ESET Online Help

Search English
Select the topic

Password policies

User Password Requirements

User can change password - If disabled, a password change is possible only when initiated by the administrator from the remote management console.

 

Password Characters

Policy setting

Supported on OS

Description

Must use lowercase letters

efde_policy_win

Password must contain at least one lowercase character (a-z).

Must use uppercase letters

efde_policy_win

Password must contain at least one uppercase character (A-Z).

Must use numbers

efde_policy_win

Password must contain at least one numeric character (0-9).

Must use symbols

efde_policy_win

Password must contain at least one special character (!@#$%).

Minimum password length

efde_policy_win

Defines the minimum required length of the password (1-127 characters).

 

Password Retries

Policy setting

Supported on OS

Description

Limit incorrect password attempts

efde_policy_win

When disabled, incorrect password attempts are unlimited. It is not recommended to disable this setting for a long period due to security risk.

Maximum incorrect password attempts

efde_policy_win

The maximum value is 254. Maximum consecutive incorrect password attempts before the account is locked and a recovery password is required to set up a new password.

 

Password Expiry

Policy setting

Supported on OS

Description

Password expires

efde_policy_win

When disabled, the user password does not have an expiration period.

Maximum password age (days)

efde_policy_win

A value between 1 and 999 days. The recommended range is between 30 and 90.

Warn user when password is due to expire

efde_policy_win

When disabled, the user is not warned by the product that their password is about to expire.

Warn when period less than (days)

efde_policy_win

A value between 1 and 999 days. Specify how many days before the password expiration is user warned.

 

Recovery Password Options

Password Retries

Policy setting

Supported on OS

Description

Limit incorrect password attempts

efde_policy_win

When disabled, there is no limit on incorrect recovery password attempts. It is not recommended to disable this setting for a long period of time due to security risk.

Maximum incorrect password attempts

efde_policy_win

The maximum value is 254. Maximum consecutive incorrect password attempts before the account is locked and a recovery password is required to set up a new password.

 

Recovery Password Uses


important

All settings in this section are not enabled by default. Ensure you enable them manually.

All settings in this section are applied and take effect after the computer is decrypted and then encrypted again.

Policy setting

Supported on OS

Description

Limit use of Recovery Password

efde_policy_win

When disabled, the same recovery password can be used repeatedly, until a new one is generated.

Maximum uses

efde_policy_win

The maximum value is 254.

Warn user when recovery password limit is near

efde_policy_win

When enabled, the user will be warned when the recovery password is near its expiration.

Warn with uses remaining

efde_policy_win

The maximum value is 255.

Automatically generate new recovery password

efde_policy_win

When enabled, a new recovery password will be generated automatically after the set remaining password uses are reached.

Generate when (uses remains)

efde_policy_win

The maximum value is 255.