Skip to main content

Password security

These settings only affect locally created users who are not synchronized with a connected Active Directory. Password settings. First you can define after how many days a password must be changed by…

Dennis Reichle
Updated by Dennis Reichle
These settings only affect locally created users who are not synchronized with a connected Active Directory.

Password settings

First you can define after how many days a password must be changed by the user. If you leave the field empty, the validity of user passwords never expires.

You can also define minimum requirements that users must meet when changing their password. These include the minimum length of the password and whether it must contain at least one uppercase letter, lowercase letter, number, or special character.

The minimum length of 8 characters must be adhered to.
SmartProcess also takes into account the password rules you set when generating a password for newly created users.

Automatic temporary access blocking

To protect the system from brute force attacks, access for users is blocked if several incorrect password entries are made for a user name within 5 minutes.

If the user has already successfully logged in once, 10 attempts are available. If the user has not yet logged in, 5 attempts are available.

If the access block is triggered, the user's login is blocked for 30 minutes. For documentation purposes, the system also creates an item in the audit trail for this event.

How did we do?

User notifications

IP Filter (only for SaaS Systems)

Contact