Global password policy reference

Every field on the Global password policy screen — password rules, expiry and reuse, auto logout and lockout, self-registration — what each one does and when it is worth changing.

Updated 17 Aug 2026

One screen, four sections, all of it tenant-wide — there is no per-building or per-group version of these rules. Everything here governs Offision passwords; a Microsoft 365, Google, LDAP or Active Directory sign-in is not subject to any of it. See How sign-in security works for why.

Global password policy

What a password has to look like. These are checked whenever a password is set — by the person, by an administrator, or through self-registration.

The character rules. Every password Offision stores has to pass all of them.

The character rules. Every password Offision stores has to pass all of them.

SettingWhat it doesWhen to change it
Minimum number of charactersThe shortest password Offision will store. Between 6 and 30Length beats complexity for real security. 12 is a better default than 8 if your people will accept it
Require lowercase charactersThe password must contain at least one a–zLeave on. Turning it off buys nothing
Require uppercase charactersThe password must contain at least one A–ZLeave on
Require numeric charactersThe password must contain at least one 0–9Leave on
Require special charactersThe password must contain one of #?!@$%^&*-()[]{}_,.:;><+|~'"Turn on where a security policy demands it. It is the rule people most often work around with a trailing !, so raising the minimum length usually does more good

Password change policy

How long a password lasts, and whether an old one can come back.

SettingWhat it doesWhen to change it
Require user to set a new passwordTurns on expiry. Off, a password lasts indefinitelyModern guidance is against routine expiry — it pushes people towards predictable variations. Turn it on when an external policy requires it, not by default
Require a new password everyThe number of months, 1 to 12. On the first sign-in past that age the person is sent to the change-password screen and cannot go anywhere else until they finish3 months is aggressive; 12 is the gentler choice if you must have expiry at all
Prevent users from reusing previous passwordsRemembers past passwords and refuses a repeatTurn on alongside expiry. Without it, expiry just makes people alternate between two passwords
Number of previous passwords to rememberHow many recent passwords are refused, 1 to 4The highest value is the useful one; a person who has to change every 3 months takes a year to cycle past four

Login setting

What happens to an idle session, and to someone typing the wrong password.

Auto logout and account lockout. Each one's numbers appear once its switch is on.

Auto logout and account lockout. Each one's numbers appear once its switch is on.

SettingWhat it doesWhen to change it
Enable user auto logoutSigns a person out after a period with no keyboard, mouse or touch activity. This one does apply to everyone, including single sign-on, because it runs in the app rather than at sign-inTurn on for shared or public machines. It is the only control here that shortens a session for everybody at once
Minutes of inactivity before logoutBetween 5 and 48015 for a reception or shared desk; anything under 10 becomes an irritation on a personal laptop
Enable account lockoutAfter too many wrong passwords, sign-in is refused for a while even with the right password. Applies to Offision passwords onlyTurn on. It is the single most useful setting on this screen for a tenant that uses passwords
Maximum failed login attemptsHow many wrong passwords trigger the lock, 1 to 20. A successful sign-in resets the count5 absorbs ordinary typing mistakes while still stopping a guessing attack
How long the account stays locked (minutes)The length of the lock, 1 to 1440. During it the person is told how many minutes remain. An administrator can clear it early from the person’s record30 is enough to defeat guessing without generating a support call

User self-registration

Whether strangers can create their own account. Off unless you turn it on.

Self-registration, with the domains allowed to use it.

Self-registration, with the domains allowed to use it.

SettingWhat it doesWhen to change it
Allow users to register themselvesAdds a Create account link to the sign-in page, so someone can sign up with their own email rather than waiting to be invitedTurn on for a site where you cannot practically invite everybody in advance. Set the allowed domains at the same time
Approval modeHow a new registration becomes usable. Auto-activate after email verification — they confirm their address and are inThe only mode the screen offers
Allowed email domains (optional)A comma-separated list, for example acme.com, partners.com. Only addresses ending in one of them may register. Blank allows any addressNever leave this blank with self-registration on: an open form on a public sign-in page will be found

What this screen does not control

  • Two-factor authentication is set on User security profiles, not here.
  • Where a person may sign in from — desktop browser, mobile, the mobile app, the Outlook and Teams add-in — and IP restrictions are also per security profile.
  • Ending a session that is already running. None of these settings sign anyone out; changing them governs the next sign-in. Signing a device out is on the person’s Login devices page.
  • How SSO users get in. Lockout, expiry, reuse and the character rules never reach a Microsoft 365, Google, LDAP or Active Directory sign-in. Set those rules in that provider’s console.
  • What someone can do once inside. That is permissions and user groups.
Open Global password policy