AdemeroHelp

Set password policy and self-service reset

Password rules, lockout, and the question-and-answer reset that puts 'Forgot your password?' on the login page — including the two switches that must both be on, and the expiration setting that takes effect immediately.

AdministratorsContent Central 7.x20 minutesVerified 2026-09-05

At the end of this guide, passwords meet the rules you chose, repeated wrong guesses lock the account, and users reset forgotten passwords themselves with security questions — without a ticket to you.

Everything lives in Administration > System Settings > Security Settings.

The baseline nobody configures

Even with no policy at all, Content Central enforces a floor: "Password must be between 6 and 128 characters in length and contain at least one alpha character." The policy settings raise that floor; they can't lower it.

The policy

Under the Password Policy subcategory:

  1. Enable password policy, then set:

    • Password length (characters minimum) — 6 to 128.
    • Password complexity - Required categories (2+ characters from each selection will be required) — then tick the categories to demand: Number (i.e., 0-9), Upper case letters (i.e., A-Z), Lower case letters (i.e., a-z), Special characters (e.g. !@#$%^&*-=_+). Note the bar: two or more characters from each category you tick.
    • Password expires after (days) — and read its description before setting it: "Enabling this setting will expire qualifying users' passwords effective immediately." On a long-lived system, that means everyone whose password is older than N days gets a change prompt at next login — set it late on a Friday and Monday is interesting. (Accounts not permitted to change their password are exempt.)
  1. Above the subcategory, the lockout pair: Lock user accounts after failed attempts + Failed attempts before lockout (3–10).

  1. Save Changes.

Self-service reset: the two-switch trap

The Forgot your password? link appears on the login page only when both of these are on:

  • Allow forgotten-password handler on Login page
  • Use question/answer challenge method

Turning on only the first produces nothing — the most common "I enabled it and there's no link" ticket, resolved. There is deliberately no email-based reset: the mechanism is security questions, so it works even when email doesn't.

Once enabled:

  • Users are prompted to Provide Security Answers (three questions of their choosing) on their next sign-in — answers must exist before a reset can work.
  • A forgetful user clicks the link, answers their questions ("Please answer your security questions to reset your password."), and sets a new password against your policy.
  • Accounts with multi-factor authentication are excluded by design — the reset flow tells them to use their authenticator or contact you: MFA identity questions don't get answered by security questions.

Success check: with a test account that has answers on file, click Forgot your password?, complete the questions, and set a password that violates your policy — the rejection message quotes your rules back, proving both halves work.