Password security policy configuration
From the Password policy section you manage the security rules that all users must follow when creating or renewing their passwords. Settings apply across the entire platform and are divided into three areas: password composition, expiration and renewal, and access and sessions.
To access: Platform Settings > Platform > Password policy.
Required Permission
This section is accessible only to users with the permission Can create and administer users, user groups, and the password policy.
Does your organization use Single Sign-On (SSO)?
If users access THRON via SSO, password management is delegated to your external Identity Provider and these settings may not apply. Contact your THRON account representative to verify your configuration.
Password composition
Defines structure requirements that passwords must meet upon creation or change.
Rule |
Description |
|---|---|
Must not contain portions of username |
Prevents using parts of the username in the password |
Must contain at least one uppercase letter |
Requires at least one uppercase letter |
Must contain at least one lowercase letter |
Requires at least one lowercase letter |
Must contain at least one numerical digit |
Requires at least one number |
Must contain at least one special character |
Requires at least one non-alphanumeric character (e.g. |
Must be at least N characters long |
Sets minimum password length. Configurable value: min. 8, max. 30 characters |
Enable or disable each rule using its toggle. Active rules are displayed to the user during password creation.
Note
Minimum length is always enforced. Default value is 8 characters.
Password expiration and renewal
Controls password lifecycle over time.
Setting |
Description |
Limits |
|---|---|---|
Password expires after N days |
Forces password renewal after configured number of days |
— |
New password must differ from previous N passwords |
Prevents reusing the last N passwords |
min. 1, max. 4 |
User activation link expires after N days |
The link sent to a new user to activate their account expires after N days |
min. 1, max. 60 |
Platform access and session management
Setting |
Description |
Notes |
|---|---|---|
Users can no longer log in after N days of inactivity |
Automatically disables access for users who have not logged in for N days |
Excludes users with role Administrator or permission Can create and administer users, user groups, and the password policy |
Recommended configuration
If configuring the policy for the first time or aligning with common security standards, start with this configuration:
Setting |
Recommended value |
|---|---|
Must not contain portions of username |
Enabled |
At least one uppercase letter |
Enabled |
At least one lowercase letter |
Enabled |
At least one numerical digit |
Enabled |
At least one special character |
Enabled |
Minimum length |
12 characters |
Password expiration |
90 days |
History memory |
3 passwords |
Activation link expiration |
7 days |
Inactivity lock |
90 days |
Need help?
For technical issues, contact support@thron.com.