Password Policies

You can setup, modify, and implement password policies in the settings.

General Password Policy

Deltek works continuously to protect the security, privacy, and integrity of the data stored within each customer’s SaaS instance of Maconomy.

As a result, when a new customer environment is activated, Maconomy SaaS is configured with the following default password policies enabled as a minimum requirement:
  • Minimum Password Length: 8
  • Minimum Number of Letters: 1
  • Minimum Number of Digits: 1
  • Minimum Number of Special Characters: 1
  • Maximum Number of Character Repeats: 6
  • Validation Period in Number of Days: 90
  • Number of Passwords between Reuse: 8
  • Invalid logon attempts before user account locked: 3

While these password policies are the minimum requirement per our cloud service, it is possible to implement more stringent policies which will be changed in to the settings. For instance, if you would like to enforce passwords of 10-character length rather than 8, then this is your responsibility as SaaS Administrator.

Password Policies for Deltek Cloud AD Accounts

If any customer utilizes a Deltek Cloud AD account to log in directly as part of their cloud product (For example, for Implementer developers in Maconomy Enterprise Cloud), then there are specific password policies in effect to be aware of.

Passwords

Deltek Global Cloud must use secure Deltek Login credentials with strong and complex passwords. Passwords require rotation every 60 days. Passwords are protected during authentication and at rest by approved cryptography mechanisms. Prior to gaining access, two-factor authentication is required for every login interface and account for any cloud service and/or code repository.

Password Complexity

Deltek Global Cloud employs password complexity requirements as follows:
  • Passwords must be at least 15 characters in length
  • Passwords must contain at least once each of upper-case letters, lower-case letters, numbers and special character.
  • Previous ten passwords are not allowed
Additional Recommended Password Controls
  • Passwords should not be comprised of, or otherwise utilize, words that can be found in a dictionary
  • Passwords should not be comprised of an obvious keyboard sequence (i.e. qwerty)
  • Passwords should not include "guessable" data such as personal information about yourself, family members, birthdays, the current month, addresses, phone numbers, locations, etc.