Preferences for Profile's Password Restrictions in Versions 9.0.6 and Above
9 min
overview & requirements this article covers profile's password restrictions applied from version 9 0 6 it looks specifically at the preferences associated with this feature, and their functionality note it is crucial for organisations to be aware of the changes introduced to password restrictions and validations in the 9 0 6 release, especially if they had a pre existing macro enforcing tailored rules with 9 0 6, this macro is no longer supported requirements profile version 9 06 preferences for the password restrictions in profile password requirements and restrictions in order to ensure the safety and integrity of your data, intrahealth has implemented some password requirements in profile versions 9 0 6 and above see profile's password restrictions in versions 9 0 6 and above docid\ pvcnulldwqg22yetri1a5 for more information on the rationale and benefits around having password requirements profile now requires user/provider password complexity, namely minimum 10 characters at least one uppercase letter at least one lowercase letter at least one number at least one special character note when updating your password, any of the following non alphanumeric characters can be used to meet the ' at lease one special character' criteria ` !@#$%^& () =+\[]{}; ’”, <>/? preferences in the password field organisations can adjust certain preferences around user passwords restrictions in organisation / preferences / technical / security (global) / security tab / password field note the exclude users button (available from profile 9 0 9) allows the administrator to exclude designated users from the password expiration preference note the use validate password macro checkbox, the validate password macro button, and the always uppercase checkbox (from earlier versions of profile pre version 9 0 6), shown in the image below, have all been removed any organiation that previously had the always uppercase checkbox ticked, will need to have their users update their passwords, as one of the criteria for password complexity in profile is to have at least one lowercase letter likewise, as mentioned above, it is crucial for organisations to be aware of the changes introduced to password restrictions and validations in the 9 0 6 release, especially if they had a pre existing macro enforcing tailored rules with 9 0 6 this macro is no longer supported minimum character length the password must contain min chars functionality allows an organisation to alter the minimum character length requirements of their users' passwords this preference gives an organisation the opportunity to increase the minimum character length up to '63' characters, if desired however, the length cannot be less than the default length of '10' characters if a value is entered below '10' an error message like the one below appears note the minimum character length is the only preference included in the password complexity criteria that can be altered all other criteria such as "at least one uppercase letter", "at least one lowercase letter", "at least one number", "at least one special character", cannot be adjusted password expiry the password expires after days field allows an organisation to specify if and when a user's password expires by clicking the password expires after checkbox, the days box becomes enabled, and a set number of days can be entered this number of days determines how long users have until they need to update their password next note this field is unchecked by default this was done in order to make for a seamless password management experience upon upgrade for those who were not previously using this feature however, if you were using a macro to set password expiry, you will need to enable the built in feature to continue this behaviour password reuse the password reuse interval feature allows an organisation to prohibit users from repeating the last set number of passwords when the password reuse interval checkbox is ticked, the day and the or/and times boxes are enabled if a clinic wishes to set a barrier of time between when a user can reuse the same password, the number of days can be entered into the days box if a clinic wishes to limit the amount of times a user can reuse the same password upon update, this can be entered into the times box warnings the start warning feature enables organisations to notify their users when it is time to renew their passwords this provides users with advance notice that they will soon need to update their passwords learn more for more information on profile's password restrictionsplease click on the article links below faq profile's password restrictions in versions 9 0 6 and above docid\ tuzfd zhhc99weba4ufpoprofile's password restrictions in versions 9 0 6 and above docid\ pvcnulldwqg22yetri1a5how to update your password to fit profile's password restriction criteria in versions 9 0 6 and above docid\ eplfxs8nzjm79z1pc1zul