Password policy
To improve system security and pass compliance reviews, Root users and system admins can configure password rules that apply to all members of the system in System Settings > Security Center > Password Policy, including password strength, password expiration, and password retry limits.
1. Password strength
After Strength checking is turned on, a member's password strength is checked at their next login. If the password doesn't meet the strength requirements, the member is forced to change the password after logging in successfully before they can continue using AE.
When password strength checking is on, the password rules are: 8-20 characters long, containing two of the following: letters, digits, and special characters. Special characters include the English symbols ~`!@#$%^&*()+=_-{}[]\|:;"'?/<>,. Spaces aren't allowed.
2. Password expiration
The password expiration period is the maximum interval between two password changes by a member. Each time a member changes their password, the password expiration date is updated based on the expiration period. After password expiration is turned on, members must change their passwords within the expiration period. From 5 days before the password expires through the day it expires, members are prompted to change their password after logging in.
You can customize password expiration in two ways: The expiration period can be set from 1 to 1024 days, and you can choose whether members can still log in after their password expires. If Login after expiration is turned on, members can log in once with their original password after it expires and are forced to change it after logging in successfully. If Login after expiration is turned off, the account can only be reactivated, and its password expiration date updated, by a Root user changing the member's password.
3. Password retry limit
To prevent brute-force password attacks, you can turn on the password retry limit. If a member enters a wrong password 5 times in a row at any time while logging in, the account is locked for 15 minutes. After the 15-minute lock ends, the member can try again. If members forget their password, they can contact a Root user to reassign one.

