Skip to main content

August 21, 2026

Passwords Settings

As a Workspace ONE UEM administrator, you can configure password policies for administrators using the Passwords settings page. The settings configured here do not apply to Directory Administrators synced or provisioned from an Identity Provider or an on-premises directory.

What can you do with the Passwords settings page?

The path to the settings page on the UEM console is Groups & Settings > All Settings > Admin > Console Security > Passwords.

Using the Passwords settings page, you can:

  • Set the length, complexity, and expiration period for the passwords.
  • Set the number of password recovery questions an admin must answer to reset the password.
  • Specify how many invalid login attempts are allowed before the user is locked out.
  • Add custom questions for password recovery.
  • Activate or deactivate the questions for password recovery.

Password Policy

You can configure Password policies for Basic Administrators at Organization Groups of type Partner and Customer. By default, these settings are inherited from Global. You can override and configure them to meet your requirements in the Partner or Customer Organization Group.

The Child Permission for Password Policy can be configured at Partner-type Organization Groups only, and can be set to either:

  • Inherit or Override
  • Inherit Only
SettingDescriptionDefault ValueMin ValueMax Value
Enforced password historyYou can prevent the administrators from reusing old passwords and thus ensure enhanced security. To do so, you can set the number of passwords that the UEM console must remember before allowing the admins to reuse any of the old passwords.405
Password Expiration Period (days)You can select the number of days after which a password must expire and must be reset or updated.12019999
Password Notification Period (days)You can configure the number of days before the Password Expiration Date the administrator must be notified regarding the upcoming expiry.51999
Minimum password lengthYou can set the least number of characters the password must contain.7715
Password complexity levelYou can set the complexity requirements for the password. You can either force users to create passwords that are a combination of letters, numbers, special characters, or not have any restrictions at all. The default complexity level is set to letters and numbers.AlphanumericAlphanumericMixed case
Alphanumeric and
special characters
Maximum invalid login attempts You can determine the number of invalid login attempts allowed before a lockout. The default amount of time admins are locked out is 10 minutes.616
Required Password Recovery QuestionsYou can select the number of password recovery questions the admin must answer to reset the password.1115
Custom Password Recovery QuestionsYou can activate this setting to allow adding of custom questions.EnabledN/AN/A

Password Recovery Questions

You can check and change the status of the password recovery questions on this page.

The status of the questions is indicated as either active or inactive.

  • Active - A green indicator against a question means the question is active and is available as a password recovery question.
  • Inactive- A red indicator against a question means the question is inactive and is unavailable as a password recovery question.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…