What is a password policy for?
A password policy defines the complexity requirements that passwords stored in your categories must meet (length, character types, and so on).
You can now choose how that policy applies within your organization, and to which scope:
- None: no policy is applied automatically.
- Default policy: the policy is applied automatically but remains editable by the user.
- Mandatory policy: the policy is enforced and cannot be changed or bypassed.
Who can configure password policies?
- Administrators and moderators of a parent or semi-autonomous organization have full access: creating, editing, deleting and applying policies.
- In a limited organization, access is restricted: the full management tab is not available and the organization inherits the policies of its parent organization.
- A Multi-Admin only sees and edits the policies of the organization they are currently signed in to.
- Standard users have no access to this configuration: they simply see the policy applied when they create or edit a password.
Configuring how a policy applies
The policy management page opens in read mode: you can review the current configuration with no risk of changing it by mistake. If no policy exists yet, a message tells you so.
To change the configuration:
- Open the Policy management page.
- Click “Edit” to switch to edit mode.
- Choose None, Default policy or Mandatory policy.
- Select the policy you want, then the scope it applies to.
- Click “Confirm”.
- Confirm again in the confirmation window that appears.
A confirmation message appears once the policy has been applied. If you click “Cancel”, nothing is saved and the previous configuration stays active.
Mandatory policy
For a mandatory policy, you must select a policy and at least one scope. It then applies systematically to every category in the scope, existing and future alike, with no way for users to bypass it.
Default policy
For a default policy, selecting a scope is optional:
- without a scope: the policy is applied automatically to new categories only;
- with a scope: it is also applied to the existing categories in the selected scope.
In both cases the policy selection field stays available: the user can pick another policy, or none.
What happens when a new category is created
- Mandatory policy configured: it is applied automatically, with no possibility of change.
- Default policy configured: it is applied automatically and the selection field stays editable.
- No policy configured: no policy is applied.
Only the state of the configuration at the moment of creation is taken into account. Automatic application never modifies categories that already exist.
Inheritance between organizations
- A semi-autonomous organization manages its own policies: it inherits nothing from its parent organization.
- A limited organization inherits the policies of its parent organization:
- a mandatory policy set by the parent applies to all of its new categories without exception;
- a default policy set by the parent is offered at creation time and remains editable.
Good to know
- Every significant change to a policy requires a confirmation before it is applied.
- In read mode, no action is possible: this is deliberate, to prevent accidental changes.
- When you edit a default policy that is already applied, the scope stays unchanged until you explicitly modify it in edit mode.
- A Multi-Admin who switches organization sees the policy list refresh: only the policies of the active organization are displayed.
Updated