Password & Session Policies
Enforce password complexity, expiry, re-use prevention, and configurable session timeouts — with forced re-authentication for high-risk actions.
Password & Session Policies give your security team centralised control over the authentication hygiene standards applied to every platform user. Define minimum password complexity, enforce regular changes, prevent re-use of recent passwords, set session timeouts appropriate to each role's risk profile, and require fresh authentication before any high-stakes action — all from the admin panel, applied consistently across the entire user base.
Everything you need, nothing you don't
Password Complexity Rules
Enforce minimum length, uppercase, lowercase, number, and special character requirements — configurable per role so admin accounts have stricter requirements than basic teller accounts.
Password Expiry Intervals
Set a maximum password age per role. Users are notified 7 days before expiry and blocked at login on expiry until they change their password.
Password Re-Use Prevention
Prevent users from reusing any of their last N passwords — configurable from 5 to 24 previous passwords — eliminating password cycling as a security bypass.
Per-Role Session Timeouts
Set inactivity timeout durations per role — short timeouts for branch tellers who share terminals, longer for office-based analysts who work uninterrupted sessions.
Absolute Session Limits
Set a maximum session duration regardless of activity — ensuring a session opened at 9am cannot still be active at midnight, even if the user has been continuously active.
Failed Login Lockout
Automatically lock accounts after a configurable number of consecutive failed login attempts. Locked accounts require admin unlock or a self-service unlock via a verified email or SMS.
Re-Authentication for High-Risk Actions
Force users to re-enter their credentials (and 2FA if enrolled) before executing high-risk actions — bulk payments, write-off approvals, role assignments — regardless of active session state.
Bulk Policy Enforcement
Apply a new password policy to all users simultaneously — with a grace period during which users are notified to update their passwords before enforcement kicks in.
Built for your team
Set and maintain password and session standards that protect the platform against credential-based attacks — without managing them on a per-user basis.
Demonstrate that your organisation enforces password standards consistent with your information security policy and any applicable regulatory requirements.
Benefit from automatic account management — new starters prompted to set a compliant password, leavers' accounts automatically expiring without manual intervention.
Ready to activate Password & Session Policies?
Sign up free and configure Password & Session Policies in minutes — or book a demo and we'll walk you through it live.