Configuring Advanced Local User Account Features

Advanced features providing more control and security are available when configuring user accounts and their passwords.

The following features are configured in this task. All these features are disabled by default:

  • Password Length
  • Password Combination Rules
  • Password Aging
  • Password History
  • User Login Attempts
  • Password Expiration

All the steps are optional and can be entered in any order.

Note: A factory-default super user account is present on new devices. On first log-in, the password for the factory-default account must be changed. See the Configuring Local User Accounts task for more details on adding local users.
  1. Enter global configuration mode.
    device# configure terminal
  2. Enable password aging to force the user to provide a new password every three months.
    device(config)# enable user password-aging
    After 90 days the CLI automatically prompts the user for a new password.
  3. Enable a minimum number of characters and a required combination of characters to ensure secure passwords.
    device(config)# enable strict-password-enforcement
    When strict password enforcement is enabled, the password must be a minimum of 15 characters and must contain the following combinations:
    • At least two uppercase characters
    • At least two lowercase characters
    • At least two numeric characters
    • At least two special characters
    The strict password enforcement feature displays an error message when the password entered does not meet the criteria.
    Note: Strict password enforcement is configured globally. Only accounts and passwords configured after the feature is enabled are subject to the minimum password length requirement.
  4. Configure the device to store up to 15 previous passwords to prevent previous passwords from being used as a security measure.
    device(config)# enable user password-history 15
    An error message will display if a user attempts to use a previous password that is still stored.
  5. Configure the maximum number of invalid login attempts a user can make before being locked out to 8 with a 15 minute time period before the user account is automatically unlocked.
    device(config)# enable user disable-on-login-failure 8 login-recovery-time 15
    If the login-recovery-time option is not configured, manual intervention by an administrator is required to unlock the user account.
  6. Configure a user password to expire in 30 days.
    device(config)# username sandy expires 30
    Password expiration can be used for temporary user accounts.
  7. (Optional) Display user account information using the show users command.

The following example shows how to configure advanced local user account features to provide more secure user accounts and passwords, including password requirements imposed by the enable strict-password-enforcement command.

device# configure terminal
device(config)# enable strict-password-enforcement
device(config)# enable user password-aging
device(config)# enable user password-history 15
device(config)# enable user disable-on-login-failure 8 login-recovery-time 15
device(config)# username sandy expires 30