Suggested answer

Password policies (Setup > Password Policies) control:

1. Minimum password length: Salesforce recommends at least 12 characters.
2. Complexity requirements: Must include uppercase, lowercase, numbers, and special characters.
3. Password expiry: Force password reset after 30/60/90 days or never.
4. Password history: Prevent reuse of last N passwords (up to 24).
5. Maximum invalid login attempts: Lock the account after N failed attempts.
6. Lockout period: Duration before the account automatically unlocks.
7. Obscure secret answer: Mask the security question answer. Best practices: longer passwords with complexity, 90-day expiry, lock after 3–5 attempts, enforce MFA alongside password policy. Password policies are set at the org level but can be overridden per profile.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.