Administering Domains, Roles and Users > User Accounts
User Account Password Policy Information
The Capital software suite includes a configurable password strength checking system that enforces industry standards to ensure user accounts can only create strong passwords.
This topic explains the password features and requirements for Capital application users, along with associated guidelines to ensure account security and protection of user information.
Default Password Settings
Objective: Ensure strong password security by enforcing complexity requirements by default.
Policy:
Length: Passwords must be between 8 and 16 characters in length. It is recommended to create passwords with 12 or more characters for enhanced security.
Composition: Passwords must include at least one uppercase letter, one lowercase letter, one number, and one symbol (for example, !, @, #, $).
Expiration Period: Passwords are set to expire after a 90 day period.
Account Lockout: User accounts are locked after 3 failed login attempts.
Password Reuse: A user account cannot reuse the last 3 previously used passwords.
When creating a new password, settings are validated in real-time and provide specific feedback if criteria are not met. The Edit Password dialog box displays help text for applicable requirements. A green marker is shown for a satisfied criteria.
Figure 16: Edit Password Dialog Box
Configurable Password Policy
Objective: Allow customization of password settings based on your organizational requirements.
Policy:
Configuration Restrictions: Password settings can be edited by user accounts with the 'Security > Administration' permission, or a user account with the User Administrator role.
Customizable Settings: User accounts with the appropriate permission or role can customize:
Password length requirements
Character requirements
Expiration period
Failed login attempt limits
Password history restrictionsPassword Settings Location: The configurable password policy settings are found under the Capital Project Manager > System Preference > User > Password Policy node. See System Preferences for Capital Access Manager in the Capital Project Manager User Guide.
Toggle Password Visibility
Objective: Enable users to verify their password entry for accuracy.
Policy:
- Visibility Toggle: All password entry fields include a button to toggle visibility between plain text and masked text .
Password Expiry and Rotation Policies
Objective: Maintain account security by enforcing regular password changes.
Policy:
Expiry: Passwords will expire every 90 days (default, configurable).
Rotation: Passwords cannot be the same as the last 3 passwords (default, configurable).
Notifications: Alerts will appear when passwords are due to expire in 7 days or less. Password expiration notifications appear in the following location:
In the status bar below the output window of Capital design applications.Customizable Settings: User administrators can adjust password expiry period and rotation requirements. See System Preferences for Capital Access Manager in the Capital Project Manager User Guide.
Note
The expiration date of your account is visible in Capital Access Manager on the Edit User Account Dialog Box.
It is strongly recommend to change your password before it expires. Once a password has expired, you must contact a user administrator to reset the password. After a reset, you must change your password in Capital Access Manager before accessing other Capital applications
Note
Changing your password in Capital Access Manager before accessing other Capital applications is applicable in all scenarios where a user administrator has been involved in a password change (first login, password expiration, forgotten password and reset password).
Note
Superuser account passwords never expire, or become locked, however they must follow password complexity requirements.
Account Locking on Consecutive Login Failures
Objective: To mitigate unauthorized access attempts by locking accounts after multiple failed login attempts.
Policy:
Invalid Attempts: The count of invalid password attempts increases with each wrong entry, showing remaining attempts.
Locking: Accounts will be marked as locked after 3 invalid attempts (default, configurable).
Reset: Invalid password count resets on successful login.
Customizable Settings: User administrators can adjust login failure attempts. See System Preferences for Capital Access Manager in the Capital Project Manager User Guide.
Unlocking: Only a user administrator can unlock accounts.
Note
A locked account can only be unlocked by a user account with the 'Security > Administration' permission, or a user with the User Administrator role. In the Edit User Account dialog box, a user security administrator must clear the ‘Account is Locked’ checkbox.
Initial Password Reset
Objective: Ensure first-time users secure their accounts by changing initial passwords.
Policy:
- First Login: When a new user account is created, to access Capital applications, the account owner must first change their password in Capital Access Manager from the default password provided by the account creator. See Creating and Editing a User Account
Login Name, Email Address, or Password.
Validation: The system will
validate new passwords against required criteria.
Note
Changing your password in Capital Access Manager before accessing other Capital applications is applicable in all scenarios where a user administrator has been involved in a password change (first login, password expiration, forgotten password and reset password).
Audit Trail Login Failures
Objective: Audit trail logging helps track and record login activities to enhance security and support troubleshooting.
Policy:
- Logging: All login failures will be logged with details including the date, user id, and application within the audit trail. Invalid usernames are shown in the event description. Optionally, login successes can also be logged in the audit trail.
Two types of events are available in Capital Project Manager > System Preference > Audit Trail:
Login failed - Failed login attempts are always logged and cannot be disabled.
Login success - Successful login attempts are not logged by default. System administrator accounts can enable this setting if needed. Figure 17: Audit Trail Login Event Types
Note Enabling Login Success in the audit trail requires a Capital Manager restart to take effect.
Migration and Import Rules
Migrated accounts: After migration, all passwords will expire 90 days from the migration date (default).
Import Behavior:
New imported users: Follow your organization's configured password policy.
Existing imported users: Their current password settings are retained.
Existing user accounts will be able to log in until the configured expiry date. After expiry, they must adhere to the password policy guidelines.
Parent Topic:
User Accounts
Capital Access Manager User Guide, 2512.2606
Unpublished work. © 2026 Siemens
Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/rsi4364144355771 · retrieved 2026-07-18