Edmissa docs

Password Policies

Configure password strength, length, character rules, and reuse protection for Edmissa users.

Password Policies control the password requirements users must meet when they join Edmissa, reset a password, or change an existing password.

Use this page when your agency wants to keep the system default policy or set a custom policy for the workspace.

What this guide helps you configure

AreaWhat it controls
Policy sourceWhether Edmissa uses the system default policy or a custom workspace policy.
Basic requirementsPassword strength score, minimum length, optional maximum length, and required character types.
Security rulesChecks that block weak, repeated, personal, or recently used passwords.
Password testingA safe way to test a sample password against the current policy before saving.

Open Password Policies

Use this path when you want to manage password rules:

  1. Open Settings.
  2. Open Team Management.
  3. Select Password Policies.
  4. Confirm the page title is Password Policies.

The direct route is /t/settings/password-policies.

The page subtitle is Configure password requirements for your organization. You need access to security settings to open and save this page.

Choose the policy source

The first card is Password Policy Override. It includes the Enable Custom Password Policy switch.

Switch stateWhat it means
OffEdmissa uses the system default password requirements. The page shows System Default as the current policy source.
OnEdmissa uses the custom requirements you set on this page. The page shows Custom Organization Policy as the current policy source.

When the switch is off, the policy controls are shown as disabled. Turn on Enable Custom Password Policy before changing requirements.

Review the system default

If you do not turn on a custom policy, Edmissa uses the system default requirements.

The current default policy is:

SettingDefault
Minimum Password Strength Score3/5, shown as Fair
Minimum Length8 characters
Maximum Length128 characters
Character Type RequirementsUppercase letters, lowercase letters, numbers, and symbols
Block Common PasswordsOn
Block Personal InformationOn
Block Sequential CharactersOn
Block Repeated CharactersOn
Prevent Password ReuseOn
Remember Last N Passwords5

This is a good first version for most agencies. Use a custom policy only when your internal security process requires different rules.

Configure Basic Requirements

Use Basic Requirements to set the minimum quality of a password.

SettingHow to use it
Minimum Password Strength ScoreMove the slider from 1 to 5. Higher scores require stronger passwords. The page labels scores from Very Weak through Very Strong.
Minimum LengthSet the fewest characters a password can have. The field accepts 4 to 50.
Maximum Length (Optional)Set the longest allowed password. Leave it blank when you do not want a limit. The field accepts 8 to 128.
Uppercase LettersRequire at least one uppercase letter.
Lowercase LettersRequire at least one lowercase letter.
NumbersRequire at least one number.
SymbolsRequire at least one symbol.

For a first setup, keep the password long enough to be useful and easy enough for staff to remember safely. A stronger score is useful for admins and users with broad access, but avoid a rule that creates constant support requests.

Configure Security Rules

Use Security Rules to block patterns that make passwords easier to guess.

SettingWhat it blocks
Block Common PasswordsCommon choices such as password123.
Block Personal InformationNames, email addresses, and similar personal details.
Block Sequential CharactersPatterns such as 123 or abc.
Block Repeated CharactersPatterns such as aaa or 111.
Prevent Password ReuseRecently used passwords.
Remember Last N PasswordsThe number of previous passwords Edmissa checks when reuse prevention is on.

For study abroad teams, these rules help protect student profiles, applications, documents, and user access settings.

Test Password Requirements

Use Test Password Requirements before saving a custom policy.

  1. Enter a sample password in Test Password.
  2. Review whether Edmissa shows Password meets requirements or Password does not meet requirements.
  3. Read any validation messages.
  4. Review the Strength Score badge.
  5. Adjust the policy if normal users would have trouble creating a compliant password.

Do not use a real user's password in the test field. Use a safe sample that matches the kind of password you want users to create.

Save or reset the policy

Use the page actions in the header:

ActionUse it when
Save PolicyYou have enabled a custom policy and want to apply the current settings.
Reset to DefaultsYou want to remove the custom policy and return to the system default.

Both actions are available only when custom password policy is enabled. After a successful save, Edmissa confirms that the password policy was updated.

For a first Edmissa setup, keep the rollout simple:

  1. Start with the system default policy unless your agency already has a stricter password standard.
  2. If you need a custom policy, change one group of settings at a time.
  3. Test a few sample passwords before saving.
  4. Tell users before making the policy stricter.
  5. Confirm invitation, password reset, and normal sign-in still work as expected.

If users report sign-in trouble after a policy change, review the policy source, minimum length, strength score, and enabled security rules first.

GuideUse it for
Security and auditUnderstand how password rules fit with wider account protection.
Session PolicyConfigure session timeout, warnings, and extra checks for sensitive actions.
UsersInvite users, reset passwords, and manage account status.
RolesControl who can manage security settings.
Access and permissions troubleshootingDiagnose missing pages, disabled actions, and access problems.