Currently, the password requirements and account security measures in place are as follows:
- Minimum Password Length: 8 characters
- Password Complexity: Must not be part of the top 10,000 most common passwords
- Password Expiration: None
- Password History: None
- System Inactivity Log Off: 4-hour inactivity timeout
- Session Log Off (regardless of activity): 24 hours
- Account Lockout Threshold: 10 unsuccessful login attempts
- Multi-Factor Authentication: Required for all users (barring API Users)