This article explains password requirements, expiration, password reuse, failed-login lockouts, and account recovery for Alloy Dashboard users.
Password requirements
Passwords for users signing in with native Alloy credentials must:
Be at least 8 characters long
Contain at least one lowercase letter
Contain at least one uppercase letter
Contain at least one number
Contain at least one special character
Be different from the previous four passwords
There is no maximum password length.
These requirements apply to users signing in with an Alloy-managed username and password. Organizations using SAML single sign-on (SSO) can manage password requirements through their identity provider.
Password expiration
Native Alloy passwords expire every 90 days. Users can update their password after confirming access to the email address associated with their Alloy account.
Password reuse
New passwords cannot match any of the previous four passwords.
For users signing in through SAML SSO, password reuse requirements are managed by the organization’s identity provider.
Failed-login lockouts
Alloy applies a tiered lockout policy to consecutive failed login attempts for users signing in with native Alloy credentials.
Failed attempts |
Result |
|---|---|
7 consecutive attempts |
The account is locked for 30 minutes. |
13 total attempts |
After the first lockout ends, 6 additional consecutive failed attempts trigger another 30-minute lockout. |
18 total attempts |
The account is permanently locked and must be unlocked by an account administrator from Settings > Agent Settings. |
Unlocking a permanently locked account
An account administrator can unlock a permanently locked agent account:
Go to Settings > Agent Settings.
Locate the agent with the locked status or lock icon.
Select the menu icon next to the agent.
Select UNLOCK ACCOUNT.
Confirm that the agent’s status changes to Account is Active.
For more information, see How Admins can Unlock “Locked” Agent Accounts.
Resetting a password
Password reset links and new-account invitation links expire after three days. If a link has expired, request a new one from the Alloy Reset Password page.
If you do not receive the reset email, see Where is my password reset email?.
Related security settings
Organizations can also configure account-level multi-factor authentication (MFA). Alloy supports authenticator apps using time-based one-time passwords (TOTP) and SMS verification for US phone numbers. TOTP is the recommended method.
See:
Comments
0 comments
Article is closed for comments.