Skip to main content

Strong Authentication for Every Account

Password Policies: Complexity Rules, MFA Enforcement & Account Lockout

Enforce password complexity requirements, rotation schedules, MFA enrollment, and account lockout rules. Protect every employee account with enterprise authentication controls.

Password Policies: Complexity Rules, MFA Enforcement & Account Lockout - Hirebee HRMS Feature

Password Policies

Password Complexity and Strength Requirements

Weak passwords are still one of the leading causes of account compromise. Hirebee's password policy engine lets administrators configure and enforce complexity requirements across the entire organization: minimum length, required character types (uppercase, lowercase, numbers, symbols), prohibition of common passwords, prohibition of passwords containing the employee's name or email address, and minimum strength scoring based on entropy calculation. Policies can be differentiated by role \u2014 administrator accounts face stricter complexity requirements than standard user accounts. When an employee sets or changes their password, the policy is validated in real time with clear feedback on what requirements haven't been met. Passwords that fail the policy cannot be saved, and the employee is guided to create one that meets the security standard.

Password Rotation and Expiration Schedules

Periodic password rotation reduces the window of exposure when credentials are compromised. Hirebee enforces configurable rotation schedules by role: standard users rotate every 90 days, privileged administrators every 30 days. Rotation reminders go out in advance of expiration \u2014 a reminder at 14 days, a warning at 7 days, and a forced change prompt at expiration. Password history enforcement prevents employees from cycling back to recently used passwords (configurable history depth: last 5, 10, or 20 passwords). For organizations that have adopted the NIST password guidance of not forcing periodic rotation for standard accounts but requiring immediate rotation on suspected compromise, Hirebee supports configuring rotation as optional for standard users while mandating it for privileged roles.

Multi-Factor Authentication Enforcement

Passwords alone are insufficient protection for systems containing sensitive employee data. Hirebee enforces MFA enrollment and usage at the organization, role, or individual level. Administrators configure which authentication factors are accepted: authenticator apps (TOTP), SMS codes, hardware security keys (FIDO2/WebAuthn), email OTP, or push notifications through apps like Duo or Okta Verify. MFA can be enforced for all logins, only for logins from unrecognized devices or locations, or only for access to sensitive modules like payroll and compensation data. Grace periods allow new employees to enroll MFA within a configured window before enforcement activates. Employees who lose access to their MFA device follow a secure recovery workflow that requires identity verification before bypassing MFA.

Account Lockout and Suspicious Login Protection

Brute-force attacks attempt to compromise accounts by trying thousands of password combinations automatically. Hirebee's account lockout policies stop these attacks by locking accounts after a configurable number of consecutive failed login attempts. Lockout duration is configurable: temporary lockout for 15 minutes, escalating lockout after repeated failures, or permanent lockout requiring administrator unlock. Suspicious login detection flags logins from new geographic locations, unfamiliar devices, or at unusual times and prompts step-up verification before granting access. Administrators receive alerts when accounts are locked due to repeated failures, enabling rapid investigation of potential credential stuffing or targeted attack attempts. All lockout events are logged in the security event trail for audit purposes.

Ready to see it in action?

Join 1,000+ companies using Hirebee. Start your free trial — no credit card required.