| Audience: DocuShare administrators |
Configure DocuShare Account and Password Policies
Overview
The Account Policies page controls password and account settings for internal DocuShare-managed accounts, including password expiration, password content rules, first-login changes, changes after an administrator reset, and failed-login lockout.
External authentication: DocuShare does not enforce its local password expiration or forced-change policy for accounts authenticating through an external directory such as LDAP or Active Directory, or through the SAML sign-in flow. The external directory or identity provider controls those users' password and sign-in policies. On a site with both internal and external accounts, the DocuShare settings apply to internal accounts only.
Before You Begin
- Sign in with an account authorized to change site settings.
- Identify which users have internal DocuShare-managed accounts and which authenticate through LDAP, Active Directory, or SAML.
- Check your organization's password and account-security requirements before changing values.
Open Account Policies
1. Open Admin Home > Site Management > Account Policies.
2. Review the current settings before changing them.
3. Change only the policies approved for your site, then apply the changes.
Configure Password Expiration and Change Requirements
- All passwords expire within specified days after creation: Set the validity period in days when periodic expiration is required. The setting assigns an expiration date when a new account is created. Changing the interval does not recalculate expiration dates already assigned to existing accounts.
- Password change at first login: Requires newly created accounts to change the password when they first sign in.
- Password change after reset by administrator: Requires a user to change the password after an administrator resets it. This setting depends on password aging being enabled.
When an administrator resets another user's DocuShare-managed password with the reset option enabled, DocuShare marks the password as expired so the user must choose a new password at the next login. The user should receive the temporary password through an approved secure method; never ask the user to return the replacement password.
What Happens to Existing Accounts When the Interval Changes?
Changing the site-wide expiration interval does not immediately change the expiration date already stored for an existing account. The user keeps that date until the password is changed or reset, or an administrator separately updates the account's expiration through a supported account-management workflow. When a password change or reset assigns a new expiration, DocuShare uses the current password-aging policy. If Password change after reset by administrator is enabled, an administrator reset can instead require the user to change the password at the next login.
Configure Password Content Rules
Use the Password Content Rules section to define requirements such as minimum length, letters, numbers, mixed case, punctuation, avoiding the user's name, and preventing password reuse. Choose requirements that satisfy your organization's policy while remaining supportable for users.
Failed Login Policy
The failed-login lockout policy on Account Policies applies to internal DocuShare accounts. If users authenticate through LDAP, Active Directory, SAML, or another identity provider, that provider may enforce separate password and lockout rules. Coordinate changes with the identity-system administrator.
Verify a Policy Change
Test changes with a non-administrator internal account. Confirm the expected password prompt and lockout behavior before communicating the change to users. Do not use the system admin or Guest account for testing; these accounts have special restrictions.
Troubleshooting
- If a user is not prompted after an administrator reset, confirm password aging is enabled, the reset was performed on the intended account, and the account uses DocuShare-managed authentication.
- If a password is rejected, compare it with the configured content rules and the user's previous password history.
- If an external-directory user is unaffected, review the password policy at the identity provider.