Password Policy Inheritance
The password policy is bound to an account. An account (a provider or reseller) can have two password policies:
- For their own users
- For child account users
A customer account does not have its own password policy.
A provider configures both password policies using the PCP. A reseller either configures both policies using the RCP or receives them from a higher-level entity (a provider or reseller).
If the policy is locked for child accounts, then a sub-reseller cannot define its own password policy for their own staff members.
If a reseller redefines the password policy for their own users, it must be stronger than the policy defined in the parent account.
If a reseller redefines the password policy for child accounts, it can be weaker than the policy defined in the parent account.
Note: IDP password policies will not be applied, if Password Quality level for Child Accounts is set to None in System > Settings > Setup > Password Quality in the Classic Control Panel.