NetSuite Password Policy Settings and PCI Rules
Configure NetSuite password policies, minimum length, expiration, PCI exceptions, and separate Customer Center password handling.
NetSuite password settings are configured at Setup > Company > General Preferences. The selected policy controls password length and character requirements, while separate fields set a longer minimum length and an expiration interval. PCI-related permissions can impose stricter requirements, and Customer Center passwords follow separate handling from non-customer center users.
What password policy levels are available?
NetSuite provides four built-in password validation levels. All NetSuite accounts are set to the Strong policy by default. Each level defines a minimum length and, except for Weak, a required number of character types.
| Policy level | Minimum length | Required character types |
|---|---|---|
| Very Strong | 10 characters | All four: uppercase letters, lowercase letters, numbers, and non-alphanumeric ASCII characters |
| Strong | 10 characters | At least three of the four character types |
| Medium | 8 characters | At least two of the four character types |
| Weak (Not Recommended) | 6 characters | No character-type requirement specified by the policy |
The selected policy determines the lowest value that can be used in the Minimum Password Length field. It does not determine the Password Expiration in Days value.
NetSuite permits a policy to be reset to Medium or Weak, but its documentation warns that moving to a less strict policy weakens account security. Before changing the policy, identify whether any users have permission to view unencrypted payment data. Those users can be subject to PCI requirements that take precedence over the account-level policy.
How does the Minimum Password Length field work?
The Minimum Password Length field sets the minimum number of characters required for user passwords. Its default comes from the selected password policy. Because Strong is the default policy, the default minimum password length is 10 characters.
Administrators can raise this field above the minimum required by the selected policy. They cannot lower it below that policy minimum. This separates the account's chosen validation level from its length requirement: a Strong policy can remain in place while the minimum length is set above 10 characters.
| Setting or user type | Documented minimum or behavior |
|---|---|
| Strong policy default | 10 characters |
| Very Strong policy | 10 characters and all four character types |
| Medium policy | 8 characters and at least two character types |
| Weak policy | 6 characters |
| Customer Center roles | 8-character minimum |
| Users with specified PCI-sensitive permissions | 12 characters, unless the company minimum is greater |
The Customer Center minimum is separate from the password-policy rules described for other NetSuite users. Administrators should not assume that changing the account-level policy or minimum length changes Customer Center password handling.
When do PCI requirements override account settings?
PCI requirements apply to users who have either of these permissions:
- View Unencrypted Credit Cards
- View Unencrypted ACH Account Numbers
For these users, passwords must have a minimum of 12 characters. If the value in Minimum Password Length is greater than 12, the greater company requirement remains in effect.
Password expiration is also constrained for these users. They must change passwords at least every 90 days. If Password Expiration in Days is set to fewer than 90 days, the shorter company requirement remains in effect. For example, a 60-day account setting stays at 60 days. If the account setting is greater than 90 days, such as 120 days, NetSuite changes the expiration interval to 90 days for users with either listed permission.
The presence of these permissions also affects decisions about lowering the password policy. NetSuite states that PCI password requirements take precedence when any users in the account have either permission. For further context on this distinction, see the PCI requirements.
How does password expiration work?
The Password Expiration in Days field specifies how many days a password remains valid before a user is prompted to change it. Valid values are 1 through 365, and the default value is 180 days.
Expiration is calculated from the date each user last changed their password, not from the date an administrator changes the company preference. Changing the field therefore does not restart every user's password age from the preference-change date.
Administrators can also prompt employees to change passwords at their next login by selecting Require Password Change on Next Login on employee records. CSV import can update this option on multiple employee records at the same time. This option is distinct from the expiration interval: it is used to prompt a change at the user's next login.
Users can review two relevant dates in the My login audit portlet:
- The date of the previous password change
- The current password expiration date
What happens when a user accesses multiple accounts?
A user who can access multiple NetSuite accounts with different password policies is subject to the strongest applicable policy. For this purpose, NetSuite defines a user as an email and password pairing.
This matters when reviewing a policy change in one account: a less strict policy in that account does not determine the effective policy for a user who also accesses another account with a stronger policy. The stronger policy is enforced for that user.
Do these policies apply to Customer Center users?
No. The account password policy is not applied to users who log in with a Customer Center role or to customers who register on a website.
Customer Center users are maintained separately from users with non-customer center roles. Employee, partner, and vendor roles are non-customer center roles. One person can use the same email address as the NetSuite username for both a non-customer center role and a Customer Center role, but NetSuite treats them as two different users because their information is maintained separately.
As a result, changing the password for a non-customer center role does not change the password for the Customer Center role. Customer Center roles have an eight-character minimum password length. This separation is important when responding to a user who appears to have the same email address in both role types.
For password-reset and authentication context, see Passwords and Two-Factor Authentication in NetSuite 2026.1.
How can users and administrators reset passwords?
In most cases, password changes are self-service. An employee, partner, or vendor can select Forgot Your Password? on the NetSuite login page. NetSuite sends an email containing a password-reset link, and that link expires after 60 minutes.
Administrators can use the User Access Reset Tool to assist users who cannot reset a password, update security questions, change a two-factor authentication device, or are locked out after five consecutive incorrect passwords. To change a user's password, an administrator must have access to every account that user can access.
The Require Password Change on Next Login option is also available on employee records and can be updated through CSV import for multiple records. For related configuration context, see General Account Preferences configuration. For separate integration authentication guidance, see Create Integration Records for OAuth 2.0 in NetSuite 2026.1.
Who This Affects
- Administrators: Configure the policy, minimum password length, expiration interval, and next-login password-change requirement.
- Employees, partners, and vendors: Use the non-customer center password process and may be subject to account policies, expiration prompts, and reset procedures.
- Users with payment-data permissions: Must meet the 12-character and at-least-every-90-days PCI requirements unless the company settings are stricter.
- Users with access to multiple accounts: Must meet the strongest password policy among those accounts.
- Customer Center users and website registrants: Are not governed by the account password policy; Customer Center users are maintained separately from non-customer center users.
Key Takeaways
- Configure password settings at Setup > Company > General Preferences.
- Strong is the default built-in policy, requiring at least 10 characters and three of four character types.
- Minimum Password Length can be raised above, but not lowered below, the selected policy's minimum.
- Password Expiration in Days accepts 1–365 days, defaults to 180, and is calculated from each user's last password change.
- PCI-sensitive permissions can require a 12-character minimum and password changes at least every 90 days.
- Customer Center passwords are separate from non-customer center passwords, even when the same email address is used.
Frequently Asked Questions (4)
Where do I configure NetSuite password policies, minimum length, and expiration?
Which permissions trigger PCI password requirements and what do those requirements enforce?
Can I set the Minimum Password Length lower than the selected policy's minimum or raise it above that minimum?
Do account-level password policies apply to Customer Center users and what are the implications?
Was this article helpful?
More in Authentication
- OpenID Connect (OIDC) Configuration in NetSuite
OpenID Connect (OIDC) enables secure access to NetSuite web stores, improving user security management.
- Single Sign-On Only Role Configuration in NetSuite
Configure Single Sign-On Only roles in NetSuite to ensure users can access accounts solely through OIDC SSO.
- Outbound Single Sign-on Deprecation and Alternatives in NetSuite
Outbound Single Sign-on (SuiteSignOn) is deprecated in NetSuite 2024.1, affecting authentication processes.
- Credentials File Management in NetSuite 2026.1
Manage credentials file errors in NetSuite 2026.1, ensuring proper permissions and passkey handling for smooth authentication.
Advertising
Reach Authentication Professionals
Put your product in front of NetSuite experts who work with Authentication every day.
Sponsor This Category