GoldFinch runs on the Salesforce platform, so Salesforce controls password strength, expiration, and login lockout through native Password Policies rather than anything GoldFinch-specific. This article covers what you can configure and where to set it.
What you can configure
Password complexity, length & history
Your Salesforce admin can set:
- Minimum password length
- Complexity requirements (e.g., requiring a mix of letters, numbers, and special characters)
- Password history — how many previous passwords a user can't reuse
These are all set in Setup → Password Policies.
Periodic password expiration
Password rotation can be enforced on a defined schedule — commonly every 30, 60, or 90 days — also configured by your Salesforce admin in Password Policies. If you're using SSO for some or all users, note that expiration policies apply to Salesforce-managed passwords; your identity provider governs rotation for federated logins instead.
Login lockout after failed attempts
Salesforce can lock an account after a defined number of consecutive failed login attempts. This threshold is configurable — commonly set anywhere from 3 to 10 attempts — and is set alongside your other login policies in Setup.
Where to configure these
| Setting | Location |
|---|---|
| Password complexity, length, history | Setup → Security → Password Policies |
| Password expiration schedule | Setup → Security → Password Policies |
| Login lockout threshold & duration | Setup → Security → Password Policies |
| SSO-based password behavior | Your identity provider's configuration |
A note on scope
These are org-level Salesforce settings, not something GoldFinch enables or restricts on its own — your Salesforce admin has full control to set thresholds that match your organization's security requirements or a specific compliance obligation (e.g., a funder or security questionnaire may specify a minimum length or lockout threshold).
Comments
0 comments
Please sign in to leave a comment.