or Submit a support ticket
Skip to content
  • There are no suggestions because the search field is empty.

Password policy

Table of contents:


Learn about Gridly's password requirements and expiration policies to keep your accounts secure. By default, Gridly doesn't enforce password expiration - this follows current guidance from Microsoft, which no longer recommend forcing regular password changes since it tends to produce weaker, more predictable passwords. If your organization requires periodic resets, you can enable this below.

Password validity period

This setting is only available to users with Owner Company role or a custom Company role with Manage company security privilege. Learn more in this article: Permission overview.

  1. Click Security in the left-hand side menu (under Company settings).ip 
  2. Under the Password Settings section, click the Setting button next to Set password policy.
  3. Select the Enable forcible password change policy checkbox.
  4. Configure the following policies:
    • Password validity period: Set how long passwords remain valid before expiring. The minimum period is 1 day.
    • Days before a user is notified that their password will expire: Set when users receive password expiration notifications. For example, setting this to 7 days sends users an email one week before expiration.
  5. Click Save.

 

A password cannot be reused until it has been changed 4 times. This prevents users from cycling back to a recently used password.

Password requirements

To protect your Gridly account and data, your password must:

  • Be 12-64 characters long
  • Include at least one uppercase letter (A-Z)
  • Include at least one lowercase letter (a-z)
  • Include at least one digit (0-9)
  • Include at least one special character ($, @, #, %, !, etc.)

Learn how to change your password.

To protect against repeated unauthorized login attempts, Gridly automatically locks an account after too many failed sign-in attempts.

  • After 5 failed login attempts, the account is locked for 15 minutes.
  • Once the lockout period ends, the user can try signing in again.