Setting Access, Login, and Security Preferences

Users with the Administrator role can set up access, login, and security preferences for the account at Setup > Company > General Preferences.

Note:

Any changes you make to general preferences are saved in system notes. For more information, see Searching System Notes.

For many preferences you set at the company level, users can override this preference at Home > Set Preferences. If you don't want users to override particular preferences, on the Overriding Preferences subtab, clear the Allow Override box for each preference.

Preference

Description

Password Policy

NetSuite has four built-in password policies for password validation. These policies set the requirements for password length and content:

  • Very strong: minimum length of 12 characters, all four of these character types - uppercase letters, lowercase letters, numbers, special characters.

  • Strong: minimum length of 10 characters, at least 3 of these four character types - uppercase letters, lowercase letters, numbers, special characters.

  • Medium: minimum length of 8 characters, at least 2 of these four character types - uppercase letters, lowercase letters, numbers, special characters.

  • Weak (You shouldn't choose this): minimum length of 6 characters.

Note:

The password policy sets the minimum for the Minimum Password Length field. It doesn't affect the value in the Password Expiration in Days field.

All NetSuite accounts use the Strong policy by default. For more information, see NetSuite Password Requirements.

Minimum Password Length

Minimum Password Length is the minimum number of characters required for user passwords. The default for this field is set by the password policy. Since the default policy is Strong, the default length is 10 characters.

You can make the minimum password length value longer than the minimum required by the policy, but you can't make it shorter.

If anyone in your account has the View Unencrypted Credit Cards permission, you must use the Strong, or Very strong policy.

Note:

Users with the View Unencrypted Credit Cards permission have a special 12 character Minimum Password Length requirement.

For new users logging in with the Customer Center role, and for website shoppers, the password require at least 6 characters.

For more information, see NetSuite Password Requirements.

Password Expiration in Days

Enter the number of days that users can log in to NetSuite before they're prompted to change their password.

Note:

As of 2015, valid values are 1-365. Values entered before 2015 aren't affected by this limit. However, if you change anything on the General Preferences page, only values in this range are accepted. For new accounts, the default is 180 days.

Days are counted from when each user last changed their password, not when the company preference changed. Users can see the dates of the previous password change and current password expiration in the My login audit portal.

Important:

Set a value for Password Expiration in Days to make sure the Password Policy applies to existing users.

  • Employees with the View Unencrypted Credit Card permission have to change their passwords at least every 90 days, unless you set a lower value here.

  • You can check the Require Password Change on Next Login box on employee records. To update many employee records at one time, you can use CSV import.

Note:

The Password Expiration in Days value doesn't apply to passwords for Customer Center users.

For more information, see NetSuite Password Requirements.

Default Role for New Customers

Select the default role assigned to customers who get NetSuite access.

This role displays on the Access subtab when you edit customer records.

User Registration Link Expiration In Hours

Number of hours before the URL for new user access expires. The default is 24 hours, and you can set it from one (1) hour to 72 hours.

The default value, 24 hours, is hard-coded in the in the following standard user access email templates:

  • Customer Center Access Email

  • Partner Center Access Email

  • Vendor Center Access Email

  • User Access Email

If you change the default value in General Preferences, be sure to update the value in the user access email templates.

Idle Session Timeout In Minutes

Number of minutes that a NetSuite user's browser session can be idle before it locks. The default is 180 minutes (3 hours).

You can set this from 15 minutes to 720 minutes (12 hours).

Customer Center Login Page

If you have a custom login page for users with Customer Center roles, select the HTML file for the page here.

For more information, see Creating Custom Pages for Login to Your NetSuite Account.

Show Help Link in Customer Center

Clear this box to hide the online help link from Customer Center users.

By default, this box is checked and the help link is visible. This preference doesn't affect any other centers.

Web Site Duplicate Email Management

Choose if you want to enable website duplicate email detection.

Website Duplicate Email Detection prevents web store shoppers from creating duplicate customer accounts on your website. For details, see Detect Duplicate Customer Email.

Related Topics

General Notices