Configuring Advanced Local User Account Features

Advanced features providing more control and security are available when configuring user accounts and their passwords.

The following features are configured in this task. All these features are disabled by default:

  • Password Length
  • Password Combination Rules
  • Password Masking
  • Password Aging
  • Password History
  • User Login Attempts
  • Password Expiration

All the steps are optional and can be entered in any order. The password length is superceded by the password combination rules if you configure both steps.

Note: On a new device, you must first create a user with Super User privileges. See the Configuring Local User Accounts task for more details.
  1. Enter global configuration mode.
    device# configure terminal
  2. Enable a minimum password length.
    device(config)# enable password-min-length
    By default, no minimum length is specified for a password. The minimum length can be set to a value from 1 through 48.
  3. Enable a minimum number of, and combination of, characters to ensure secure passwords.
    device(config)# enable strict-password-enforcement
    The strict password enforcement feature displays an error message when the password entered does not meet the criteria.
  4. Enable password masking to hide the password characters from the console display as they are entered using the CLI.
    device(config)# enable user password-masking
    When password masking is enabled, press the Enter key before entering the password, and enter the password when prompted.
  5. Enable password aging to force the user to provide a new password every three months.
    device(config)# enable user password-aging
    After 90 days the CLI automatically prompts the user for a new password.
  6. Configure the device to store up to 15 previous passwords to prevent previous passwords from being used as a security measure.
    device(config)# enable user password-history 15
    An error message will display if a user attempts to use a previous password that is still stored.
  7. Configure the maximum number of invalid login attempts a user can make before being locked out to 8 with a 15 minute time period before the user account is automatically unlocked.
    device(config)# enable user disable-on-login-failure 8 login-recovery-time 15
    If the login-recovery-time option is not configured, manual intervention by an administrator is required to unlock the user account.
  8. Configure a user password to expire in 30 days.
    device(config)# username sandy expires 20
    Password expiration can be used for temporary user accounts.
  9. Display user account information using the show users command.
    device(config)# show users

The following example shows how to configure advanced local user account features to provide more secure user accounts and passwords. The password length example is not shown because it is superceded by the enable strict-password-enforcement command.

device# configure terminal
device(config)# enable strict-password-enforcement
device(config)# enable user password-masking
device(config)# enable user password-aging
device(config)# enable user password-history 15
device(config)# enable user disable-on-login-failure 8 login-recovery-time 15
device(config)# username sandy expires 20