SAP Knowledge Base Article - Public

2603553 - Password Policy

Symptom

What are the available options in Learning about the password policy?

Environment

SAP SuccessFactors Learning

Resolution

This configuration can be find by following: System Admin > Configuration > System Configuration > PASSWORD_POLICY

  • PASSWORD_POLICY

Note:  When password policies are enabled, ‘rule hint’ labels are displayed to users when resetting or establishing initial passwords. The rule hint labels by default correspond to the default password policy setting, therefore the corresponding rule hint label must be modified if the password policy deviates from the default. E.g., if Password Length Rule is enabled and min/max is set to 6/30, the corresponding rule hint label (instruction.passwordvalidation.PasswordLengthRuleHint) value should be modified to read appropriately.  Each active locale ID (Language Packs – if applicable) should be modified to display properly to users:

PASSWORD_POLICY:  Password Length Rule:
This setting determines the required length of the password.

 

Description

Value Options

Chosen Value

Enabled

TRUE, FALSE

 

Rule Type

ALL – Always applicable

CREATE - applicable only when a User account is being created

CHANGE - applicable only when password is changed

CREATE_AND_CHANGE - applicable when password is created or changed.

 

User Type

LEARNER, ADMINISTRATOR, ALL

 

Minimum Password Length

1

 

Maximum Password Length

40

 

 

PASSWORD_POLICY:  Required Characters Rule:

This setting determines the characters required to be within a password.

 

Description

Value Options

Chosen Value

Enabled

TRUE, FALSE

 

Rule Type

ALL – Always applicable

CREATE - applicable only when a User account is being created

CHANGE - applicable only when password is changed

CREATE_AND_CHANGE - applicable when password is created or changed.

 

User Type

LEARNER, ADMINISTRATOR, ALL

 

Required Characters

EnglishUpperCaseLetters ("A" - Z") EnglishLowerCaseLetters" (“a” – “z”) ArabicNumerals (“0”-“9”) NonAlphaNumericCharacters (!@#$%^&*()-_+={}[]<>?/'";:\|)

 

 

PASSWORD_POLICY:  Successive Character Repetition Rule:

The number of times a character can be repeated successively.

 

Description

Value Options

Chosen Value

Enabled

TRUE, FALSE

 

Rule Type

ALL – Always applicable

CREATE - applicable only when a User account is being created

CHANGE - applicable only when password is changed

CREATE_AND_CHANGE - applicable when password is created or changed.

 

User Type

LEARNER, ADMINISTRATOR, ALL

 

Max Repetition Count

2

 

 

PASSWORD_POLICY:  Un-Broken Login ID Rule:

Password cannot contain the User’s login id. Check can be case sensitive or case insensitive.

 

Description

Value Options

Chosen Value

Enabled

TRUE, FALSE

 

Rule Type

ALL – Always applicable

CREATE - applicable only when a User account is being created

CHANGE - applicable only when password is changed

CREATE_AND_CHANGE - applicable when password is created or changed.

 

User Type

LEARNER, ADMINISTRATOR, ALL

 

Case Sensitive

TRUE, FALSE

 

 

PASSWORD_POLICY:  First and Last Name Rule:

Password cannot contain User’s first name or last name or both together.

 

Description

Value Options

Chosen Value

Enabled

TRUE, FALSE

 

Rule Type

ALL – Always applicable

CREATE - applicable only when a User account is being created

CHANGE - applicable only when password is changed

CREATE_AND_CHANGE - applicable when password is created or changed.

 

User Type

LEARNER, ADMINISTRATOR, ALL

 

Check Type

The valid values for are:

1. FIRSTNAME_ONLY - implies the password cannot contain Users first name. It can contain Users lastname.

2. LASTNAME_ONLY - implies the password cannot contain Users lastname. It can contain Users firstname.

3. FIRSTNAME_OR_LASTNAME - implies the password cannot contain Users firstname or lastname

4. FIRST_NAME_AND_LAST_NAME- implies the password cannot contain Users firstname and lastname together. But it can contain either the firstname or the lastname but not both.

 

Case Sensitive

TRUE, FALSE

 

 

PASSWORD_POLICY:  Previous Passwords Rule:

Password cannot be same as specified number of previous passwords.

This check can be case sensitive or case insensitive.

 

Description

Value Options

Chosen Value

Enabled

TRUE, FALSE

 

Rule Type

ALL – Always applicable

CREATE - applicable only when a User account is being created

CHANGE - applicable only when password is changed

CREATE_AND_CHANGE - applicable when password is created or changed.

 

User Type

LEARNER, ADMINISTRATOR, ALL

 

Case Sensitive

TRUE, FALSE

 

# of previous passwords

1

 

 

 

PASSWORD_POLICY:  Sub-String from Last Password Rule:

Password cannot contain substring of last password.

This check can be case sensitive or case insensitive.

 

Description

Value Options

Chosen Value

Enabled

TRUE, FALSE

 

Rule Type

ALL – Always applicable

CREATE - applicable only when an User account is being created

CHANGE - applicable only when password is changed

CREATE_AND_CHANGE - applicable when password is created or changed.

 

User Type

LEARNER, ADMINISTRATOR, ALL

 

Length

Password cannot contain substring from last password containing same # of characters

 

Case Sensitive

TRUE, FALSE

 

 

PASSWORD_POLICY:  Minimum Time Between Password Change Rule:

Password cannot be changed before the minimum time between password change has elapsed.

 

Description

Value Options

Chosen Value

Enabled

TRUE, FALSE

 

Rule Type

ALL – Always applicable

CREATE - applicable only when an User account is being created

CHANGE - applicable only when password is changed

CREATE_AND_CHANGE - applicable when password is created or changed.

 

User Type

LEARNER, ADMINISTRATOR, ALL

 

Number of Days

90

 

 

PASSWORD_POLICY:  Password Same As Esig Rule:

Password cannot be same as the Users electronic signature (PIN).

 

Description

Value Options

Chosen Value

Enabled

TRUE, FALSE

 

Rule Type

ALL – Always applicable

CREATE - applicable only when an User account is being created

CHANGE - applicable only when password is changed

CREATE_AND_CHANGE - applicable when password is created or changed.

 

User Type

LEARNER, ADMINISTRATOR, ALL

 

Case Sensitive

TRUE, FALSE

 

See Also

2805834 - PIN Rules - LMS

2499908 - How to reset users PIN

2420220 - eSignature Notification received when PIN fails

2333583 - Enable Admins to Reset E-Signature Password

Keywords

password, policy, lms, login, rule, username, pin, user , KBA , LOD-SF-LMS , Learning Management System , LOD-SF-LMS-ADM , System Admin, Global Variables, References , How To

Product

SAP SuccessFactors Learning all versions