Account Advanced Features

Advanced features can be enabled from either the COS or the Account.  The account inherits the COS features, but accounts can override the COS feature configurations.

The advanced features are listed below.

Feature

Description

Disable attachment viewing from Webmail UI

If checked, attachments cannot be viewed. This can also be set as a global setting.

 

 

 

 

 

 

 

 

Account quota

Mailbox size limit in megabytes (MB). This is the assigned limit of disk space an account can use on the mailbox server. When the mailbox reaches the assigned limit, messages cannot be delivered. The default is 0, which means unlimited. This means users could use all the disk space on the server.

Address book size limit

The maximum number of entries a user can have in their personal contacts list. The default is 0 (no limit).

 

  • The password settings in Advanced do not effect the passwords set by users in domains that are configured to use external authentication.

Minimum password length

Maximum password length

This specifies the required length of a password. The minimum length is 6 characters. The maximum length is 64 characters.

Minimum password age

Maximum password age

Configuring a minimum and maximum password age sets the password expiration date. Users can change their passwords at any time between the minimum and maximum set. they must change it when the maximum password age is reached.

  • Minimum number of days a password must remain unchanged before it can be changed. The default is 0 (no limit).

  • Maximum number of days that can elapse before users are  forced to change their password. The default is 0 (no limit).

 

  • Configuring the next settings will require users to create more complex passwords

Minimum upper case characters

Upper case A - Z

Minimum lower case characters

Lower case a - z

Minimum punctuation symbols

Non-alphanumeric, for example !, $, #, %

Minimum numeric characters

Base 10 digits 0 - 9

Minimum number of unique passwords history

Number of unique new passwords that a user must create before he can reuse an old password.  The default is 0 (no limit).

 

Password locked

 

If this is enabled, users cannot change their password.  This should be enabled, if the authentication is external.

Email message lifetime

Number of days an email can remain in any folder before it is automatically purged. The default is 0, email messages are not deleted.

Trashed message lifetime

Number of days an email can remain in the trash folder before it is automatically purged. The default is 30 days.

Spam message lifetime

Number of days an email can remain in the Junk folder before it is automatically purged. The default is 30 days.

Auth token lifetime

This feature sets how long an auth token is valid for. The default is 2 days. If users check "remember me" on the log on page, when they quit their browser they will not have to log on again until the time expires or the session is timed out.

Session idle timeout

This sets how long a user session remains active if no activity occurs on the email client. Activity includes any clickable mouse action, such as viewing contents or folder or clicking a button.

 

  • The following settings set up your failed login policy

Enabled failed login lockout

When this box is checked, the "failed login lockout" feature is enabled and you can configure the following settings.

Number of consecutive failed logins allowed.

The number of failed login attempts before the account is locked out. the default s 10 attempts. If this is set to 0, an unlimited number of failed login attempts are allowed. This means the account is never locked out.

Time to lockout the account

The amount of time in seconds, minutes, hours, or days the account is locked out. If this is set to 0, the account is locked out until the correct password is entered, or the administrator manually changes the account status and creates a new password. The default is 1 hour.

Time window in which the failed logins must occur within to lock the account

The duration of time in seconds, minutes, hours, or days after which the number of consecutive failed login attempts is cleared from the log. The default is 0, the user can continue attempts to authenticate, no matter how many consecutive failed login attempts have occurred.