Password Policy Authentication
Huddle supports password authentication. Under the Company Manager the Password Policy for the company can be adjusted to be more complex than the default. All accounts that fall under this Company are impacted by the change. This article provides more detail on the options available.
Accessing Password Configuration
From the Company Manager admin page navigate to Security->Password Configuration.
Configurable Options
The following areas of a Password can be configured. Toggling the On/Off switch to the right will enable the setting and open up any additional options.
Password Complexity
- Password length - the default is a minimum of 8 and a max of 16 characters.
- Upper and lower case - define if the password must have mix or a specific casing.
- Numbers - toggle whether the password must have numbers as well.
- Special characters - enable the use of special characters in the password. The acceptable characters are, !@#$%&^*.
Password History
Define how long the current password can be used for, Once the date has been met the password will need updating. Disabling the toggle will allow passwords to be used indefinetely.
- Password expire after - set the duration of the password after which the password expires.
- Prompt user - define when the user should be prompted that their password is about to expire.
Lock Out
The final setting allows the Company Manager to define what happens when the password has been entered incorrectly.
- Lock out - how many tries the user has before the account is locked out.
- Account is automatically unlock after x minutes - set the length of minutes the lock remains enabled.
- Show signin attempts count - provide verbose messaging on the login screen counting down the number of password attempts remaining.
- Send lockout email to user - notify the user via email their account has been locked.
Note
If a user is a member of workspaces in accounts for other companies, the password policy that will apply to the user with be based on the primary company associated with the user. Support can advise what the primary company is for a user.
Q&A
Here are some questions that we have received and the answers to these:
- What is the user experience when the password configuration is enabled?
- Once enabled, would all users require an immediate update to their password or only if their existing password does not meet the requirements?
- the new rule would only be triggered when the user attempts to change or resets their password
- Would there be an email sent out to users asking them to create a new password?
- No email is sent out, prompts are via in-app baners
- Or would they simply get a password incorrect message the next time they login (and have to proactively use forgot my password)?
- They would be prompted to update their password
- Is the above true if only password expiry is enabled and no other changes are made?
- This would depend on the password age, as the expiry is calculated from date of password creation, not when the toggle was turned on.
- Would a change in password policy also require users to reset their 2FA?
- No, as this is separate and not tied to the password mechanism
- Once enabled, would all users require an immediate update to their password or only if their existing password does not meet the requirements?
- What happens to a user when their password is expired and what is the process to reset their password? If using their old password, would it say that their password is expired or simply that the password is incorrect?
- They would be prompted to update their password
- I’ve noticed for new users, by default we already require a number of items listed in the password configuration, So what does the password complexity options actually do?
- They allow managers to set their own complexity configurations in addition to Huddle's defaults (such as the min/max length)
- Is the default password policy for new users already applied to previous users?
- They would be still using their old passwords, unless they had changed it; which would prompt them to match the new configurations