Password rotation helps improve account security. You can choose to disable it if you don’t want account users to be required to change their password every 90 days.
Password rotation doesn't apply to users logging in with Single Sign-On.
Learn more in Set up Single Sign-On (SSO) for your account.
Before you start
Things you need to know:
For top‑level accounts created after 8 November 2023, and their child accounts, password rotation is disabled by default.
For child accounts of parent accounts created before 8 November 2023, password rotation is enabled by default.
Password rotation is applied at account level.
If a user has access to multiple accounts and any of them have password rotation enabled, they may be prompted to change their password when signing in.To manage password rotation, you must be the account owner, or a managed user with the Can manage account permission.
Learn more in Restrict and grant user access permissions.
Password rotation behaviour
Password rotation is set at account level, but passwords are updated at user level.
Example
A user has access to three Dotdigital accounts:
Account A: password rotation disabled
Account B: password rotation disabled
Account C: password rotation enabled
If it’s been more than 90 days since the user last updated their password, they can continue to sign in to Accounts A and B without changing it.
The first time the user signs in to Account C after the 90‑day period, they’re prompted to update their password.
After the password is updated, the new password applies across all Dotdigital accounts the user can access.
Enable or disable password rotation
Expand the User menu and go to Settings > General > Account settings.
Under Security, select or clear the Password rotation checkbox to enable or disable the feature.
Select SAVE SETTINGS.
You can see the last date and time the password rotation setting was updated, and which user updated it.
This information is hidden if the setting has never been changed.
Notifications
When the password rotation setting is changed for an account, an email notification is sent to the account owner, and any managed users with the Can manage account permission enabled.
