Articles in this section

Password requirements

Published:
Updated:

This article describes the password rules MobilityManager enforces, so you can choose a password that will be accepted the first time.

The enforced rule

MobilityManager enforces a single password rule everywhere a password is set:

  • Your password must be at least 8 characters long.
  • It cannot be blank or consist only of spaces.

If a password is shorter than 8 characters, you see: "Password must be at least 8 characters long." Enter a longer password to continue.

Note: The 8-character minimum is the only rule the system requires. There is no enforced requirement for uppercase letters, numbers, or symbols. That does not mean a short, simple password is a good idea, only that the platform will not reject it on those grounds.

Where the rule applies

The same minimum-length check runs at every point where a password is set, so the rule cannot vary between different screens:

SituationWho does it
Creating a new user accountSystemAdmin or FleetManager
Administrator resetting another user's passwordSystemAdmin or FleetManager
Self-service password resetAny user with a local password

Recommended practice

Although only length is enforced, a strong password protects your account and your company's fleet data. We recommend that you:

  • Use a passphrase of several unrelated words, which is easy to remember and hard to guess.
  • Mix in uppercase letters, numbers, and symbols where you can.
  • Avoid reusing a password from another service.
  • Use a password manager to generate and store a long, unique password.
Tip: Because repeated wrong entries lock your account for 15 minutes after 5 failed attempts, a password you can remember reliably is worth choosing. If you do get locked out, a password reset clears the lockout immediately.

Single sign-on accounts

If you sign in through single sign-on (for example Azure AD or Keycloak), your password is managed by your identity provider, not by MobilityManager. The 8-character rule described here applies only to local passwords held in MobilityManager. For SSO accounts, follow your provider's password policy.

Related

  • Resetting your password
  • Account lockout: what it is and how to recover
  • Signing in with your email and password
  • Single sign-on: an overview
AH
Written by Alexander Hagemann
Updated:
Access denied
Access denied