This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
Folks,
Is it possible to have an internal user account (for T+ users) never expire AND to have the Users Password Policies in effect for the majority of the users (password expiration and account lockout durations)? I have a customer looking to have a few service accounts only that never expire and still use the password policies for the rest.
Solved! Go to Solution.
You have the option of modifying the User and Password policies globally for internal users but not per user.
Have a look under
Administration > Identity Management > Settings > User Authentication Settings
You have the option of modifying the User and Password policies globally for internal users but not per user.
Have a look under
Administration > Identity Management > Settings > User Authentication Settings
So the answer then is that when I am using the global policies, I cannot then do a permanent per user account. Correct?
You are correct pretty much. For ISE internal network access users, we may globally permit users not to expire and then set expired dates on individual user accounts as needed.
Please bring your feedback to our PM team.