Enforcing Strong Passwords with Default Login Rules in SFM
Strong passwords are essential for maintaining security. In SFM, Login Rules help ensure users create passwords that are difficult to guess or crack.
These rules can be configured to apply either to:
- User Groups: via Administration > Groups & Permissions
- Individual Users: via Administration > User Accounts
When rules are set at the group level, they are automatically applied to all users in that group. However, these settings can be customized per user from the User Accounts screen. Applying login rules is optional, administrators can choose whether or not to enforce them for each user.
Enabling Default Login Rules
Administrators can activate the login rules by selecting the Enable Rules checkbox (highlighted in red in the interface). Not all rules need to be enabled, it's up to the administrator to determine the desired level of password strength and security.
Description of Login Rules
Here’s a breakdown of each available rule:
- Min Length: Sets the minimum number of characters required in a password.
- Requires Both Case Letters: Ensures the password includes at least one uppercase and one lowercase letter (A–Z, a–z).
- Requires Digits: Requires at least one numeric digit (0–9).
- Requires Symbols: Requires at least one special character (e.g., @, *, &, %).
- Password History: Specifies how many previous passwords are remembered and cannot be reused. If a user attempts to reuse a recent password, the system will display a warning message.
- Expire Every [X] Days: Defines how long a password remains valid before it must be changed. When a password expires, the user is prompted to update it.
- Notify Before [X] Days: Sets how many days in advance users are notified before their password expires. A reminder message is displayed accordingly.
Changing an Expired Password
When prompted to change an expired password, users are directed to a password update screen. The new password must comply with the login rules defined for their account.