Authentication settings
You can use different authentication methods for your organization depending on your needs. You can also reset your authentication settings as necessary.
Password policy
For users on the Command Platform, you can select a default password policy or create a custom one.
Default password policy
The default Command Platform password policy requires that all passwords meet these formatting rules:
- Minimum of 8 characters
- At least 1 uppercase (
A-Z) character - At least 1 lowercase (
a-z) character - At least 1 number (
0-9) - Must not contain any part of the user’s Rapid7 account email address
Options for custom password policies
If you prefer to enforce a custom password policy for your Command Platform users, these configuration options are available:
- Minimum password length:
- 12 characters
- 16 characters
- New passwords cannot be the same as the user’s previous…
- 5 passwords
- 12 passwords
- Do not enforce this
- Passwords expire after…
- 90 days
- 365 days
- Never
Reset authentication
If a user loses access to their MFA device, forgets their password, or cannot sign in through single sign-on (SSO), you can reset their authentication settings to allow them to reconfigure their credentials.
To reset a user’s authentication:
- From Command Home, go to Administration > Users.
- Select a user in the Users table.
- Select Reset MFA or Reset Password.
A confirmation banner indicates that the user’s MFA or password has been reset. The user receives an email with instructions for reconfiguring their MFA options.