Search Results :

×

How to Install and Configure Magento Password Policy Manager?

miniOrange Password Policy Manager for Magento helps store owners eliminate weak and reused passwords across their store by enforcing configurable password strength rules on every account creation, login, and password reset for both admin users and store customers with full visibility through flagged account tracking and audit logging.
The extension lets you define Magento password policies with requirements for password length, uppercase and lowercase characters, numbers, and special characters. Store administrators can apply customized password rules to both admin and customer accounts based on their security needs. With configurable password expiration, password history, and account security policies, businesses can reduce compromised credentials and prevent password reuse. Enforcing strong password requirements helps Magento stores strengthen authentication security, reduce brute-force and credential-based attacks, and maintain better control over account access.

  • Purchase the miniOrange Password Policy Manager extension from Magento Marketplace (Adobe Commerce Marketplace).
  • Go to My profile -> My Purchases
  • Please ensure you are using correct access keys (My Profile - Access Keys)
  • Paste the access keys in your auth.json file inside your project
  • Use the below command to add the extension to your project.
    "composer require {module_name}:{version}"
  • You can see the module name and list of versions in the selector below the extension module name.
  • Run the following commands on command prompt to enable the extension.
    php bin/magento setup:upgrade

  • Go to Password Policy Manager → Configuration and select Admin or Customer (Premium) to configure password policy enforcement.
Magento password policy manager- Admin and Customer Configuration
  • Enable password policy enforcement for Account Creation, Login, and Forgot / Reset Password as required.
  • For each enabled flow, choose the When password is weak action to either block or warn weak password.
  • Also, customize the Error message, then click Save.
Magento password policy manager for admin settings
  • Open Password Policy Settings and select the required password rules: Uppercase, Lowercase, Number, Special Character, and No email in password.
  • Click Save to apply these requirements to all enabled enforcement flows.
Magento password policy manager- Password Policy Settings
  • Open User Management to view and search Flagged Accounts that failed the password policy.
  • Review account details, select users if needed, and use the Action dropdown for bulk actions. Use pagination controls to browse additional records.
Magento password policy manager- Flagged Accounts
  • Open Reports to manage Debug Logs and Audit Logs for troubleshooting and policy monitoring.
  • Enable debug logging only when required, and use Clear or Download to manage or export log data. Audit logging records policy events for security and compliance review.
Magento password policy manager- Reports

Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

We'll Reach Out to You at the Earliest!


ADFS_sso ×
Hello there!

Need Help? We are right here!

support