Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Maximize reset password request unlock window duration

The password_reset.request.unlock_window property controls the number of minutes a user must wait to start a reset request after the last successful unlock account action.

The password_reset.request.unlock_window system property controls the number of minutes a user must wait to start a reset request after the last successful unlock account.

Ensure the property password_reset.request.unlock_window is set to a value of 1440 or greater.

More information

AttributeDescription
Configuration namepassword_reset.request.unlock_window
Configuration typeSystem Properties \(/sys\_properties\_list.do\)
Data typeInteger
Recommended valueAn integer greater than or equal to 1440
Default value<none>
Fallback value1440
CategoryAuthentication
Security risk- Severity score: 5.9 - CVSS rating: Medium - Security risk details: If the value is too low, it increases the opportunity for a malicious actor from brute forcing the user's password using automated tools.
Functional impactNone
Dependencies and prerequisitesNone

Parent Topic:Authentication