PeopleTools Security - Password Controls

PeopleTools delivers support to manage passwords which are maintained internally in PeopleSoft.

  • Set password controls.
  • Create email text for forgotten passwords.
  • Create hints for forgotten passwords.
  • Delete hints for forgotten passwords.
  • Set up the site for forgotten passwords.

Click Here for the PeopleSoft Security PeopleBook

Delivered Password Controls

  • Age
    You define a number of days (between 1 and 365) that a password is valid. Users logging on after a password expires must change their password to log on. You can also specify a warning period.
  • Account Lockout
    This control enables you to lock an account after n number of failed logon attempts. After the account is locked out, a system administrator needs clear the "Account Locked" manually.
  • Miscellaneous
    The "Allow password to match User ID" control enables administrators to make sure users don't use their own user ID as a password.
  • Minimum Length
    Administrators can opt to set a minimum length for passwords maintained by the PeopleSoft system.
  • Character Requirements
    Administrators can require a set number of digits, upper and lower case or special characters within a password.
    Here is the list of special characters you can include within a password: ! @ # $ % ^ & * ( ) -   = + \ |[ ] {} ; : / ? . > <
  • Purge Inactive User Profiles
    This setting enables you to purge the system of user profiles that have not been used in a specified amount of time.
  • Note. Because Password Controls are enabled in Signon PeopleCode, you can extend or customize the controls by modifying the PeopleCode, for instance to specify a minimum number of upper and lower case characters.

    Support for Forgotten Passwords

    Users, upon forgetting their password, access the Forgot My Password page. The user answers the question correctly and gets a new password sent through your email system.

    You can have numerous password hints, but typically, you send all new passwords using the same email message template.

    PeopleSoft recommends setting up a site specifically designed for users who have forgotten their passwords. This site would require no password to enter, but provides access only to the forgotten password pages.

    Please also refer to the following solution on My Oracle Support (login required) How to configure the Forgotten Password Site for PeopleTools 8.4x

    Documentation Archive http://www.oracle.com/technetwork/documentation/psftarch-096292.html

Oracle 1-800-633-0738