Skip to main content

Setting up the ObservePoint Password

A quick guide on how to set up a strong and secure password for ObservePoint users

Written by Luiza Gircoveanu

Overview

Maintaining robust password standards is our first line of defense against unauthorized access. This policy outlines the specific requirements for creating and resetting application user passwords to ensure the integrity of our systems and user data.

Recommended steps on how to set up your ObservePoint password

1. Password Complexity Standards

All new passwords must satisfy the following four complexity requirements:

  • Minimum Length: Passwords must be at least 8 characters long.

  • Character Variety:

    • Uppercase: Must contain at least one uppercase letter ([A-Z]).

    • Lowercase: Must contain at least one lowercase letter ([a-z]).

    • Numbers or Symbols: Must contain at least one numeric digit (\d) or a special character/symbol (\W).

2. Strength and Predictability

To prevent "brute-force" or "dictionary" attacks, passwords must not be common.

  • The system will automatically reject passwords that trigger a security warning.

  • This includes easily guessable patterns (e.g., "Password123"), common dictionary words, or sequential character strings.

3. Password Reset & Rotation Rules

When a user updates or resets their password, the following historical checks are enforced:

  • No Current Reuse: The new password cannot be identical to the password currently in use.

  • 12-Month History: To prevent users from cycling between two familiar passwords, the system will reject any password used within the past 12 months.

Best Practices for Users

While the system enforces the technical rules above, we recommend users follow these additional guidelines:

  • Use Passphrases: Longer strings of random words are often easier to remember but harder for machines to crack.

  • Avoid Personal Info: Do not use names, birthdays, or pet names that can be found on social media.

  • Unique Credentials: Never reuse a password from a personal account (like social media or personal email) for this application.

Conclusion

Adhering to these password standards is a shared responsibility essential to safeguarding our application's ecosystem. By enforcing a combination of complexity, unpredictability, and historical uniqueness, we significantly reduce the risk of credential compromise and ensure a secure environment for all users

Did this answer your question?