Password Policies
Configure password strength, length, character rules, and reuse protection for Edmissa users.
Password Policies control the password requirements users must meet when they join Edmissa, reset a password, or change an existing password.
Use this page when your agency wants to keep the system default policy or set a custom policy for the workspace.
What this guide helps you configure
| Area | What it controls |
|---|---|
| Policy source | Whether Edmissa uses the system default policy or a custom workspace policy. |
| Basic requirements | Password strength score, minimum length, optional maximum length, and required character types. |
| Security rules | Checks that block weak, repeated, personal, or recently used passwords. |
| Password testing | A safe way to test a sample password against the current policy before saving. |
Open Password Policies
Use this path when you want to manage password rules:
- Open Settings.
- Open Team Management.
- Select Password Policies.
- Confirm the page title is Password Policies.
The direct route is /t/settings/password-policies.
The page subtitle is Configure password requirements for your organization. You need access to security settings to open and save this page.
Choose the policy source
The first card is Password Policy Override. It includes the Enable Custom Password Policy switch.
| Switch state | What it means |
|---|---|
| Off | Edmissa uses the system default password requirements. The page shows System Default as the current policy source. |
| On | Edmissa uses the custom requirements you set on this page. The page shows Custom Organization Policy as the current policy source. |
When the switch is off, the policy controls are shown as disabled. Turn on Enable Custom Password Policy before changing requirements.
Review the system default
If you do not turn on a custom policy, Edmissa uses the system default requirements.
The current default policy is:
| Setting | Default |
|---|---|
| Minimum Password Strength Score | 3/5, shown as Fair |
| Minimum Length | 8 characters |
| Maximum Length | 128 characters |
| Character Type Requirements | Uppercase letters, lowercase letters, numbers, and symbols |
| Block Common Passwords | On |
| Block Personal Information | On |
| Block Sequential Characters | On |
| Block Repeated Characters | On |
| Prevent Password Reuse | On |
| Remember Last N Passwords | 5 |
This is a good first version for most agencies. Use a custom policy only when your internal security process requires different rules.
Configure Basic Requirements
Use Basic Requirements to set the minimum quality of a password.
| Setting | How to use it |
|---|---|
| Minimum Password Strength Score | Move the slider from 1 to 5. Higher scores require stronger passwords. The page labels scores from Very Weak through Very Strong. |
| Minimum Length | Set the fewest characters a password can have. The field accepts 4 to 50. |
| Maximum Length (Optional) | Set the longest allowed password. Leave it blank when you do not want a limit. The field accepts 8 to 128. |
| Uppercase Letters | Require at least one uppercase letter. |
| Lowercase Letters | Require at least one lowercase letter. |
| Numbers | Require at least one number. |
| Symbols | Require at least one symbol. |
For a first setup, keep the password long enough to be useful and easy enough for staff to remember safely. A stronger score is useful for admins and users with broad access, but avoid a rule that creates constant support requests.
Configure Security Rules
Use Security Rules to block patterns that make passwords easier to guess.
| Setting | What it blocks |
|---|---|
| Block Common Passwords | Common choices such as password123. |
| Block Personal Information | Names, email addresses, and similar personal details. |
| Block Sequential Characters | Patterns such as 123 or abc. |
| Block Repeated Characters | Patterns such as aaa or 111. |
| Prevent Password Reuse | Recently used passwords. |
| Remember Last N Passwords | The number of previous passwords Edmissa checks when reuse prevention is on. |
For study abroad teams, these rules help protect student profiles, applications, documents, and user access settings.
Test Password Requirements
Use Test Password Requirements before saving a custom policy.
- Enter a sample password in Test Password.
- Review whether Edmissa shows Password meets requirements or Password does not meet requirements.
- Read any validation messages.
- Review the Strength Score badge.
- Adjust the policy if normal users would have trouble creating a compliant password.
Do not use a real user's password in the test field. Use a safe sample that matches the kind of password you want users to create.
Save or reset the policy
Use the page actions in the header:
| Action | Use it when |
|---|---|
| Save Policy | You have enabled a custom policy and want to apply the current settings. |
| Reset to Defaults | You want to remove the custom policy and return to the system default. |
Both actions are available only when custom password policy is enabled. After a successful save, Edmissa confirms that the password policy was updated.
Recommended rollout
For a first Edmissa setup, keep the rollout simple:
- Start with the system default policy unless your agency already has a stricter password standard.
- If you need a custom policy, change one group of settings at a time.
- Test a few sample passwords before saving.
- Tell users before making the policy stricter.
- Confirm invitation, password reset, and normal sign-in still work as expected.
If users report sign-in trouble after a policy change, review the policy source, minimum length, strength score, and enabled security rules first.
Related guides
| Guide | Use it for |
|---|---|
| Security and audit | Understand how password rules fit with wider account protection. |
| Session Policy | Configure session timeout, warnings, and extra checks for sensitive actions. |
| Users | Invite users, reset passwords, and manage account status. |
| Roles | Control who can manage security settings. |
| Access and permissions troubleshooting | Diagnose missing pages, disabled actions, and access problems. |