FAQ: Profile's Password Restrictions in Versions 9.0.6 and Above
20 min
faq quick links what will the changes include? docid\ tuzfd zhhc99weba4ufpowhy is intrahealth making these changes to profile? docid\ tuzfd zhhc99weba4ufpowhen will the new password restrictions go into effect? docid\ tuzfd zhhc99weba4ufpodoes this affect all regions? docid\ tuzfd zhhc99weba4ufpowill these changes affect us if we already had similar requirements in place using the old 'validate password macro'? docid\ tuzfd zhhc99weba4ufpowhat if the 'always uppercase' checkbox was ticked in older versions of profile? docid\ tuzfd zhhc99weba4ufpohow does this align with domain account functionality/active directory single sign on? will profile requirements 'trump' the local ad security rules? docid\ tuzfd zhhc99weba4ufpohow will we know if our old password meets the new criteria? docid\ tuzfd zhhc99weba4ufpohow do we change/update our passwords to fit the new requirements? docid\ tuzfd zhhc99weba4ufpohow can i keep track of my password and login information? docid\ tuzfd zhhc99weba4ufpohow will it look if a system administrator tries to reset a password on someone's behalf and it does not fit the new password criteria? docid\ tuzfd zhhc99weba4ufpoare there ways to customise the password requirement preferences? docid\ tuzfd zhhc99weba4ufpowhat enhancements have been made to the password reuse interval? docid\ tuzfd zhhc99weba4ufpogoing forward, will our passwords expire after a given amount of time by default? docid\ tuzfd zhhc99weba4ufpocan we disable these rules? docid\ tuzfd zhhc99weba4ufpolearn more docid\ tuzfd zhhc99weba4ufpo frequently asked questions what will the changes include? the changes will include user/provider password complexity will be added and the following criteria will be enforced minimum 10 characters at least one uppercase letter at least one lowercase letter at least one number at least one special character note when updating your password, any of the following non alphanumeric characters can be used to meet the ' at lease one special character' criteria ` !@#$%^& () =+\[]{}; ’”, <>/? a new preference allowing customers to set a higher (but not lower) minimum number of characters a new and intuitive user interface to help guide users through password creation you'll see real time indicators, such as red x's for unmet rules and green checkmarks for fulfilled criteria, ensuring that your passwords meet our requirements effortlessly the validate password macro that was used to configure password complexity and expiry will no longer be supported by profile the removal of the 'always uppercase' checkbox an enhanced password reuse interval functionality why is intrahealth making these changes to profile? the rationale and benefits for these change are that they ensuring profile's adherence to nist standard password composition guidelines https //blog netwrix com/nist password guidelines enable direct configuration and flexibility within profile, streamlining password restrictions setup and management for organisations allow for alignment with password restrictions and guidelines when will the new password restrictions go into effect? the new password restrictions go into effect upon upgrade to profile version 9 0 6 and above, as soon as the user tries to log on does this affect all regions? yes these changes are mandatory for all will these changes affect us if we already had similar requirements in place using the old 'validate password macro'? if a user's current password meets the new password criteria, then they will not be prompted to change their password what if the 'always uppercase' checkbox was ticked in older versions of profile? if the old 'always uppercase' checkbox was ticked in older versions of profile, then users will need to reset their passwords, as they will not meet the 'at least one lowercase letter' criteria how does this align with domain account functionality/active directory single sign on? will profile requirements 'trump' the local ad security rules? no the password requirement changes apply only to the profile user passwords any integration with an external identity service which replaces the profile user password will trump the password rules profile settings would not apply how will we know if our old password meets the new criteria? as soon as a user upgrades to the applicable version, upon log on, the system will check if the user's current password meets the minimum criteria if their current password meets the new criteria, then the user will not be required to enter a new password if their current password does not meet the new criteria, then the user will be required to reset their password to fit the new requirements and the following window will appear once they click ok, they will be taken through the process of choosing a new password how do we change/update our passwords to fit the new requirements? intrahealth has developed a new user interface that will guide users with their password creation it will show users which requirements they have fulfilled in real time the ok button will become enabled so the user will know when their password fits all of the requirements read how to update your password to fit profile's password restrictions in versions 9 0 6 and above docid\ eplfxs8nzjm79z1pc1zul for a step by step guide on this process how can i keep track of my password and login information? we recommend using a digital password manager to securely store your login information there are several reliable options available the choice of whether to use a password manager, and which one to select, is determined by your clinic or organization how will it look if a system administrator tries to reset a password on someone's behalf and it does not fit the new password criteria? when an administrator tries to reset someone else's password (in their people and places record, special view), it will will not let them reset it to a password that does not meet the new criteria if this occurs, an error, like the one below will appear are there ways to customise the password requirement preferences? yes read our article on preferences for profile's password restrictions in versions 9 0 6 and above docid\ khgtyokjvccjfohbctmxe for more details what enhancements have been made to the password reuse interval? the password reuse interval preference still places limitations to prevent the reuse of specific passwords from a certain number of days now, organisations also have the option to prohibit users from repeating the last set number of passwords read the article on preferences for profile's password restrictions in versions 9 0 6 and above docid\ khgtyokjvccjfohbctmxe for more information it is important to note that these changes will be up to your organisation to implement going forward, will our passwords expire after a given amount of time by default? no we want to ensure that your password management experience remains seamless as such, we will not be enforcing password expiry by default for customers who were not previously using this feature however, if you were using a macro to set password expiry, you will need to enable the built in feature to continue this behaviour read the article on preferences for profile's password restrictions in versions 9 0 6 and above docid\ khgtyokjvccjfohbctmxe for more information can we disable these rules? no there will be no option to disable the password rules disabling these rules could weaken the overall security of the system and increase the risk of unauthorised access or breaches learn more click on the following links to read more about the new password restrictions in profile how to update your password to fit profile's password restrictions in versions 9 0 6 and above docid\ eplfxs8nzjm79z1pc1zulpreferences for profile's password restrictions in versions 9 0 6 and above docid\ khgtyokjvccjfohbctmxeprofile's password restrictions in version 9 0 6 and above docid\ pvcnulldwqg22yetri1a5