Set password policy and self-service reset
Password rules, lockout, and the question-and-answer reset that puts 'Forgot your password?' on the login page — including the two switches that must both be on, and the expiration setting that takes effect immediately.
At the end of this guide, passwords meet the rules you chose, repeated wrong guesses lock the account, and users reset forgotten passwords themselves with security questions — without a ticket to you.
Everything lives in Administration > System Settings > Security Settings.
The baseline nobody configures
Even with no policy at all, Content Central enforces a floor: "Password must be between 6 and 128 characters in length and contain at least one alpha character." The policy settings raise that floor; they can't lower it.
The policy
Under the Password Policy subcategory:
Enable password policy, then set:
- Password length (characters minimum) — 6 to 128.
- Password complexity - Required categories (2+ characters from each selection will be required) — then tick the categories to demand: Number (i.e., 0-9), Upper case letters (i.e., A-Z), Lower case letters (i.e., a-z), Special characters (e.g. !@#$%^&*-=_+). Note the bar: two or more characters from each category you tick.
- Password expires after (days) — and read its description before setting it: "Enabling this setting will expire qualifying users' passwords effective immediately." On a long-lived system, that means everyone whose password is older than N days gets a change prompt at next login — set it late on a Friday and Monday is interesting. (Accounts not permitted to change their password are exempt.)
Above the subcategory, the lockout pair: Lock user accounts after failed attempts + Failed attempts before lockout (3–10).
Save Changes.
Self-service reset: the two-switch trap
The Forgot your password? link appears on the login page only when both of these are on:
- Allow forgotten-password handler on Login page
- Use question/answer challenge method
Turning on only the first produces nothing — the most common "I enabled it and there's no link" ticket, resolved. There is deliberately no email-based reset: the mechanism is security questions, so it works even when email doesn't.
Once enabled:
- Users are prompted to Provide Security Answers (three questions of their choosing) on their next sign-in — answers must exist before a reset can work.
- A forgetful user clicks the link, answers their questions ("Please answer your security questions to reset your password."), and sets a new password against your policy.
- Accounts with multi-factor authentication are excluded by design — the reset flow tells them to use their authenticator or contact you: MFA identity questions don't get answered by security questions.
Success check: with a test account that has answers on file, click Forgot your password?, complete the questions, and set a password that violates your policy — the rejection message quotes your rules back, proving both halves work.
