---
title: "February 2023 | Tip - Password Management"
canonical: "https://kb.myframeworks.com.au/space/Blog/blog/10223628/February%202023%20%7C%20Tip%20-%20Password%20Management"
format: markdown
---
# Overview

It is important, for the security of your Frameworks data, that your business employs good configuration and management of your user accounts. To do this, check and ensure you are using all the features that are currently available in Frameworks:

## 1. Check you have strong password rules defined in Frameworks

To ensure all user accounts require a strong password Frameworks has a range of System Settings that can be enabled.

**1. System Administration > System Tables > Miscellaneous Table Maintenance - System Settings - General**

| Flag | Description | Value |
| --- | --- | --- |
| **PwdAdminGrps** | List of User Groups that require extra password length restrictions as defined by **PwdMinLenAdmin** | values to be entered separated by a comma eg sysadmin, sales |
| **PwdSpecList** | List of special characters that a user must use in their password | ~!@#$%^&*`-_=+<br>These are the default values loaded by the installer but can be changed to suit your needs. |

**2. System Administration > System Tables > Miscellaneous Table Maintenance - System Settings - Numeric**

| Flag | Description |
| --- | --- |
| **PwdExpNot** | Enter the number of days before the user's password expires to notify the user when they log in. |
| **PwdMinLen** | Enter the minimum length of password. A minimum password length of 8 - 10 characters is good as it provides adequate security and is still short enough for users to easily remember. |
| **PwdMinLenAdmin** | Enter the minimum length of the password for users with Security Class sysadmin and User Group in **PwdAdminGrps** |
| **PwdMinLow** | Enter the minimum number of lower-case characters. 1 or more is recommended to enforce a strong password. |
| **PwdMinNum** | Enter the minimum number of numeric characters. 1 or more is recommended to enforce a strong password. |
| **PwdMinSpec** | Enter the minimum number of special characters from **PwdSpecList. **1 or more is recommended to enforce a strong password. |
| **PwdMinUp** | Enter the minimum number of upper-case characters. 1 or more is recommended to enforce a strong password. |
| **PwdReuse** | Number of days where a previous password can't be reused. This ensures that passwords are not able to be repeated. This helps reduce the risk of a compromised password being used. |


## 2. Make sure that invalid login attempts lock the user account after 3 attempts.

The following settings allow you to lock a user's account after a number of failed login attempts. This help to reduce hackers from being able to use a brute force attack to gain access to your system

**1. System Administration > System Tables > Miscellaneous Table Maintenance - System Settings - Numeric**

| Flag | Description |
| --- | --- |
| **PwdRetry** | Enter the number of incorrect password attempts before locking a user account. We recommend setting this to 3 attempts as it allows your users to make a mistake and still access the system. |

Once the maximum number of retries has been exceeded, the user is locked out and their user ID, under **User Maintenance**, is set to **Account Locked**. Only an administrator can unlock the user by disabling the **Account Locked **checkbox in the User's maintenance screen.


## 3. Set a password expiry period and make sure that all users have strong passwords.

While we understand that having to think of a new password every 30 - 90 days is a bit annoying, by doing so you are making it harder for an attacker to know what anyone's password is at any given time. Plus, it helps if you forget to disable an ex-employee account because they will not be able to log in after the defined period. 

To define the password expiry period there are 2 steps:

1. Navigate to **System Administration > System Tables > System Control File Maintenance.**
  1. Under the **Site **tab, in the **Password Expiry Days** field enter the number of days a password will be valid.
2. Navigate to **System Administration > Users & Security > Users > User Maintenance.**
  1. In the **Must Change by** field select an expiry date (if it defers from the default period defined in System Control File Maintenance)

> 📝 The **Password Expiry Days** field in [System Control File Maintenance](https://skb.sterland.com:8443/display/FRAM/System+Control+File+Maintenance) requires a value for the** Must Change by **field to be visible in [User Maintenance](https://skb.sterland.com:8443/display/FRAM/User+Maintenance)

Once these are defined and based on the value defined under flag **PwdExpNot **when next logging into Frameworks users will receive a warning that the password is due to expire in xxx days. Users will then need to log in to Frameworks and reset their password before the expiry date.

> ❌ **NOTE:** If **Password will Not Expire** has been defined in [Security Group Maintenance](https://skb.sterland.com:8443/display/FRAM/Security+Group+Maintenance) on a security group assigned to a user then the above password expiries will be overwritten to NOT expire.


## 4. Review your user accounts and disable accounts that are no longer required.

Using the User Listing report you can review all your accounts and which ones are disabled.


# Additional Considerations

Strong password management is only one part of the security picture. Some other considerations are:

- If you use Frameworks API’s, make sure the API-KEY limits what the 3<sup>rd</sup> party is allowed to use. Ask us for a new API-KEY if required or you need help.
- If you access Frameworks from outside your company network, make sure you access it with an https connection.