BILLmanager 6
en En
es Es

Password settings

This article describes how a provider works with passwords in BILLmanager: 

  • setting up mandatory password changes and complexity rules;
  • generating secure combinations;
  • access recovery by users;
  • protection against brute-force attacks;
  • importing forbidden passwords.

To set up the password policy, go to Provider → Password settings.    

Mandatory password changes

You can set up mandatory password changes:

  • for all employees and users in BILLmanager;
  • for a specific employee or user.

You can also configure the platform to check a user’s new password against:

  • the user’s login or email;
  • previous passwords.

With this setting, users and employees see a notification about the need to change their password when they log in.

To set up password change on the next employee login:

  1. Go to Provider → Staff.
  2. Select an employee.
  3. Click Change password.
  4. Click Ok.

To set up password change on the next user login:

  1. Go to Clients → Users.
  2. Select an employee.
  3. Click Change password.
  4. Click Ok.

To set up password changes for all employees or users:

  1. Go to Provider → Password settings.
    1. In Main settings block:
      1. Set the Password complexity level:
        • do not check;
        • weak;
        • good;
        • strong.
        Read more about password strength levels in Configuration file.
    2. Enable the Consider restricted passwords option if you want to prevent specific passwords from being used. Click on the List of restricted passwords to open the editing menu. You can create, edit, or delete passwords from the list. For more information, see Forbidden passwords.
    3. Specify the Minimum password length. For example, 10 characters.
    4. Select which characters the password should contain. The Пароль должен содержать field offers the following options:
      • Digits;
      • Lowercase Latin characters — select this option if you want the password to include characters from a to z;
      • Uppercase Latin characters — select this option if you want the password to include characters from A to Z;
      • Special characters — characters from the list:  +-*/^()[]{}=<>"''$,;:%!&?_#@.
  2. In the Change password block:
    1. Enable Require employees to change password. When enabled, fill in the fields:
      1. Warn after — the number of days after which BILLmanager warns the employee that the password must be changed.
      2. Block after — the number of days after which the employee must change the password to keep working in the system.
      3. Exclude employees — enter the employee IDs, separated by spaces, for employees who do not need to change their password on next login.
    2. Enable Ask users to change their password. When enabled, fill in the fields:
      1. Warn after — the number of days after which BILLmanager warns the user that the password must be changed.
      2. Block after — the number of days after which the user must change the password to keep working in the system.
      3. Exclude users  — enter the user IDs, separated by spaces, for users who do not need to change their password on next login.
    3. Set a date in the Do not block till field. This is the date until which employees’ and users’ access will not be blocked if they have not changed their password.

      Example
    4. Compare password with login/email — enable this option to prevent users from setting a password that matches their login or email.
    5. Compare the new password with the previous ones — enable this option to compare the new password with previous passwords when changing it. If enabled, in Password history depth specify how many recent passwords the new password should be compared against.
  3. Click Ok to save the changes.

Password recovery

If a user forgets the password for an account in BILLmanager, they can go through the password recovery process. To recover the password, the user must specify the email address used as the login for the account.

By default, BILLmanager sends the recovery code to the user’s email. To let BILLmanager send emails, configure the outgoing mail server.

Configure the number of password reset attempts by email:

  1. Go to Provider → Password settings.
  2. In the Password recovery block, specify:
    1. Recovery request limit — the maximum number of password recovery emails that can be sent during the period specified in the Recovery request period field.
    2. Recovery request period — the time before the request limit is reset, in seconds. 
  3. Click Ok to save the changes.

To make the platform send a confirmation code to a verified phone number:

  1. Enable and configure anti-fraud protection.
  2. Go to Provider → Providers  → select a provider → click Clients verification → create a phone verification rule. For more information, see Clients verification.
  3. Go to Provider → Global settings → the Main block → enable Password recovery via SMS to allow sending a confirmation code to a verified phone number.
    If the user does not have a verified phone number, the confirmation code will be sent to email.
    1. Attempts to send a code — the limit on attempts to receive a password reset code by SMS. After the limit is exceeded, password recovery will only be possible by email. 
    2. Code receiving timeout , in seconds — the minimum interval between repeated password reset code sends.
    3. How to receive a code — this option lets the user choose how to receive the code: by SMS or email.

Password generation

You can configure password generation for all employees or users. The settings will be used for all cases where a password needs to be set. For example, for a login password or a password when ordering a virtual server.

To configure password generation:

  1. Go to Provider → Password settings.
  2. In the Password generation block:
    1. Specify Длину пароля. The generated password length:
      • must meet the specified password complexity level;
      • cannot be less than the minimum password length specified in the Main block.
    2. Specify Allowed symbols that will be used when generating the password. For example, 0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
  3. Click Ok to save the changes.

Authorization parameters

You can limit the number and frequency of failed login attempts to the platform (authorization) and apply a lockout for users who try to guess the password. These restrictions help protect the platform from network attacks that use automatic password guessing (brute force).

To configure authorization parameters:

  1. Go to Provider → Password settings.
  2. In the Authorization parameters block:
    1. Specify Incorrect password entry limit — the maximum number of times a user can enter the wrong password during login. After the limit is exceeded, the system will lock the user for the time specified in the settings. Default value: 3. The setting does not apply to the root user.
    2.  Specify Attempt tracking interval — the time in minutes during which failed password entries will be counted. For example, 5 failed attempts in 15 minutes.  You can enter only an integer number of minutes. Default value: 15 attempts.
    3. Select the User lockout type:

      1. Temporary lockout — the user is locked for a period and unlocked automatically. When this option is selected, specify Время задержки после ошибочного ввода пароля, секунды. You can enter only an integer number of seconds. Default value: 20 seconds.
      2. Permanent lockout — the user must reset the password using:

      Default value: Temporary lockout.
  3. Click Ok to save the changes.

Changing a password by an administrator

To change an employee password:

  1. Go to Provider → Staff.
  2. Select an employee → Edit.
  3. Enter the new password. To:
    • show the entered password, click the icon  ;
    • generate a password, click the icon . 
  4. In the Confirmation field, enter the password again.
  5. Click Ok to save the changes.

To change a user password:

  1. Go to Clients → Users.
  2. Select a user → Edit.
  3. Enter the new password. To:
    • show the entered password, click the icon  ;
    • generate a password, click the icon . 
  4. In the Confirmation field, enter the password again.
  5. Click Ok to save the changes.

Forbidden passwords

You can configure the system so that users and employees cannot use certain passwords. To do this:

  1. Enable Consider restricted passwords.
  2. Click List of restricted passwords to open the edit menu. You can create, edit, and delete passwords from this list.
  3. Add passwords to the List of restricted passwords. We recommend including:
    • passwords that contain:
      • the organization name;
      • the user name;
      • the client domain name;
      • the server or account IP address.
    • popular passwords from public dictionaries. For example, 123456, password, qwerty.

Importing forbidden passwords

To import forbidden passwords:

  1. Go to Provider → Password settings.
  2. In the Main settings block, enable Consider restricted passwords.
  3. Click List of restricted passwords to open the edit menu. 
  4. Click Add to create a new forbidden password list.
  5. Add several passwords as a list — one password per line. ASCII characters are allowed in passwords.
  6. Click Ok to save the changes.
Useful tips

Related topics: