply to all passwords.

Validate your changes

After you save, verify the following:

  1. New password policy values are enforced for the target named password.
  2. If AD complexity is enabled, password updates align with AD policy requirements.
  3. Password expiry notifications trigger on the configured schedule.

Manage Named Passwords

To manage Named Passwords:

  1. Click > Policies > Authenticators. The Authenticators page appears.
  2. Select Password. The Password settings appear.
  3. Select the Named Password.
  4. Do the following as required:
    1. Click next to Named Password to disable. When disabled, you cannot edit the Named Password policy and users cannot use the Named Password.
    2. Click to enable the Named Password.
    3. Click to edit the name of the Named Password.
  5. Click Save.