Password Policy Expiration Too Weak – Password Lifetime Over 90 Days

< 1 min read

Impact Area

Security

 

Severity

Medium

 

Affected Element

Profile

Org Config

Rule ID #

SF-109

Impact #

Weak password expiration policies can open you up to brute force and dictionary attacks. Passwords with over 90 days expiration time are unsafe.

Remediation #

Modify the password expiration time to ninety days or less.

Time to fix #

30 min

References #

This rule is linked to Common Weakness Enumeration CWE-521 Weak Password Requirements.

Updated on March 21, 2025
Was it helpful ?