Configuring Local User Account Features

The features providing more control and security are available when configuring user accounts and their passwords.

The following features are configured in this task. All these features are disabled by default:

  • Password Masking
  • Password Combination Rules
  • Password Aging
  • Password History
  • User Login Attempts
  • Password Expiration

After entering global configuration mode, all subsequent steps are optional and can be entered in any order.

  1. Enter global configuration mode.
    device# configure terminal
  2. Enable password aging to force the user to provide a new password every three months.
    device(config)# enable user password-aging
    After 90 days the CLI automatically prompts the user for a new password.
  3. Configure a user password to expire in 30 days.
    device(config)# username sandy expires 30
    Password expiration can be used for temporary user accounts.
  4. Enable a minimum number of characters and a required combination of characters to ensure secure passwords.
    device(config)# enable strict-password-enforcement
    Note: Strict password enforcement is configured globally. Only accounts and passwords configured after the feature is enabled are subject to the minimum password length requirement.
  5. Enable password masking to hide the password characters from the console display as they are entered using the CLI.
    device(config)# enable user password-masking
    When password masking is enabled, press the Enter key before entering the password, and enter the password when prompted.
  6. Configure the device to require a password be input when a user enters the enable command to access Privileged EXEC mode.
    device(config)# enable privilege-mode password TestPass123$
  7. Configure the device to store up to 15 previous passwords to prevent previous passwords from being reused as a security measure.
    device(config)# enable user password-history 15
  8. Configure the maximum number of invalid login attempts a user can make before being locked out to 8 with a 15-minute time period before the user account is automatically unlocked.
    device(config)# enable user disable-on-login-failure 8 login-recovery-time 15
  9. Display user account information using the show users command.