---
title: FAQ: Profile's Password Restrictions in Versions 9.0.6 and Above
slug: portal-sub/faq-profiles-password-restrictions-in-versions-906-and-above
docTags: 
createdAt: 2026-03-04T12:03:15.231Z
---

# FAQ: Quick Links

- [What will the changes include?](docId\:TUzFd_ZHHC99weba4uFPO)
- [Why is Intrahealth making these changes to Profile?](docId\:TUzFd_ZHHC99weba4uFPO)
- [When will the new Password Restrictions go into effect?](docId\:TUzFd_ZHHC99weba4uFPO)
- [Does this affect all regions?](docId\:TUzFd_ZHHC99weba4uFPO)
- [Will these changes affect us if we already had similar requirements in place using the old 'Validate Password Macro'?](docId\:TUzFd_ZHHC99weba4uFPO)
- [What if the 'Always uppercase' checkbox was ticked in older versions of Profile?](docId\:TUzFd_ZHHC99weba4uFPO)
- [How does this align with Domain Account Functionality/Active Directory single sign on? Will Profile requirements 'trump' the local AD security rules?](docId\:TUzFd_ZHHC99weba4uFPO)
- [How will we know if our old password meets the new criteria?](docId\:TUzFd_ZHHC99weba4uFPO)
- [How do we change/update our passwords to fit the new requirements?](docId\:TUzFd_ZHHC99weba4uFPO)
- [How can I keep track of my password and login information?](docId\:TUzFd_ZHHC99weba4uFPO)
- [How will it look if a System Administrator tries to reset a password on someone's behalf and it does not fit the new password criteria?](docId\:TUzFd_ZHHC99weba4uFPO)
- [Are there ways to customise the password requirement preferences?](docId\:TUzFd_ZHHC99weba4uFPO)
- [What enhancements have been made to the Password reuse interval?](docId\:TUzFd_ZHHC99weba4uFPO)
- [Going forward, will our passwords expire after a given amount of time by default?](docId\:TUzFd_ZHHC99weba4uFPO)
- [Can we disable these rules?](docId\:TUzFd_ZHHC99weba4uFPO)
- [Learn More](docId\:TUzFd_ZHHC99weba4uFPO)

# Frequently Asked Questions

## What will the changes include?

The changes will include:

- User/Provider Password complexity will be added and the following criteria will be enforced:
  - Minimum 10 characters
  - At least one uppercase letter
  - At least one lowercase letter
  - At least one number
  - At least one special character

:::hint{type="info"}
**Note:&#xA0;**&#x57;hen updating your password, any of the following non-alphanumeric characters can be used to meet the '**At lease one special character'&#xA0;**&#x63;riteria:
\`\~!@#$%^&\*()-\_=+\[]\{};:’”,.\<>/?

:::

- A new preference allowing customers to set a higher (but not lower) minimum number of characters.
- A new and intuitive user interface to help guide users through password creation. You'll see real-time indicators, such as red X's for unmet rules and green checkmarks for fulfilled criteria, ensuring that your passwords meet our requirements effortlessly.
- The Validate Password Macro that was used to configure password complexity and expiry will no longer be supported by Profile. 
- The removal of the 'Always uppercase' checkbox.
- An enhanced Password reuse interval functionality.

***

## Why is Intrahealth making these changes to Profile?

The rationale and benefits for these change are that they:

- Ensuring Profile's adherence to [NIST standard password composition guidelines](https://blog.netwrix.com/nist-password-guidelines).
- Enable direct configuration and flexibility within Profile, streamlining password restrictions setup and management for organisations.
- Allow for alignment with password restrictions and guidelines. 

***

## When will the new Password Restrictions go into effect?

The new Password Restrictions go into effect upon upgrade to Profile Version 9.0.6 and above, as soon as the user tries to log on. 

***

## Does this affect all regions?

Yes. These changes are mandatory for all. 

***

## Will these changes affect us if we already had similar requirements in place using the old 'Validate Password Macro'?

If a user's current password meets the new password criteria, then they will not be prompted to change their password.

***

## What if the 'Always uppercase' checkbox was ticked in older versions of Profile?

If the old 'Always uppercase' checkbox was ticked in older versions of Profile, then users will need to reset their passwords, as they will not meet the 'At least one lowercase letter' criteria.  

***

## How does this align with Domain Account Functionality/Active Directory single sign on? Will Profile requirements 'trump' the local AD security rules?

No. The password requirement changes apply only to the Profile user passwords. Any integration with an external identity service which replaces the Profile user password will trump the password rules. Profile settings would not apply. 

***

## How will we know if our old password meets the new criteria?

As soon as a user upgrades to the applicable version, upon log on, the system will check if the user's current password meets the minimum criteria. 

1. If their current password meets the new criteria, then the user will not be required to enter a new password
2. If their current password does not meet the new criteria, then the user will be required to reset their password to fit the new requirements and the following window will appear. Once they click OK, they will be taken through the process of choosing a new password. 

![](https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/7HxLZ3sXB9hHlVAcIr7a9_udyd9onlajct9hzkzplinxhfv-wymlcw.png)

***

## How do we change/update our passwords to fit the new requirements?

Intrahealth has developed a new user interface that will guide users with their password creation. It will show users which requirements they have fulfilled in real-time. The **OK** button will become enabled so the user will know when their password fits all of the requirements. Read [How to Update your Password to Fit Profile's Password Restrictions in Versions 9.0.6 and Above](docId\:EpLFxS8nZjM79Z1PC1Zul) for a step-by-step guide on this process. 

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/JsJY2Uzu_Kt00aCHoDn_t_7x-gyre44bwtwootrk-p72ojws21lzykq.png" size="71" isUploading="false" initialPath="assets/7x-gyrE44bwtwooTrk-P72OjwS21_LZYKQ.png" githubPath="en/General Settings and Configuration/Authentication/assets/7x-gyrE44bwtwooTrk-P72OjwS21_LZYKQ.png" position="flex-start" showCaption="false"}

***

## How can I keep track of my password and login information?

We recommend using a digital password manager to securely store your login information. There are several reliable options available. The choice of whether to use a password manager, and which one to select, is determined by your clinic or organization.

***

## How will it look if a System Administrator tries to reset a password on someone's behalf and it does not fit the new password criteria?

When an Administrator tries to reset someone else's password (in their People and Places record, Special view), it will will not let them reset it to a password that does not meet the new criteria. If this occurs, an error, like the one below will appear.

![](https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/-dB3GxMqseER2eqjJo0iA_oe8yseulpysnlw8ixfiacgmunz8pxb7zgg.png)

***

## Are there ways to customise the password requirement preferences?

Yes. Read our article on [Preferences for Profile's Password Restrictions in Versions 9.0.6 and Above](docId\:KhGTyOkJvcCJfOhBCtmxe) for more details. 

***

## What enhancements have been made to the Password reuse interval?

The Password reuse interval preference still places limitations to prevent the reuse of specific passwords from a certain number of days. Now, organisations also have the option to prohibit users from repeating the last set number of passwords. Read the article on [Preferences for Profile's Password Restrictions in Versions 9.0.6 and Above](docId\:KhGTyOkJvcCJfOhBCtmxe) for more information.  It is important to note that these changes will be up to your organisation to implement. 

***

## Going forward, will our passwords expire after a given amount of time by default?

No.  We want to ensure that your password management experience remains seamless. As such, we will not be enforcing password expiry by default for customers who were not previously using this feature. However, if you were using a macro to set password expiry, you will need to enable the built-in feature to continue this behaviour. Read the article on [Preferences for Profile's Password Restrictions in Versions 9.0.6 and Above. ](docId\:KhGTyOkJvcCJfOhBCtmxe) for more information. 

***

## Can we disable these rules?

No. There will be no option to disable the password rules. Disabling these rules could weaken the overall security of the system and increase the risk of unauthorised access or breaches. 

# Learn More

Click on the following links to read more about the new Password Restrictions in Profile. 

- [How to Update your Password to Fit Profile's Password Restrictions in Versions 9.0.6 and Above](docId\:EpLFxS8nZjM79Z1PC1Zul)
- [Preferences for Profile's Password Restrictions in Versions 9.0.6 and Above](docId\:KhGTyOkJvcCJfOhBCtmxe)
- [Profile's Password Restrictions in Version 9.0.6 and Above](docId\:pvCnullDWQG22YETrI1A5)
