NetSuite Password Policy Settings and PCI Rules

Configure NetSuite password policies, minimum length, expiration, PCI exceptions, and separate Customer Center password handling.

·7 min read·View Oracle Docs

NetSuite password settings are configured at Setup > Company > General Preferences. The selected policy controls password length and character requirements, while separate fields set a longer minimum length and an expiration interval. PCI-related permissions can impose stricter requirements, and Customer Center passwords follow separate handling from non-customer center users.

What password policy levels are available?

NetSuite provides four built-in password validation levels. All NetSuite accounts are set to the Strong policy by default. Each level defines a minimum length and, except for Weak, a required number of character types.

Policy levelMinimum lengthRequired character types
Very Strong10 charactersAll four: uppercase letters, lowercase letters, numbers, and non-alphanumeric ASCII characters
Strong10 charactersAt least three of the four character types
Medium8 charactersAt least two of the four character types
Weak (Not Recommended)6 charactersNo character-type requirement specified by the policy

The selected policy determines the lowest value that can be used in the Minimum Password Length field. It does not determine the Password Expiration in Days value.

NetSuite permits a policy to be reset to Medium or Weak, but its documentation warns that moving to a less strict policy weakens account security. Before changing the policy, identify whether any users have permission to view unencrypted payment data. Those users can be subject to PCI requirements that take precedence over the account-level policy.

How does the Minimum Password Length field work?

The Minimum Password Length field sets the minimum number of characters required for user passwords. Its default comes from the selected password policy. Because Strong is the default policy, the default minimum password length is 10 characters.

Administrators can raise this field above the minimum required by the selected policy. They cannot lower it below that policy minimum. This separates the account's chosen validation level from its length requirement: a Strong policy can remain in place while the minimum length is set above 10 characters.

Setting or user typeDocumented minimum or behavior
Strong policy default10 characters
Very Strong policy10 characters and all four character types
Medium policy8 characters and at least two character types
Weak policy6 characters
Customer Center roles8-character minimum
Users with specified PCI-sensitive permissions12 characters, unless the company minimum is greater

The Customer Center minimum is separate from the password-policy rules described for other NetSuite users. Administrators should not assume that changing the account-level policy or minimum length changes Customer Center password handling.

When do PCI requirements override account settings?

PCI requirements apply to users who have either of these permissions:

  • View Unencrypted Credit Cards
  • View Unencrypted ACH Account Numbers

For these users, passwords must have a minimum of 12 characters. If the value in Minimum Password Length is greater than 12, the greater company requirement remains in effect.

Password expiration is also constrained for these users. They must change passwords at least every 90 days. If Password Expiration in Days is set to fewer than 90 days, the shorter company requirement remains in effect. For example, a 60-day account setting stays at 60 days. If the account setting is greater than 90 days, such as 120 days, NetSuite changes the expiration interval to 90 days for users with either listed permission.

The presence of these permissions also affects decisions about lowering the password policy. NetSuite states that PCI password requirements take precedence when any users in the account have either permission. For further context on this distinction, see the PCI requirements.

How does password expiration work?

The Password Expiration in Days field specifies how many days a password remains valid before a user is prompted to change it. Valid values are 1 through 365, and the default value is 180 days.

Expiration is calculated from the date each user last changed their password, not from the date an administrator changes the company preference. Changing the field therefore does not restart every user's password age from the preference-change date.

Administrators can also prompt employees to change passwords at their next login by selecting Require Password Change on Next Login on employee records. CSV import can update this option on multiple employee records at the same time. This option is distinct from the expiration interval: it is used to prompt a change at the user's next login.

Users can review two relevant dates in the My login audit portlet:

  • The date of the previous password change
  • The current password expiration date

What happens when a user accesses multiple accounts?

A user who can access multiple NetSuite accounts with different password policies is subject to the strongest applicable policy. For this purpose, NetSuite defines a user as an email and password pairing.

This matters when reviewing a policy change in one account: a less strict policy in that account does not determine the effective policy for a user who also accesses another account with a stronger policy. The stronger policy is enforced for that user.

Do these policies apply to Customer Center users?

No. The account password policy is not applied to users who log in with a Customer Center role or to customers who register on a website.

Customer Center users are maintained separately from users with non-customer center roles. Employee, partner, and vendor roles are non-customer center roles. One person can use the same email address as the NetSuite username for both a non-customer center role and a Customer Center role, but NetSuite treats them as two different users because their information is maintained separately.

As a result, changing the password for a non-customer center role does not change the password for the Customer Center role. Customer Center roles have an eight-character minimum password length. This separation is important when responding to a user who appears to have the same email address in both role types.

For password-reset and authentication context, see Passwords and Two-Factor Authentication in NetSuite 2026.1.

How can users and administrators reset passwords?

In most cases, password changes are self-service. An employee, partner, or vendor can select Forgot Your Password? on the NetSuite login page. NetSuite sends an email containing a password-reset link, and that link expires after 60 minutes.

Administrators can use the User Access Reset Tool to assist users who cannot reset a password, update security questions, change a two-factor authentication device, or are locked out after five consecutive incorrect passwords. To change a user's password, an administrator must have access to every account that user can access.

The Require Password Change on Next Login option is also available on employee records and can be updated through CSV import for multiple records. For related configuration context, see General Account Preferences configuration. For separate integration authentication guidance, see Create Integration Records for OAuth 2.0 in NetSuite 2026.1.

Who This Affects

  • Administrators: Configure the policy, minimum password length, expiration interval, and next-login password-change requirement.
  • Employees, partners, and vendors: Use the non-customer center password process and may be subject to account policies, expiration prompts, and reset procedures.
  • Users with payment-data permissions: Must meet the 12-character and at-least-every-90-days PCI requirements unless the company settings are stricter.
  • Users with access to multiple accounts: Must meet the strongest password policy among those accounts.
  • Customer Center users and website registrants: Are not governed by the account password policy; Customer Center users are maintained separately from non-customer center users.

Key Takeaways

  • Configure password settings at Setup > Company > General Preferences.
  • Strong is the default built-in policy, requiring at least 10 characters and three of four character types.
  • Minimum Password Length can be raised above, but not lowered below, the selected policy's minimum.
  • Password Expiration in Days accepts 1–365 days, defaults to 180, and is calculated from each user's last password change.
  • PCI-sensitive permissions can require a 12-character minimum and password changes at least every 90 days.
  • Customer Center passwords are separate from non-customer center passwords, even when the same email address is used.

Frequently Asked Questions (4)

Where do I configure NetSuite password policies, minimum length, and expiration?
Configure password settings at Setup > Company > General Preferences. The selected policy controls required character types and the policy's minimum length, while the Minimum Password Length and Password Expiration in Days fields set the account's length and expiration interval independently. Strong is the default policy and the default minimum length is 10 characters.
Which permissions trigger PCI password requirements and what do those requirements enforce?
PCI requirements apply to users with either the View Unencrypted Credit Cards or View Unencrypted ACH Account Numbers permission. Those users must use passwords of at least 12 characters (unless the company minimum is greater) and must change passwords at least every 90 days; if the account expiration is less than 90 days that shorter interval remains, and if the account expiration is greater than 90 days NetSuite enforces a 90-day interval for those users.
Can I set the Minimum Password Length lower than the selected policy's minimum or raise it above that minimum?
You cannot lower the Minimum Password Length below the selected policy's minimum, but administrators can raise it above that minimum. The selected policy determines the lowest value permitted in the Minimum Password Length field (for example, Strong sets a 10-character minimum by default).
Do account-level password policies apply to Customer Center users and what are the implications?
No — the account password policy does not apply to Customer Center roles or website registrants. Customer Center users are maintained separately, have an eight-character minimum, and a non-customer center password change does not change a Customer Center password even if the same email address is used for both roles.
Source: Password Policy Oracle NetSuite Help Center. This article was generated from official Oracle documentation and enriched with additional context and best practices.

Was this article helpful?

More in Authentication

View all Authentication articles →