Skip to main content
Question

How to set Maximum Password Age setting

  • June 10, 2026
  • 3 replies
  • 30 views

Hello Team,

We are looking for setting configuration for Maximum Password Age and Minimum Password Age to be set in Configuration > Role Based Access > Local Account Settings > Account Password.

I don't see that option field for version BeyondTrust Password Safe 25.1 version. Can someone help to know how to see these fields in configuration part.

Thanks,

Prasad

3 replies

Prudhvi Keertipati
Forum|alt.badge.img+3

@prasadp87 Local account settings or password policy for BeyondInsight local accounts doesn't have minimum or maximum age, you can only set the password complexity and password history.


  • Author
  • Trailblazer
  • June 11, 2026

Hi ​@Prudhvi Keertipati ,

 

I just had confirmation from Beyond Trust support, this feature was visible earlier, but they have removed from 23.3.0

 

https://docs.beyondtrust.com/bips/changelog/beyondinsight-23-3-0

Removed the Minimum Password Age and Maximum Password Age options from the Configuration > Role Based Access > Local Account Settings page in BeyondInsight. Guidance from experts in the field indicates that these settings no longer offer significant value.


Forum|alt.badge.img+2
  • BeyondTrust Employee
  • June 12, 2026

Couple of bits of information that can help understand the justification for that change-  

Minimum Password Age: 
Password Changes versus Password Resets- Password Safe utilizes the Functional Account to perform a Password RESET. This is not the same thing as a Password CHANGE.
Reset is an administrative change, whereas a change is considered a user level action. There is typically no limit to Administrative Resets. Password Safe is performing a Password Reset by default.

Maximum Password Age: 
Selection criteria can be specified to target accounts based on a Password Age.
See Managed Account Smart Rules> Selection Criteria>
User Account Attributes: Password Age
Managed Account Fields: Last Change Date 

What that means, how to use this information: 
Password Change/Reset behavior can currently be changed by selecting the option to “Use Current Password to Change Password” on the Managed Account. This option would be the same as a user changing their own password and will be subject to a minimum password age policy. Be careful with this, it may cause you to fail to rotate passwords that have not met the minimum age requirement.

Additionally, when “Automatic Password Management” is enabled and the Change Password Frequency is designated, the password will be rotated on that interval regardless of other password change/reset activity before that period of time has been reached. So 30 day rotation + change on release= password is updated every time I use the account AND every 30 days regardless of how many changes during that 30 day period.