NetSuite Password Expiration Settings and PCI Rules

Set Password Expiration in Days, prompt employee password changes at next login, and apply PCI rules for unencrypted-data access.

·7 min read·1 views·View Oracle Docs

Password Expiration in Days sets how long a password remains valid before NetSuite prompts a user to change it. Configure the field at Setup > Company > General Preferences. Values run from 1 to 365 days, with a default of 180. PCI rules can impose a 90-day maximum for users with specified unencrypted-data permissions.

Where Do You Set Password Expiration?

Administrators can modify password settings at Setup > Company > General Preferences. The available settings discussed here are related but serve different purposes:

SettingWhat it controls
Password PolicyPassword length and character-content requirements for NetSuite users
Minimum Password LengthThe minimum number of characters required for user passwords
Password Expiration in DaysHow many days a password remains valid before the user is prompted to change it

The selected password policy does not affect the value in Password Expiration in Days. Set the expiration interval independently of the password-policy level, subject to the PCI rules that apply to certain users.

How Does Password Expiration in Days Work?

Password Expiration in Days is the number of days a password is valid before a user is prompted to change it. The valid range is 1 through 365 days, and the default value is 180 days.

The calculation is based on the date on which each user last changed their password. It is not calculated from the date on which the company preference was changed. This distinction matters when an administrator updates the company-level value: the documented calculation point remains each user's most recent password change date.

Users can view the date of their previous password change and their current password-expiration date in the My login audit portlet.

How Can You Prompt Employees to Change Passwords?

Changing the company preference is not the only available action. To prompt employees to change their passwords at their next login, select Require Password Change on Next Login on employee records.

For a larger employee group, CSV import can update this option on more employee records at the same time. This gives administrators a record-level method for prompting a password change without relying only on the expiration interval.

ActionDocumented method
Set the company password-validity intervalUpdate Password Expiration in Days at Setup > Company > General Preferences
Prompt one employee to change a password at next loginSelect Require Password Change on Next Login on the employee record
Prompt more employees at onceUse CSV import to update Require Password Change on Next Login

Which PCI Rules Override the Company Setting?

Users with either of the following permissions must change their passwords at least every 90 days:

  • View Unencrypted Credit Cards
  • View Unencrypted ACH Account Numbers

If Password Expiration in Days is set to fewer than 90 days, the shorter company requirement remains in effect for those users. For example, a 60-day company setting does not change their expiration date.

If the company setting is longer than 90 days, NetSuite automatically changes the setting to 90 days for users with either permission. For example, a company value of 120 days becomes a 90-day expiration requirement for these users.

PCI requirements also affect password length. Passwords for users with access to unencrypted credit card numbers or unencrypted ACH accounts must contain at least 12 characters. If the value set in Minimum Password Length is greater than 12, the greater requirement remains in effect. All users with this access must change passwords to comply with the PCI requirements.

For related configuration detail, see NetSuite Password Policy Settings and PCI Rules and NetSuite Minimum Password Length and PCI Rules.

How Do Password Policy and Expiration Differ?

Password policy validates password length and content; password expiration determines when a password is due for a change. The password-policy selection determines the minimum acceptable value for Minimum Password Length, but it does not affect Password Expiration in Days.

All NetSuite accounts are set to the Strong policy by default. The built-in policies are:

PolicyMinimum lengthCharacter-type requirement
Very strong10 charactersAll four: uppercase letters, lowercase letters, numbers, and non-alphanumeric ASCII characters
Strong10 charactersAt least three of the four character types
Medium8 charactersAt least two of the four character types
Weak (Not Recommended)6 charactersNo additional character-type requirement stated

You can increase Minimum Password Length above the minimum required by the selected policy, but you cannot set it below that policy minimum. Although a policy can be reset to Medium or Weak, NetSuite states that moving to a less strict policy weakens account security.

If a user accesses multiple NetSuite accounts with different password policies, the strongest policy is enforced for that user. For this purpose, a user is defined as an email and password pairing. This rule concerns password policy; the source does not state an equivalent cross-account rule for password-expiration values.

What Should You Know About Customer Center Roles?

The password policy is not applied to users who log in with a Customer Center role or to customers who register on a website. Customer Center password handling also differs from non-customer-center roles.

Employee, partner, and vendor roles are non-customer-center roles. A person can use the same email address for both a non-customer-center role and a Customer Center role, but NetSuite treats them as two different users because the information is maintained separately. Changing the password for non-customer-center roles does not affect the password for the Customer Center role.

The documented minimum password length for Customer Center roles is eight characters.

What Should You Review Before Changing the Setting?

Use the following source-based checks when reviewing password-expiration configuration:

  • Confirm that Password Expiration in Days is within the permitted 1–365-day range.
  • Remember that the expiration calculation is tied to each user's last password change, not the date the company preference changes.
  • Identify users with View Unencrypted Credit Cards or View Unencrypted ACH Account Numbers permissions, because their password expiration cannot exceed 90 days.
  • Confirm that password length for those users meets the 12-character PCI minimum, unless the company has set a higher Minimum Password Length.
  • Use Require Password Change on Next Login on employee records when employees should be prompted to change passwords at their next login, and use CSV import when updating more employee records.
  • Keep Customer Center users distinct from employee, partner, and vendor users when reviewing password behavior for the same email address.

Who This Affects

  • Administrators who modify password settings at Setup > Company > General Preferences or update employee records.
  • Employees whose passwords expire based on their last password-change date or who are marked to change passwords at next login.
  • Users with access to unencrypted credit card numbers or unencrypted ACH account numbers, who are subject to the PCI 90-day and 12-character requirements.
  • Employees, partners, and vendors using non-customer-center roles.
  • Customer Center users and website registrants, for whom the documented password-policy treatment differs from standard NetSuite users.
  • Users with access to multiple NetSuite accounts, where NetSuite enforces the strongest applicable password policy.

Key Takeaways

  • Configure Password Expiration in Days at Setup > Company > General Preferences.
  • The field accepts values from 1 to 365 days and defaults to 180 days.
  • Expiration is calculated from the date each user last changed their password.
  • Select Require Password Change on Next Login on employee records, or use CSV import to update that option for more employees.
  • Users with specified unencrypted credit card or ACH permissions must change passwords at least every 90 days; a shorter company interval still applies.
  • Password policy, minimum password length, and password expiration are separate settings, though PCI requirements can override the ordinary expiration and length thresholds.
  • Customer Center roles are handled separately from non-customer-center roles for the documented password-policy and password-maintenance behavior.

Frequently Asked Questions (4)

If I change the company Password Expiration in Days, does that immediately reset every user’s expiration date?
No. Expiration is calculated from each user’s most recent password-change date, not from the date the company preference is changed. Users can view their last password-change date and current expiration in the My login audit portlet.
Does changing the account Password Policy alter the Password Expiration in Days value?
No. Password Policy controls length and character-content requirements and sets the minimum for Minimum Password Length, but it does not affect the Password Expiration in Days. You must set the expiration interval independently, subject to any applicable PCI rules.
How can I force users to change passwords at their next login for one or many employees?
For a single employee, select Require Password Change on Next Login on the employee record. To prompt a larger group, update that same employee-field across records using a CSV import.
Which permissions trigger the PCI overrides and what password requirements do they impose?
Users with either View Unencrypted Credit Cards or View Unencrypted ACH Account Numbers must change passwords at least every 90 days. If the company setting is under 90 days, that shorter interval still applies; if the company setting is above 90 days, NetSuite enforces a 90-day expiration for those users. In addition, those users’ passwords must contain at least 12 characters unless the account’s Minimum Password Length is set higher.
Source: Password Expiration in Days Field Oracle NetSuite Help Center. This article was generated from official Oracle documentation and enriched with additional context and best practices.

Was this article helpful?

More in Authentication

View all Authentication articles →