---
sourceDocument: Xanadu Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/platform-security

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Configuring your password policy

# Configuring your password policy {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Password policy criteria enables you to secure your password and adhere to the
minimum password complexity requirements.

## Before you begin

Role required: admin

## About this task

The Password Policy \[com.glide.password_policy\] plugin is enabled by default. It goes into effect when a user changes or resets the password. If you customized your instance, through the ValidatePasswordStronger installation exit or your Password Reset credential store \[pwd_cred_store\], see [password policy
properties](https://www.servicenow.com/docs/GjR8L2RxudkFlrEXUtRifA "The password policy properties enable you to administrate password policies, exclude list passwords, and apply a password policy during login.").

## Procedure

1. Navigate to AllPassword PolicyPassword Policies.  
   Note:  
   Default Strong preset in enabled as a default password acceptance criteria. In case, if you want to add a new criteria, you can perform the following steps.
2. Click New.  
   The Password Policy New record page, has the following sections that you
   must specify for setting your password:
   * Password Policy Criteria
   * Sequence Matching
   * Test Your Password

   {#set-your-password-policy__ul_ydk_ksr_1rb}
3. Specify the Name for your password policy.
4. In the Password Policy Criteria section, select the preset from the Password Strength Preset. The presets available are as follows:  
   {#set-your-password-policy__table_cdt_mtr_1rb__entry__2}

   | Password Strength Preset | Description |
   |-|-|
   | Default | Selecting Default auto-populates the password characters required as follows: * One Minimum Uppercase Character * One Minimum Lowercase Character * One Minimum Numeric Character {#set-your-password-policy__ul_vgq_ytr_1rb} |
   | Medium | Selecting Medium auto-populates the password characters required based on characters as follows: * One Minimum Uppercase Character * One Minimum Lowercase Character * One Minimum Numeric Character * One Minimum Special Character {#set-your-password-policy__ul_syx_b5r_1rb} |
   | High | Selecting High auto-populates the password characters as follows: * One Minimum Uppercase Character * Two Minimum Lowercase Character * One Minimum Numeric Character * Three Minimum Special Character {#set-your-password-policy__ul_mxw_d5r_1rb} |
   | Default Strong | Selecting Default Strong auto-populates the password characters required based on characters as follows: * One Minimum Uppercase Character * One Minimum Lowercase Character * One Minimum Numeric Character * One Minimum Special Character {#set-your-password-policy__ul_qg3_35r_1rb} |
   | Custom | Selecting Custom auto-populates the password characters required based on characters as follows: * One Minimum Uppercase Character * One Minimum Lowercase Character * One Minimum Numeric Character * One Minimum Special Character {#set-your-password-policy__ul_jmq_j5r_1rb} You can also customize the Password Policy Script that is displayed. |
   | Advanced | Selecting Advanced displays Password Rule Script and Password Strength Script. Based on your requirement you can customize these scripts. |
   [Table 1. Password Strength Preset and its description]

   {#set-your-password-policy__table_cdt_mtr_1rb}  
   Note:  
   Password policy is applied based on the selected preset.
5. Specify the fields described in the table:  
   {#set-your-password-policy__table_sks_f5c_jjb__entry__2}

   | Field | Description |
   |-|-|
   | Minimum Password Length | Minimum length of the password. This option is displayed for all the presets except Advanced. Note: Minimum Password Length is a required field and recommended setting it to a minimum of 8--10 characters. |
   | Maximum Password Length | Maximum length of the password. This option is displayed for all the presets except Advanced. Note: Maximum Password Length is an optional field and recommended to set it to a maximum 100 characters. |
   | Minimum Uppercase Character(s) | Minimum number of uppercase characters in the password, from 0 to 10. |
   | Minimum Lowercase Character(s) | Minimum lowercase characters in the password, from 0 to 10. |
   | Minimum Numeric Character(s) | Minimum numeric of characters in the password, from 0 to 10. |
   | Minimum Special Character(s) | Minimum number of special characters in the password, from 0 to 10. |
   | Included Special Characters | Allow a restricted set of special characters without any delimiter. For example, if you enter "$,!" users can only use "$" and "!" as special characters in the password. No other special characters can be used, and a password with other special characters is not allowed. |
   | Excluded Special Characters | Allow a restricted set of special characters without any delimiter. For example, when '@$!' is entered, users should not be able to use '@', '$' and '!' as special characters in their passwords. Note: This option is available if the glide.password_policy.use_excluded_special_char property is enabled. |
   | Disallow User Data | It is enabled to disallow the user data. |
   [Table 2. Password Policy form]

   {#set-your-password-policy__table_sks_f5c_jjb}
6. In the Sequence Matching section, specify the Sequence Length Threshold and Repetition Length Threshold.  
   Note:  
   * Both the sequence length threshold and repetition length threshold can have a maximum of eight characters. These fields enable you to restrict weak combinations of passwords that have predictable and repeating sequences such as "123456", "qwerty", "!@#$%\^", "aaaaa", and so on.
   * For Default Strong, the length for both sequence length threshold and repetition length threshold is selected as four characters.
   {#set-your-password-policy__ul_jhf_crw_brb}
7. In the Test Your Password section, specify your password.
8. Click Test Your Password.
9. Once the password is valid, click Submit to submit the password.  
   Note:  
   Always test your password before submitting.

*[\>]: and then


