As a Workspace ONE UEM administrator, you can configure password policies for administrators using the Passwords settings page. The settings configured here do not apply to Directory Administrators synced or provisioned from an Identity Provider or an on-premises directory.
What can you do with the Passwords settings page?
The path to the settings page on the UEM console is Groups & Settings > All Settings > Admin > Console Security > Passwords.
Using the Passwords settings page, you can:
- Set the length, complexity, and expiration period for the passwords.
- Set the number of password recovery questions an admin must answer to reset the password.
- Specify how many invalid login attempts are allowed before the user is locked out.
- Add custom questions for password recovery.
- Activate or deactivate the questions for password recovery.
Password Policy
You can configure Password policies for Basic Administrators at Organization Groups of type Partner and Customer. By default, these settings are inherited from Global. You can override and configure them to meet your requirements in the Partner or Customer Organization Group.
The Child Permission for Password Policy can be configured at Partner-type Organization Groups only, and can be set to either:
- Inherit or Override
- Inherit Only
| Setting | Description | Default Value | Min Value | Max Value |
|---|---|---|---|---|
| Enforced password history | You can prevent the administrators from reusing old passwords and thus ensure enhanced security. To do so, you can set the number of passwords that the UEM console must remember before allowing the admins to reuse any of the old passwords. | 4 | 0 | 5 |
| Password Expiration Period (days) | You can select the number of days after which a password must expire and must be reset or updated. | 120 | 1 | 9999 |
| Password Notification Period (days) | You can configure the number of days before the Password Expiration Date the administrator must be notified regarding the upcoming expiry. | 5 | 1 | 999 |
| Minimum password length | You can set the least number of characters the password must contain. | 7 | 7 | 15 |
| Password complexity level | You can set the complexity requirements for the password. You can either force users to create passwords that are a combination of letters, numbers, special characters, or not have any restrictions at all. The default complexity level is set to letters and numbers. | Alphanumeric | Alphanumeric | Mixed case Alphanumeric and special characters |
| Maximum invalid login attempts | You can determine the number of invalid login attempts allowed before a lockout. The default amount of time admins are locked out is 10 minutes. | 6 | 1 | 6 |
| Required Password Recovery Questions | You can select the number of password recovery questions the admin must answer to reset the password. | 1 | 1 | 15 |
| Custom Password Recovery Questions | You can activate this setting to allow adding of custom questions. | Enabled | N/A | N/A |
Password Recovery Questions
You can check and change the status of the password recovery questions on this page.
The status of the questions is indicated as either active or inactive.
- Active - A green indicator against a question means the question is active and is available as a password recovery question.
- Inactive- A red indicator against a question means the question is inactive and is unavailable as a password recovery question.
Was this page helpful?