ANS-1125 · ROLES, PERMISSIONS & SECURITY
How to Manage Password Expiration for NetSuite Web Service Roles?
NetSuite password expiration is an account-wide preference, but specific roles and compliance standards introduce important exceptions.
Short answer
NetSuite password expiration is an account-wide preference, but specific overrides apply for PCI-compliant roles (90 days), Customer Center roles (no expiration), and NSPOS roles. The 'Password Expiration in Days' field is limited to 1-365 days, with a general recommendation not to exceed 180 days for security best practices.
Scenario
Users often inquire about the ability to set distinct password expiration policies for specific NetSuite roles, such as those used for web services integrations. The concern arises from the need to manage security requirements that may vary by role or compliance standard, questioning if the account-wide preference can be overridden.
Solution
NetSuite's password expiration policy is primarily configured as an account-wide preference. While the general setting applies broadly, specific overrides exist for certain role types and compliance standards.NetSuite's password expiration policy is primarily configured as an account-wide preference. While the general setting applies broadly, specific overrides exist for certain role types and compliance standards. Account-Wide Preference: The default password expiration is set at the account level. PCI Compliance: Roles requiring PCI compliance automatically enforce a 90-day password expiration interval, overriding the account-wide setting. Customer Center Roles: Passwords for Customer Center roles do not expire. NetSuite Point of Sale (NSPOS): NSPOS allows for role-specific password policy configuration, providing more granular control for these roles. The 'Password Expiration in Days' field, which controls this setting, is limited to a range of 1 to 365 days. Although the system permits up to 365 days, it is a best practice recommendation to set password resets at a maximum of 180 days for improved security. For roles subject to PCI compliance, a 90-day interval is mandatory.
Expert NetSuite Support
Need help with this NetSuite issue?
Roles, Permissions & Security consulting and configuration support
