The security settings control user password rules, password security,
and log in lockout features for all user passwords in the application..
Permissions
are required to work in the application Setup.
Minimum Password Length: A password should not
be less than six characters for security. Eight to ten characters
is usually a good number for both security and for the user to remember.
You can set the password to expire, forcing the user
to create a new one.
Password Must Contain: You can select any or all
(or none) of these options, forcing the user to create a more secure password
by using more characters than the letters of the alphabet, and making
the password harder to guess or crack.
Password History tracks the last five passwords for
the user, so that they can not simply change between two passwords all
of the time.
The Security Question allows the user to provide an
answer to a question that only they should know. This is useful
should a user forget their password and need to verify their identity
in some other way.
The Invalid Login Attempts and Locked Period allows
the application to prevent any logins from a computer where the user has
failed to provide the correct information several times in a row. This
provides both a defence against someone guessing at logins, and provides
an indication that someone has been trying to do this.