According to the new NIST guidelines for password security, they recommend never changing your password unless you forget the password or you believe it has been phished.
Going off of this, I would like to set this up for my users. We currently have a 90 day password policy expiration. I would like to implement the new policy (which includes other password requirements) WITHOUT affecting the current 90 day expiration. Basically I want to apply the new Password Policy for new passwords, and have everyone's current passwords following the existing policy now. Their current passwords should continue to work and the 90 day expiration should still be in place. When 90 days is up, the user is forced to change their password and the new password will be based off of the new password policies with no expiration date.
I believe it is possible to change the password requirements without affecting existing passwords (only applying to new passwords) but I am not sure what the consequences are for changing the time to expire. Existing passwords used by users should absolutely not apply to his policy and they should be expected to change their password at some point to the new policy.
Is this possible? Thanks!
1 个回答
Hi Jordan,
Take a look into this site - https://help.salesforce.com/articleView?id=000229780&type=1
--
Thanks,
Prashant