ANS-0851 · ROLES, PERMISSIONS & SECURITY
How to Manage Password Expiration for NetSuite Web Services Roles
Understand NetSuite's password expiration policies, including account-wide settings and specific role-based exceptions for compliance and security.
Short answer
NetSuite's password expiration is generally account-wide, configurable 1-365 days. Exceptions exist: PCI-related roles enforce a 90-day expiry, NSPOS allows role-specific settings, and Customer Center roles have no expiration. Account-wide settings are overridden by stricter role-based rules.
Scenario
Users often inquire about the flexibility of NetSuite's password expiration settings, particularly concerning Web Services (WS) roles. The primary question revolves around whether password expiry can be configured on a per-role or per-user basis, or if it is strictly an account-wide setting.
Solution
NetSuite's password expiration is primarily an account-wide preference. However, there are specific exceptions where password expiration rules are enforced by role or user. For instance, users with PCI-related permissions (e.g., 'View Unencrypted Credit Cards' or 'View Unencrypted ACH Account Numbers') are subject to a mandatory 90-day password expiration, overriding longer account-wide settings. NetSuite Point of Sale (NSPOS) also allows for configuring password requirements, including expiration, by role. Additionally, passwords for Customer Center roles do not expire. The 'Password Expiration in Days' field in NetSuite is limited to a range of 1 to 365 days. While the system allows up to 365 days, it is generally recommended to set a maximum of 180 days between password resets for enhanced security. A 90-day interval is required for PCI compliance for relevant roles.
Expert NetSuite Support
Need help with this NetSuite issue?
Roles, Permissions & Security consulting and configuration support
