Skip to main content
What a password has to be, what happens when somebody guesses wrong, whether a second step is required, and how long being signed in lasts.
Nothing on this screen is enforced by the screen itself — every rule is applied by the server on every sign-in and every password change. What this screen does is describe the numbers, so an organisation that has never opened it is not an organisation with no policy: it is running on the product’s own defaults until somebody changes them.

What a password has to be

Minimum length, and which character classes are required — a capital letter, a lower-case letter, a digit, a symbol.
A longer minimum costs an attacker more than requiring a capital, a digit and a symbol does — that combination tends to produce “Password1!” across a whole site. The character-class toggles are here for the security standard that requires them, not because they are the strongest choice available.

What it may not be again

How many previous passwords are remembered, and the shortest time a new one must be kept before being changed again — without a minimum age, someone can cycle through their history in a minute and land back on the password you were stopping them reusing. Passwords can also be set to expire after a number of days; left at zero, they never do.

When somebody guesses

How many failed attempts lock an account, and for how long. Locking the wait can also double on each repeat failure, up to a day, for the ordinary case where the same person still hasn’t found their password. An administrator clears a lockout from people and access, and doing so writes an audit row naming who cleared whose.

Whether a password is enough

Two-step sign-in, for anybody signing in with a password: Start with Anybody may turn it on rather than moving straight to Everybody: the middle setting is what lets people enrol in their own time, ahead of the day it becomes required for everyone. Enrolling shows a QR code for an authenticator app and a set of recovery codes, shown once, on the way in — not on a screen you have to sign in again to find. Each recovery code signs in once, and is the way back from a lost phone that doesn’t need an administrator.
This governs password sign-ins only. Somebody arriving through an identity provider is not asked again here — their second factor lives with their provider, administered by their own security team. See identity providers.

How long being signed in lasts

Who is signed in

A live register of sessions — who, from where, since when — with an End action per row. Ending a session refuses that token’s next request; it is not the same as revoking a handset, which also stops that device’s sync and its ability to sign in again. For a lost handset, do both — see the Sync Center.

Who can use this

Changing this policy needs the authentication permission, kept deliberately apart from general configuration. Reading who is signed in, and ending a session, are governed separately again — see roles.