---
title: Preferences for Profile's Password Restrictions in Versions 9.0.6 and Above
slug: portal-sub/preferences-for-profiles-password-restrictions-in-versions-906-and-above
docTags: 
createdAt: 2026-03-04T12:03:15.262Z
---

# Overview & Requirements

This article covers Profile's password restrictions applied from version 9.0.6. It looks specifically at the Preferences associated with this feature, and their functionality. 

**Note:&#xA0;**&#x49;t is crucial for organisations to be aware of the changes introduced to password restrictions and validations in the 9.0.6 release, especially if they had a pre-existing macro enforcing tailored rules. With 9.0.6, this macro is no longer supported.

## Requirements

- Profile Version 9.06

# Preferences for the Password Restrictions in Profile

## Password Requirements and Restrictions

In order to ensure the safety and integrity of your data, Intrahealth has implemented some password requirements in Profile versions 9.0.6 and above. See [Profile's Password Restrictions in Versions 9.0.6 and Above](docId\:pvCnullDWQG22YETrI1A5) for more information on the rationale and benefits around having password requirements.

Profile now requires user/provider password complexity, namely:

- Minimum 10 characters
- At least one uppercase letter
- At least one lowercase letter
- At least one number
- At least one special character

:::hint{type="info"}
**Note:&#xA0;**&#x57;hen updating your password, any of the following non-alphanumeric characters can be used to meet the '**At lease one special character'&#xA0;**&#x63;riteria:
\`\~!@#$%^&\*()-\_=+\[]\{};:’”,.\<>/?

:::

## Preferences in the Password Field

Organisations can adjust certain preferences around user passwords restrictions in **Organisation / Preferences / Technical / Security (Global) / Security&#xA0;**&#x74;ab **/ Password** field

![](https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/V6v9gjBnJ3Cn37YY_VnKS_e9pxfuixjgoufq1mlo2b5ckuv-4d621q.png)

:::hint{type="info"}
**Note:&#xA0;**&#x54;he **Exclude users** button (available from Profile 9.0.9) allows the Administrator to exclude designated users from the password expiration preference.

:::

:::hint{type="info"}
**Note:&#x20;**&#x54;he **Use validate password macro** checkbox, the **Validate password macro** button, and the **Always uppercase&#xA0;**&#x63;heckbox (from earlier versions of Profile - pre version 9.0.6), shown in the image below, have all been removed.
![](https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/wC0UhodhPO8dWXd8Fyj7P_qtyhgw7ydqt5jsprfhm6efmzpupcftd9vg.png)
Any organiation that previously had the **Always uppercase&#xA0;**&#x63;heckbox ticked, will need to have their users update their passwords, as one of the criteria for password complexity in Profile is to have at least one lowercase letter.
Likewise, as mentioned above, it is crucial for organisations to be aware of the changes introduced to password restrictions and validations in the 9.0.6 release, especially if they had a pre-existing macro enforcing tailored rules. With 9.0.6 this macro is no longer supported.

:::

### Minimum Character Length

Th&#x65;**&#xA0;Password must contain min\_\_ chars&#xA0;**&#x66;unctionality allows an organisation to alter the minimum character length requirements of their users' passwords. This preference gives an organisation the opportunity to increase the minimum character length up to '63' characters, if desired. However, the length cannot be less than the default length of '10' characters. If a value is entered below '10' an error message like the one below appears.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/2NVqQ0DHf9Fy34OxwFAud_egonsxidq0zxrjw0dj8vbtvqzazrlpvkxa.png" size="57" isUploading="false" initialPath="assets/EgONsxIDq0zxrJw0DJ8VBTvQZAZrLpvKXA.png" githubPath="en/General Settings and Configuration/Authentication/assets/EgONsxIDq0zxrJw0DJ8VBTvQZAZrLpvKXA.png" position="flex-start" showCaption="false"}

:::hint{type="info"}
**Note:&#xA0;**&#x54;he minimum character length is the only preference included in the password complexity criteria that can be altered. All other criteria such as "At least one uppercase letter", "At least one lowercase letter", "At least one number", "At least one special character", cannot be adjusted.

:::

### Password Expiry 

The **Password expires after \_\_ days** field allows an organisation to specify if and when a user's password expires. By clicking the **Password expires after** checkbox, the **days** box becomes enabled, and a set number of days can be entered. This number of days determines how long users have until they need to update their password next.

:::hint{type="info"}
**Note:&#xA0;**&#x54;his field is unchecked by default. This was done in order to make for a seamless password management experience upon upgrade for those who were not previously using this feature. However, if you were using a macro to set password expiry, you will need to enable the built in feature to continue this behaviour.

:::

### Password Reuse

The **Password reuse interval** feature allows an organisation to prohibit users from repeating the last set number of passwords. When the **Password reuse interval&#xA0;**&#x63;heckbox is ticked, the **day&#xA0;**&#x61;nd the **or/and\_\_\_times&#xA0;**&#x62;oxes are enabled. If a clinic wishes to set a barrier of time between when a user can reuse the same password, the number of days can be entered into the **days&#xA0;**&#x62;ox. If a clinic wishes to limit the amount of times a user can reuse the same password upon update, this can be entered into the **times&#xA0;**&#x62;ox.

### Warnings

The **Start warning&#xA0;**&#x66;eature enables organisations to notify their users when it is time to renew their passwords. This provides users with advance notice that they will soon need to update their passwords. 

# Learn More

For more information on Profile's Password Restrictionsplease click on the article links below:

- [FAQ: Profile's Password Restrictions in Versions 9.0.6 and Above](docId\:TUzFd_ZHHC99weba4uFPO)
- [Profile's Password Restrictions in Versions 9.0.6 and Above](docId\:pvCnullDWQG22YETrI1A5)
- [How to Update your Password to Fit Profile's Password Restriction Criteria in Versions 9.0.6 and Above](docId\:EpLFxS8nZjM79Z1PC1Zul)
