Password configuration for user security
An administrator can define the following formatting and entry requirements for passwords directly in the CIS application on the Security tab of the Configuration page.
- Password expiration (days)—Number of days before a user password expires and the user must change the password when logging on. The recommended setting is 30 days.
 - Minimum password length—Minimum number of characters a user password must contain. The default is 8 characters.
Note: Allowed characters in passwords are upper and lowercase letters, digits, underscore (_), pound sign (#), and dollar sign ($).
 - Minimum password complexity
- 0 - Minimum Length Only
 - 1 - Password includes a number, a special character OR mixed case
 - 2 - Password includes at least two of: a number, a special character, mixed case
 - 3 - Password includes a number, a special character AND mixed case (Default)
 
 - Failed logon limit—Number of consecutive failed login attempts allowed. The recommended setting is 3.
 - User Lockout Timeout (minutes)—The amount of time a user is locked out of an account after issuing too many incorrect passwords (surpasses the Failed logon limit).
 



