16.6.2025: Password Policies Managed by the Organization

View Categories

16.6.2025: Password Policies Managed by the Organization

Organizations can now define the minimum password length for their users and specify how many previous passwords are restricted when setting a new one. This enables organizations to enforce stricter password policies than the default, preventing password recycling.

Password settings can be found on the Info page and can only be modified by administrators. Existing passwords remain valid when settings are changed; the new length requirement will apply at the next password change. Organization administrators can also set a time limit after which users will be prompted to change their password upon their next login.

These new settings do not alter other existing password requirements.

Additionally, the system has global minimum password requirements, which cannot be lowered below the system’s minimum, currently set at 15 characters according to the Finnish National Cybersecurity Centre’s recommendations.

Go to Top