Why this matters
EyeQuestion environments rely on password policies to maintain secure access for both internal users and external panellists. Defining strong password requirements helps prevent unauthorized access and ensures compliance with security standards, including GDPR. This guide explains how to view and understand your password policy.
User vs. Panellist
A User refers to someone with access to the EyeQuestion software backend, somebody who can create questionnaires, export data, edit panellists, such as project managers. A Panellist is someone who participates in studies by responding to surveys. These groups may have different security requirements, which is why password settings can be customized separately.
Where to find the Password Policy in EQ
The password policy defines the requirements for creating a secure password and allows for customization of these settings.
You can view the password policy of your environment here: Administration > System Settings > Password policy
Password settings can be configured independently for panellists and users, depending on your organization’s security needs.
As you can see in the screenshot below, you can adjust a lot of different specifics to create a valid password.
Explanation of the Password Policy Settings Possibilities
Minimal Length : Set up the minimal length of characters for a valid password.
Maximum Length : Set up the maximum length of characters for a valid password.
Not the same as last password : New password must not be the same as the last.
Does not contain username : Password cannot contain user name.
Forced upper and lower case : Enable / Disable forced lower and upper case characters.
Minimal numerical characters : Set up the minimum amount of numerical characters needed for a password.
Minimal special characters : Set up the minimum amount of special characters needed for a password.
Max password date : Maximum time of validity of password (in days). E.g. 180 means, that the password needs to be changed after 180 days to still be able to login. If it is set on 0, the password will be valid indefinitely, so no forced change request will occur.
Max failed attempts : Maximum amount of failed attempts before user/panellist is blocked.
Password History Amount : Amount of times a user can use the same password. (If it is set to 0, then all passwords need to be unique. You can never use exactly the same password which has been used at some point before.)
Note on Access to the Password Policy Settings
Project Managers have read-only access to the password policy settings and cannot make any changes. Only the System Manager has the authority to modify the password policy.
For SaaS clients, EyeQuestion Support is the designated System Manager. If you would like to request a change to your password policy, please contact our support team at support@eyequestion.nl.
Please note that, in accordance with security and data protection regulations (such as GDPR), changes can only be made upon receipt of a completed authorization form, provided by EyeQuestion, and signed by your company’s designated Primary User.
Note for on-premise clients: It is currently possible to assign a System Manager other than EyeQuestion Support.