Skip to main content

Alloy Login Password Rules

This article explains password requirements, expiration, password reuse, failed-login lockouts, and account recovery for Alloy Dashboard users.

Password requirements

Passwords for users signing in with native Alloy credentials must:

  • Be at least 8 characters long

  • Contain at least one lowercase letter

  • Contain at least one uppercase letter

  • Contain at least one number

  • Contain at least one special character

  • Be different from the previous four passwords

There is no maximum password length.

These requirements apply to users signing in with an Alloy-managed username and password. Organizations using SAML single sign-on (SSO) can manage password requirements through their identity provider.

Password expiration

Native Alloy passwords expire every 90 days. Users can update their password after confirming access to the email address associated with their Alloy account.

Password reuse

New passwords cannot match any of the previous four passwords.

For users signing in through SAML SSO, password reuse requirements are managed by the organization’s identity provider.

Failed-login lockouts

Alloy applies a tiered lockout policy to consecutive failed login attempts for users signing in with native Alloy credentials.

Failed attempts

Result

7 consecutive attempts

The account is locked for 30 minutes.

13 total attempts

After the first lockout ends, 6 additional consecutive failed attempts trigger another 30-minute lockout.

18 total attempts

The account is permanently locked and must be unlocked by an account administrator from Settings > Agent Settings.

Unlocking a permanently locked account

An account administrator can unlock a permanently locked agent account:

  1. Go to Settings > Agent Settings.

  2. Locate the agent with the locked status or lock icon.

  3. Select the menu icon next to the agent.

  4. Select UNLOCK ACCOUNT.

  5. Confirm that the agent’s status changes to Account is Active.

Resetting a password

Password reset links and new-account invitation links expire after three days. If a link has expired, request a new one from the Alloy Reset Password page.

If you do not receive the reset email, see Where is my password reset email?.

Related security settings

Organizations can also configure account-level multi-factor authentication (MFA). Alloy supports authenticator apps using time-based one-time passwords (TOTP) and SMS verification for US phone numbers. TOTP is the recommended method.

See:

Did this answer your question?