6.0.3

Table Of Contents
2 Browse to Administration > Single Sign-On > .
3 Click the Policies tab and select Password Policies.
4 Click Edit.
5 Edit the password policy parameters.
Option Description
Description
Password policy description.
Maximum lifetime
Maximum number of days that a password can exist before the user must
change it.
Restrict reuse
Number of the user's previous passwords that cannot be selected. For
example, if a user cannot reuse any of the last six passwords, type 6.
Maximum length
Maximum number of characters that are allowed in the password.
Minimum length
Minimum number of characters required in the password. The minimum
length must be no less than the combined minimum of alphabetic,
numeric, and special character requirements.
Character requirements
Minimum number of dierent character types that are required in the
password. You can specify the number of each type of character, as
follows:
n
Special: & # %
n
Alphabetic: A b c D
n
Uppercase: A B C
n
Lowercase: a b c
n
Numeric: 1 2 3
The minimum number of alphabetic characters must be no less than the
combined uppercase and lowercase requirements.
In vSphere 6.0 and later, non-ASCII characters are supported in passwords.
In earlier versions of vCenter Single Sign-On, limitations on supported
characters exist.
Identical adjacent characters
Maximum number of identical adjacent characters that are allowed in the
password. The number must be greater than 0. For example, if you enter 1,
the following password is not allowed: p@$$word.
6 Click OK.
Edit the vCenter Single Sign-On Lockout Policy
A vCenter Single Sign-On lockout policy species the conditions under which a user's vCenter Single Sign-
On account is locked when the user aempts to log in with incorrect credentials. You can edit the lockout
policy.
If a user logs in to vsphere.local multiple times with the wrong password, the user is locked out. The lockout
policy allows you to specify the maximum number of failed login aempts and how much time can elapse
between failures. The policy also species how much time must elapse before the account is automatically
unlocked.
N The lockout policy applies only to user accounts, not to system accounts such as
administrator@vsphere.local.
Procedure
1 Log in to the vSphere Web Client as administrator@vsphere.local or as another user with vCenter Single
Sign-On administrator privileges.
Users with vCenter Single Sign-On administrator privileges are in the Administrators group in the
vsphere.local domain.
vSphere Security
52 VMware, Inc.