Password expiration

Configure password expiration for user and service accounts.

SnapLogic Environment admins can configure password expiration for user and service accounts. You can expire passwords immediately or set them to expire periodically, after a specified number of days. With periodic expiration, the Expiration notice period determines how far in advance users start receiving a notification to reset their password.

With expired passwords, users:

  • Cannot invoke SnapLogic Public APIs.
  • The user's scheduled tasks stop running.
  • Human users must reset their password by providing the old password and a new one, whether resetting through the UI or via the API. Service accounts use a different reset path — see Expire all passwords below.

Limitations

  • Password expiration does not apply to users who log in using SSO.
  • Expire all passwords only affects users whose accounts are in environments where you have administrative privileges. For example, if Tom has accounts in dev and prod, but you are only an Environment admin in prod, his password will not expire when you click Expire all passwords.
  • If a user belongs to multiple environments with different periodic expiration policies, the shortest expiration period and the longest notice period from those environments apply.

Page controls

By default, password expiration is disabled. The Expiration period displays 0 until you set a policy:


Admin Manager Password expiration screen

Controls include:

  • Expiration period: Set the number of days before all passwords expire, including those for service accounts. Valid values are from 0, which means passwords do not expire, to 90 days. The default value is 0 days, no expiration. The countdown starts from the account creation date or the most recent password change.
  • Expiration notice period: Set the number of days before expiration when users start receiving notices to reset their passwords. When the notice period begins, users receive a one-time email. They also see an in-app reminder dialog on every login until they reset their password. The notice period value can be from 1 to 14 days. The default value is 14 days. Once you set an expiration period greater than 0, the notice period can't exceed it within that environment. But if a user belongs to multiple environments, their combined notice period can still end up longer than their combined expiration period, because SnapLogic applies the shortest expiration period and the longest notice period across all their environments.
  • Expire all passwords: Signs out users in environments you administer on their next interaction, including you, and forces a password reset.
    • For service accounts, the admin who created the account receives an expiration email with a reset link.
    • Anyone with access to the service account's email can also use the Reset password link on the login screen.
    • Remember to update any app or integration using the service account with the new password.

Troubleshooting

A user's password did not expire as expected. Check the following:

  • The user logs in using SSO. SSO users are exempt from password expiration.
  • For Expire all passwords: the user has an account in an environment where you are not an Environment admin. Only users in environments you administer are affected.
  • The user belongs to multiple environments. The shortest expiration period across all environments the user belongs to applies, which may be shorter than the period you configured in your environment.