# Set password policy and self-service reset

Password rules, lockout, and the question-and-answer reset that puts 'Forgot your password?' on the login page — including the two switches that must both be on, and the expiration setting that takes effect immediately.

Product: content-central · Versions: 7.x · Audience: system-administrator · Time: 20 minutes · Last verified: 2026-09-05

Canonical: https://help.ademero.com/content-central/administration/set-password-policy-and-self-service-reset

**At the end of this guide, passwords meet the rules you chose, repeated wrong guesses lock the account, and users reset forgotten passwords themselves with security questions — without a ticket to you.**

Everything lives in **Administration** > **System Settings** > **Security Settings**.

## The baseline nobody configures

Even with no policy at all, Content Central enforces a floor: "Password must be between 6 and 128 characters in length and contain at least one alpha character." The policy settings raise that floor; they can't lower it.

## The policy

Under the **Password Policy** subcategory:

1. **Enable password policy**, then set:
   - **Password length (characters minimum)** — 6 to 128.
   - **Password complexity - Required categories (2+ characters from each selection will be required)** — then tick the categories to demand: **Number (i.e., 0-9)**, **Upper case letters (i.e., A-Z)**, **Lower case letters (i.e., a-z)**, **Special characters (e.g. !@#$%^&*-=_+)**. Note the bar: *two or more* characters from each category you tick.
   - **Password expires after (days)** — and read its description before setting it: "Enabling this setting will expire qualifying users' passwords effective immediately." On a long-lived system, that means everyone whose password is older than N days gets a change prompt at next login — set it late on a Friday and Monday is interesting. (Accounts not permitted to change their password are exempt.)

2. Above the subcategory, the lockout pair: **Lock user accounts after failed attempts** + **Failed attempts before lockout** (3–10).

3. **Save Changes**.

## Self-service reset: the two-switch trap

The **Forgot your password?** link appears on the login page only when **both** of these are on:

- **Allow forgotten-password handler on Login page**
- **Use question/answer challenge method**

Turning on only the first produces nothing — the most common "I enabled it and there's no link" ticket, resolved. There is deliberately **no email-based reset**: the mechanism is security questions, so it works even when email doesn't.

Once enabled:

- Users are prompted to **Provide Security Answers** (three questions of their choosing) on their next sign-in — answers must exist before a reset can work.
- A forgetful user clicks the link, answers their questions ("Please answer your security questions to reset your password."), and sets a new password against your policy.
- Accounts with [multi-factor authentication](/content-central/administration/set-up-multi-factor-authentication) are excluded by design — the reset flow tells them to use their authenticator or contact you: MFA identity questions don't get answered by security questions.

**Success check:** with a test account that has answers on file, click **Forgot your password?**, complete the questions, and set a password that *violates* your policy — the rejection message quotes your rules back, proving both halves work.

## What's next

- [Set up multi-factor authentication](https://help.ademero.com/content-central/administration/set-up-multi-factor-authentication)
- [How signing in works](https://help.ademero.com/content-central/administration/how-signing-in-works)
