Existing Account Password Does Not Comply With Current Password Policy
Existing company accounts may have passwords that do not meet the current password policy, while newly created or updated passwords are required to follow the latest password rules.
The password policy is validated when a password is saved or changed. Existing passwords are not automatically revalidated against the current policy during login. Therefore, an existing account with an older, non-compliant password can continue to log in successfully.
Example Questions
-
- Why is an existing company using a password that does not meet the current password policy?
- Why can an existing account log in with a non-compliant password?
- Why is the password rejected when creating a new company but accepted for an existing company?
- Are existing accounts with older passwords affected by the new password policy?
- How can we update an existing account to comply with the current password policy?
Symptoms / How to Identify
- An existing account has a password that does not meet the current password requirements.
- The same password is rejected when creating a new account.
- The existing account can still log in successfully using the old password.
- The password policy works correctly when setting a new password.
Information Required Before Troubleshooting
- Company/account name.
- Existing password policy requirements.
- Screenshot of the account/company overview, if required.
- Confirmation of whether the issue occurs with an existing or newly created account.
- Login and password-change behavior.
Troubleshooting Steps
- Identify whether the account is an existing account or a newly created account.
- If it is an existing account, check whether its password was created or updated before the current password policy was introduced.
- Test setting or changing the password using the existing password value.
- Verify that the system applies the current password policy when saving the new password.
- If the password does not meet the current requirements, update it with a compliant password.
- Verify that the account can log in successfully using the updated password.
- If the issue involves an unexpected password update or inconsistent account data, check the available logs for further investigation.
- If the issue recurs, capture the occurrence while it is happening so the technical team can investigate it with additional logging.
Possible Cause
- The account was created or its password was set before the current password policy was introduced.
- Password policy validation is performed when a password is set or changed, rather than continuously validating passwords already stored.
- In some cases, an incomplete password-update operation may result in inconsistent account information. Logs should be reviewed to confirm such cases.
Resolution / Action
Existing accounts with passwords that do not comply with the current policy can continue to log in because the password is not automatically revalidated against the newer policy during login.
To bring the account into compliance, update the password from the company/account overview screen using the current password requirements.
If an unexpected password update or data inconsistency is observed, escalate the case with the account details and relevant timestamps so the technical team can review the logs.