Last updated: 2026-04-04
Source: https://support.freshservice.com/support/solutions/articles/213865-password-policy
Password policy
You can set up different levels of password security using Freshdesk for your customers. By default, any password must contain a minimum of 8 characters and must not contain the username.
You can also opt for advanced settings and set up custom password policies like the password expiration time or the minimum password length. The more sensitive the data your customers have access to, the more stringent your password rules must be. Please note that you will not be able to set up password policies if your SSO is enabled.
Quick guide to setting up your password policy:

What happens after the changes are made:
_Note:_
If your customers are facing login issues, here's how you can reset their password \- https://www.youtube.com/watch?v=oJTcbYch5T8&list=PLsYJ3BsyR4qGFujlW0iDtOBOf4IPVsAqt&index=2
You can set up different levels of password security using Freshdesk for your agents and customers. By default, any password must contain a minimum of 8 characters and must not contain the username.
You can also opt for advanced settings and set up custom password policy like the password expiration time or the minimum password length. The more sensitive the data your agents/customers have access to, the more stringent your password rules must be. Please note that you will not be able to set up password policies if your SSO is enabled.
Quick guide to setting up your password policy:
- choose the minimum number of characters required for the password, - decide when the passwords should expire, - control the repetition of passwords, using the corresponding drop downs.
What happens after the changes are made:
- the agents who are logged in will be prompted to change their passwords for at least an hour after which they will be logged out. They can login again after setting up a new password that complies with the policy changes. - the agents who are not logged in will be made to change their passwords the next time they try to log in.

