You can set an expiry date for passwords of users in your team. When users try to log in with an expired password, they are blocked and prompted to reset it. Use this feature to align with your organization's password policy (requiring periodic changes).
Who can configure this
Only users with Owner permissions.
Steps to configure
- Open "Owner Functions" in the side menu
- Select the "Security" tab at the top and open the "Password policy" card
- Check "Enable password expiration"
- Enter the expiration period (days) (1–365 days)
- If needed, turn on "Force change on first log in"
- This prevents new users from continuing to use the initial password when they first log in
- Click "Save"
Behavior after enabling
- When users try to log in with a password that has exceeded the set expiry date, a password change screen is forcibly displayed
- No other operations are allowed until the password change is completed
- Users who log in via Single Sign-On (SSO) are subject to the IdP (Microsoft Entra ID / SAML provider) policy and are not covered by this setting
- Email-free accounts also log in using passwords, so they are subject to this policy
Tips for effective use
- An expiry period of 90 to 180 days is a common industry guideline (avoid setting it too short, as this can encourage password reuse; align with your organization's policy)
- When distributing accounts to new users, turning on forced password change on first login makes operations smoother
- If your operations are primarily SSO-based, consolidate the policy on the IdP side and disable the Dive password policy to keep management simpler