Skip to main content

EasyPay: Configure your password policy in EasyPay

Learn what each password policy setting does and how to configure them to keep your organisation's accounts secure.

The password policy feature lets you define a set of rules that encourage users to create strong, secure passwords. This article explains what each setting does so you can configure the policy to suit your organisation's security requirements.

📌Note: Password policy settings are typically managed by a system administrator. Ensure you have the appropriate permissions before making changes.


Password complexity settings

These settings control the character requirements for all user passwords.

Minimum password length

Defines the minimum number of characters a password must contain. Setting a higher value makes passwords harder to guess or crack through brute-force methods.
​

Minimum number of upper case characters (A–Z)

Defines the minimum number of English upper case letters a password must include. Requiring at least one upper case character increases password complexity.
​

Minimum number of lower case characters (a–z)

Defines the minimum number of English lower case letters a password must include. Combined with upper case requirements, this ensures a mix of character types.
​

Minimum number of numeric digits (0–9)

Defines the minimum number of numeric characters a password must contain. Including numbers alongside letters significantly strengthens password security.


Password history and reuse

Keep history of last 10 passwords

When enabled, the system stores a record of each user's last 10 passwords. Users will not be able to reuse any of their previous 10 passwords when setting a new one. This prevents users from cycling back to familiar, potentially compromised passwords.


Account lockout settings

These settings protect accounts from unauthorised access by limiting failed login attempts.
​

Maximum number of failed logins

Defines how many consecutive failed login attempts are allowed before an account is locked. Once this limit is reached, the account is automatically locked to prevent further attempts.
​

Failed login interval (in minutes)

Defines how long a locked account remains locked after the maximum number of failed logins has been reached. Once this duration has passed, the account is automatically unlocked and the user can attempt to log in again.


Session and password expiry settings

User account lock-out duration (in minutes)

Defines the period of inactivity after which a user is automatically logged out. If a user's session has been idle for longer than the set duration, they will be signed out and required to log in again.

🤓Tip: Setting a shorter inactivity timeout reduces the risk of unauthorised access if a user leaves their session unattended.

Maximum password age (in days)

Defines how long a password can be used before the user is prompted to change it. The system tracks the date each password was last changed. When the current date exceeds the last changed date plus the maximum password age value, the user is prompted to set a new password at their next login.

Did this answer your question?