function readOnly(count){ }
Starting November 20, the site will be set to read-only. On December 4, 2023,
forum discussions will move to the Trailblazer Community.
+ Start a Discussion
Swagat.TusharSwagat.Tushar 

Locked customer portal is able to reset password

The customer portal user account is getting locked after 3 wrong password attempts. But when customer portal user perform the forgot password steps, he is able to receive a mail with temporary password and able to unlock the account.

 

This is not in case of internal salesforce user. Internal salesforce user can login only after Lockout effective period is over or the account is unlicked by a system admin. We want to implement same password policies for customer portal user too.

Sonam_SFDCSonam_SFDC

Hi Swagat,

 

I tested this on my DEV ORG and unfortunately I am not able to see this behavior.

 

Setting for the ORG:

Maximum invalid login attempts : 3

Lockout effective period: Forever(must be reset by Admin)

 

What happens for my Customer Portal user is the following:

When I hit the 3 password attempt limit and try to send myself a reset password email : Email doesn't come through and only the Admin is able to unlock my Portal account for me to login again.

 

Could you confirm if the above setting is similar in your ORG?

 

 

 

 

Swagat.TusharSwagat.Tushar

Hi Sonam,

 

our Org setting:

Maximum invalid login attempts : 3

Lockout effective period: 30 minutes