5.8.5

Table Of Contents
Set Password Policies
You can configure the account lockout, password strength, and password change policy settings for
vCenter Operations Manager user passwords.
NOTE vCenter Operations Manager sessions time out after 30 minutes of inactivity and require users to log
in again. You cannot change this timeout value.
Procedure
1 Select Admin > Security.
2 Select the Password Policy tab.
3 In the Account Lockout Policy group, configure the account lockout settings.
Option Description
Active
Locks users out of vCenter Operations Manager after the number of failed
login attempts specified in Allowed Login Attempts.
Allowed Login Attempts
The number of login attempts that a user can attempt before being locked
out of vCenter Operations Manager.
4 In the Password Strength Policy group, configure the password strength policy settings.
Option Description
Active
Select this check box to set password strength requirements.
Password Min Length
The minimum number of characters that a password can contain.
Password Must Have Letters and
Numbers
Select this check box to require passwords to contain at least one letter and
at least one number.
Password Must Not Equal To User
Select this check box to prevent users from using their user name as their
password.
5 In the Password Change Policy group, configure the password change policy settings.
Option Description
Active
Forces users to change their passwords after the number of days specified
in Password Expiration Period.
Password Expiration Period (days)
Number of days before users are forced to change their passwords.
Password Prior Expiration Warn
Period (days)
Number of days before a password expires that users are warned that their
passwords are about to expire.
6 Click the Save Policy icon to save your configuration.
Maintaining Users and User Groups
To maintain users and user groups in vCenter Operations Manager, you might need to add, remove, or edit
user accounts and user groups.
Edit a User Account
When you edit a user account, you can change user and password information. You can also activate,
deactivate, lock out, or unlock a user account.
If you imported a user from LDAP, you cannot change user name or password-related information, but you
can edit other user information.
Chapter 6 Configuring and Managing Users
VMware, Inc. 75