You can create unique password policies for user groups to define specific password complexity, aging, lockout, and recovery email settings to align with the needs of different groups. This enables you to implement targeted security strategies that match the specific risk profiles and needs of each group, ultimately easing the password management burden on individual users.
Key Features
- Create customized policies
- Assign User Groups
- Define password complexity, aging, lockout, and recovery email settings
- Customizable policy precedence so admins can manage the password settings of overlapping users in multiple policies.
Prerequisites
- In order to leverage this functionality, you need to create user groups based on distinct password security needs, possibly according to roles. See Get Started: User Groups to learn more.
Managing Password Policies
To view Password Policies:
- Log in to the .
- Go to Security Management > Password Policies.
The Password Policy page displays the Default Policy.聽

This default policy is the current password management settings set in Settings > Security > Password Management.
You can create custom policies using the + New button. Any custom policies that you create will be added here.
You can view details such as the order of precedence, policy name, user groups assigned to the policy along with password requirements such as minimum length, lockout attempts, and password expiration.
See Create Custom Password Policy to learn more.
FAQ
It will automatically become the default policy as you add your first custom password policy by user group.
The first best matching policy will be enforced based on the defined policy precedence.
Yes, if they share the same password requirements.
Users who are not part of any user group associated with a custom password policy are subject to the password settings of the Default Policy. It acts as a safety net, so no user in the org exists without a password policy requirement.