I would like to see an option for passwords to expire if a new user (who has a temporary password) has not changed their password in x days. I am thinking there needs to be a text field for the number of days.

If this is already possible, please let me know. I may have missed it.

Thanks!

Comments

erikwebb’s picture

Just to be clear, once they pass this first threshold they would then be subject to the normal time limits?

shrop’s picture

Yes, that sounds right. This would just a be an expiration for new users. If the user changes their temp password before the expiration, they can continue on, but are subject to all other aspects of their assigned password policy.

erikwebb’s picture

How do you see this working differently for uses with a generated password versus those that pick their initial password? Should this apply to both or only to the generated ones?

shrop’s picture

Good questions Erik. My first thought is that if a user picks their initial password and it follows the rest of the policy, it shouldn't expire. With that said, if I as an admin user set a password for the user, that password should probably expire. For that scenario, I would have a requirement to have the user change their password at login. Between that and the expiration, it creates a nice policy.

Does that help?

erikwebb’s picture

aohrvetpv’s picture

Issue summary: View changes
Status: Active » Postponed (maintainer needs more info)