Skip to main content
A predefined password security policy protects reseller and customer accounts from unauthorized access through two rules: password reuse and password expiration.
  • Password reuse: after a password expires, a user must create three unique passwords before reusing an old one; Gcore stores the last three passwords to enforce this rule.
  • Password expiration: the frequency of expiration is configurable, or the requirement can be disabled entirely to let passwords remain valid indefinitely.

Enable password policy

The password policy can’t be saved unless the Username/Password login option is enabled first.
1

Enable username and password login

(Optional) Skip this step if username and password login is already enabled.
  1. Navigate to the Security settings.
  2. Click Authorization.
  3. Enable the Username/Password login toggle.
  4. Click Save to apply the changes.
Authorization settings with Username/Password login and SSO login toggles
2

Activate password policy

  1. Navigate to the Security settings.
  2. Click Password policy.
  3. Enable the Frequency of the password changing toggle.
  4. Specify the number of days after which the password expires, between 30 and 180 days.
  5. Click Save to apply the changes.
Password policy page with the Frequency of the password changing toggle off
Password policy page with the frequency toggle enabled and set to 70 days
A frequency between 60 and 90 days balances security and convenience.
Two weeks before a password expires, users with the policy enabled receive an email reminder to change it.