Password Policy Parameters
The following settings govern how external users interact with the Secure Inbox for PGP Encryption Cloud Server:
- **Inactivity Expiration:** Defines the number of days an account can remain idle before it is marked for deletion.
- **Account Expiration Reminders:** Determines when a user is notified that their account is approaching the inactivity limit.
- *Default:* 15 days prior to expiration.
- **Message Expiration:** Controls how long individual encrypted messages remain in the Secure Inbox, independent of account activity.
- **Password Complexity:** Enforces requirements for external user passphrases (e.g., minimum length, use of special characters, and digits).
- **Lockout Threshold:** The number of failed login attempts allowed before the account is temporarily locked (typically 3–5 attempts).
- **Unlock/Reset Window:** The time-to-live (TTL) for security codes emailed to users for account unlocking or password resets.
These parameters are configured at the server level by Broadcom.
If your organization requires adjustments to any of these policies (e.g., shortening the inactivity window or increasing password complexity):
- Identify the specific parameter and the new value you wish to implement.
- Open a technical support case with **PGP Encryption Support**.
- An engineer will verify your identity and apply the requested changes to your Cloud Server instance.