• 1
    • 22
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      NOTE: This suggestion is for Confluence Cloud. Using Confluence Server? See the corresponding suggestion.

      Modern companies require advanced password management. This includes:

      • Password aging: Automatically invalidating a password after a certain period of time,
      • Password strength check: Making sure that the passwords that are used are strong
        (an example can be found here: http://passwordstrength.net/)

      Two features that are getting more common every day.

          Form Name

            [CONFCLOUD-11496] Advanced password management

            Sam Jallad added a comment -

            Just purchased Confluence and noticed that it does not have complex password policy or any password policy at all! How so? This is a major security problem. I saw some articles about setting up a password policy in the cloud based version but not on the server based one. How come? Obviously this can be done. Please provide a status on this issue.  This is issue should be marked as a Major issue and not just a suggestion. You are putting our systems and corporate environment at a high risk. 

            Sam Jallad added a comment - Just purchased Confluence and noticed that it does not have complex password policy or any password policy at all! How so? This is a major security problem. I saw some articles about setting up a password policy in the cloud based version but not on the server based one. How come? Obviously this can be done. Please provide a status on this issue.  This is issue should be marked as a Major issue and not just a suggestion. You are putting our systems and corporate environment at a high risk. 

            Stephen Hodgson added a comment - - edited

            Just to be clear, this should allow managing separate authentication directories separately (something JIRA's implementation missed). For example, users from our delegated LDAP directory don't need a policy applied, because there's already a password policy somewhere else. However, the internal directory need the password policy applied.

            Stephen Hodgson added a comment - - edited Just to be clear, this should allow managing separate authentication directories separately (something JIRA's implementation missed). For example, users from our delegated LDAP directory don't need a policy applied, because there's already a password policy somewhere else. However, the internal directory need the password policy applied.

            +1 would be a basic feature. JIRA has it Confluence hasn;t

            Laurens Toning added a comment - +1 would be a basic feature. JIRA has it Confluence hasn;t

            +1

            Terry Bailey added a comment - +1

            We need this - without it we will have to limit the security level of our content.

            Kevin Hughes added a comment - We need this - without it we will have to limit the security level of our content.

            +1

            SSchoepel added a comment -

            +1
            Needed for a regulated industry to show control.

            SSchoepel added a comment - +1 Needed for a regulated industry to show control.

            +1

            Rachel Smith added a comment - +1

            +1!

            Maurice Pasman added a comment - +1!

            +1

              Unassigned Unassigned
              fb239a42de73 Erik Erik
              Votes:
              104 Vote for this issue
              Watchers:
              77 Start watching this issue

                Created:
                Updated: