Configuring account policies



You can use the Account Policies page to establish security criteria and policies for user accounts and passwords, and to set default values. You can also automatically disable or delete inactive user accounts, and enable the option to receive a warning notification before this action is completed.

Related topics

The following image displays the Account Policies section:

authentication server_account policies.png

Password Policies

The following table describes the UI features in the Password Policies section:

UI feature

Description

Minimum Password Length nnn

Used by the password strength checker

It requires the user-entered passwords to be at least this length.

Require Numeric Character

Used by the password strength checker

It requires a user-entered passwords to contain at least one numeric character.

Require Special Character

Used by the password strength checker

A non-alpha or non-numeric characters is required to be present within the password if checked.

Prohibits Repeating Characters

Used by the password strength checker

Adjacent repeating characters are prohibited if this control is checked.

Prohibits Dictionary Words

Used by the password strength checker

The password is stripped of numeric and special characters and checked against a dictionary file.

Prevent reuse of previous nnn passwords

Maintains a limited history of old passwords and prevents attempts to use one of them

Important

nnn indicates the number of previous passwords you want to reuse.

Account Settings

UI feature

Description

Lockout users after nnn invalid login attempts

The number of times a user may enter an incorrect password for a valid user ID before the account is disabled and the user is locked out.

Important

nnn indicates the number of invalid login attemts allowed.

Disable Account

Enable this toggle button if you want to lock out the user unless a BMC AMI Ops Console Management administrator manually re-enables the user.

Unlock Users after nnn (minutes)

Enable this toggle button if you want to automatically re-enable the account after a specific time elapses.

Passport expires after nnn Days

Number of days before a password must be changed

Perform automatic Account Management

Checking this enables a daily check by the server for inactive user accounts and taking action as defined by the remaining options.

Disable users after nnn inactive days

The number of days an account may remain idle before it is automatically disabled.

Delete users after nnn inactive days

The number of days an account may remain idle before it is automatically deleted.

Warn about deleting after nnn inactive days

The number of days an account may remain idle before an e-mail is generated.

Send Email to

Email address(es) to receive notification

If more than one address is needed, enter a comma-separated list of email addresses to send notifications.

SMTP Server

The mail server used for delivering emails.


 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*