<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009sh7yyCAAOkta Classic EngineAuthenticationAnswered2023-12-04T15:56:17.000Z2023-12-01T19:16:25.000Z2023-12-04T15:56:17.000Z

JoshH.78879 (Customer) asked a question.

Password Policy changes for security.

Our current password policy is set to the minimum of 8 characters. We also are wanting to enable multiple features to make accounts more secure such as.

Symbols

No Firstname

No Lastname

Will current users be asked to update their current password right away? If not since we do not have a password expiry policy what is the best way to ensure everyone is updated to the new requirements?


  • Mihai N. (Okta, Inc.)

    Hi @JoshH.78879 (Customer)​ , Thank you for reaching out to the Okta Community! 

     

    The users will not be prompted to change their password if you modify the policy. The policy will apply to them only once they have to change the password, either via self-service, expiration or admin trigger. 

    Seeing as you mentioned that your current policy did not have an expiration period, you will need to trigger it. 

    Depending on the scale of your operation, you can do it individually from the Admin UI or in bulk via expire password API call.  

    There is also an “expire all” option in the Okta Admin UI under Directory People More action tab, but I would advise against it. I recommend doing it gradually, with batches of users.  

     

    More details about managing password expiration here:  

    https://help.okta.com/en-us/content/topics/users-groups-profiles/usgp-manage-password-expiry.htm

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

    --------------------------------

    Ask Away: OIG Product Experts Answer Your Questions Thru Thur., Dec 14

    Expand Post
    Selected as Best
  • Mihai N. (Okta, Inc.)

    Hi @JoshH.78879 (Customer)​ , Thank you for reaching out to the Okta Community! 

     

    The users will not be prompted to change their password if you modify the policy. The policy will apply to them only once they have to change the password, either via self-service, expiration or admin trigger. 

    Seeing as you mentioned that your current policy did not have an expiration period, you will need to trigger it. 

    Depending on the scale of your operation, you can do it individually from the Admin UI or in bulk via expire password API call.  

    There is also an “expire all” option in the Okta Admin UI under Directory People More action tab, but I would advise against it. I recommend doing it gradually, with batches of users.  

     

    More details about managing password expiration here:  

    https://help.okta.com/en-us/content/topics/users-groups-profiles/usgp-manage-password-expiry.htm

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

    --------------------------------

    Ask Away: OIG Product Experts Answer Your Questions Thru Thur., Dec 14

    Expand Post
    Selected as Best
This question is closed.
Loading
Password Policy changes for security.