Hi,
I would like to suggest an enhancement to eSupport, we need Password Policy enforcement within the app, both on the Staff side and the Client side. With the application exposed on the internet (like I would imagine most are), there is risk that should be mitigated within the application, so as to avoid a security breach (hacking etc.) and in some cases, comply with regulations governing the protection of clients data.
Below are the features I believe should be available at minimum, and should be selectable (ie. you can turn an individual option on/off as your security policies require)
Password composition complexity - Upper case
- Lower case
- Numeric
- Special characters
Password Length- Minimum password length
- Maximum password length
Prohibited names/words - This would require an input box where you could add/remove names/words
Password history (changes required before duplicate) - Number of password(s) remembered
Password Aging- Maximum password age
- Number of day(s)
- Interval before the Password Age expiration date
- Maximum consecutive failures before lockout
Thanks,
Rich