Owner's Manual

100 Security
Login Policy
The LoginPolicy section of the Application Security Policy page sets policies about user logins.
These policies govern the message that appears in the login screen and the various security
measures applied to user’s attempts to log in.
Figure 4-20. Login Policy Page
The individual policies available from the Login Policy Page are:
Expired Account Age
Inactivity Timeout
Login Attempts
Lockout Period
Privacy Warning
Idle Account Age
Maximum Logins per UserId
Session Inactivity Timeout
Each Login Policy appears in the list along with its current setting. Edit a policy by clicking it; an
editor appropriate to that setting appears in the lower portion of the page.
Expired Account Age
The Expired Account Age setting determines how many weeks an account can remain active if it
has an expired password and no logins. Once this threshold is reached, the account is disabled and
can only be reactivated by an administrator.