Password Policy for MSP Administrators
Password Policy for organizations encourages the use of strong passwords and ensures that administrators get added security for their Managed Services Center (MSC) accounts. This policy is applicable to all MSP Admins, Tenant Admins, and Read-only Admins.
Note: Only an MSP Administrator can configure the Password Policy. Tenant Admins and Read-only Admins do not have access to these settings.
Note for SSO Users: If your organization utilizes Single Sign-On (SSO), your password complexity and expiration are governed by your Identity Provider (IdP). This MSC Password Policy strictly applies only to local MSC passwords and the MSP Admin "Failsafe" login method. To know more about this, refer to the Sign in to MSP documentation.
Password Policy Configurations
The Password Policy is enabled by default with mandatory settings that allow you to govern password creation and control the password lifecycle.
Password Configuration | Settings |
Strong Password Strength
Minimum password length, which includes mandatory usage of alphanumeric characters including special characters, that help you build a strong password. | Password must have:
|
Reset Password Policy
Prohibits the usage of old passwords when it is time to set a new password. | Cannot be the same as the last 3 passwords. |
Max Invalid Login Attempts
Provides additional security by temporarily blocking the administrator's account for a period of 30 minutes and prevents unauthorized access in the event of repeated invalid/failed login attempts. | 5
After the limit is exhausted, login for that Admin is blocked for 30 minutes. This lockout remains active for the full 30 minutes, even if the password is reset. |
Password Expires Every (Configurable)
Keeps the password healthy by enforcing a regular cycle of changing passwords as per the predefined intervals. | The default is 60 days.
MSP Admins have the option to change it between a range of 30-99 days.
Once the configured duration expires, administrators will be automatically prompted to create a new password directly on the login screen during their next sign-in attempt.
|
View and Update the Password Expiry
Navigate to Managed Services Center (MSC) > Settings > Access Settings
2. The Password Policy section displays the policy configurations
3. Only the Password Expiry configuration is editable
Password Expiry Details
Public Cloud: default is 60 days, maximum allowed is 99 days
