---
version: "2026.1.0"
language: "en"
---
# Security

The **Security** section updates password complexity requirements for [user management](https://docs.leapwork.com/leapwork-flow/latest/administration/user-management.md).  
Security settings would be available if you are logged in as an administrator.  
![image-20260610-115244.png](https://docs.leapwork.com/__attachments/a_e22a2ecaf37a1bd7e4440de042b9f3203429c8ddf46345ae6c7bb283f45b07f8/image-20260610-115244.png?cb=7a4fb9ba2cfdc5099acd2184fbcf7ac7)  
**Note** : The screenshots on this page use the **Elegance Design** , introduced in **2025.3**. If you are using an earlier version, your layout may look different.

1. Configure

Password Complexity:  
* The **Require at least one lowercase letter** check box is checked if yourequire at least one lowercase letter.

* The **Require at least one uppercase letter** check box is checked if yourequire at least one uppercase letter.

* The **Require at least one digit** check box is checked if yourequire at least one digit.

* The **Require at least one special (non-alphanumeric) character** check box is checked if you want to add special character to the list of requirements.

* The **Minimum password length** filed is used to add a minimum required password length (within Leapwork's range of 6 to 20 characters).

The **Password Expiration** drop-down is used to select options from **Never expires** or **Days before expires** and enforce password renewal after a set number of days.  
![image-20260610-115327.png](https://docs.leapwork.com/__attachments/a_ebc984b177ae6c1b927feb709c58ad7b5babfe72d74d281e2c635d59da0ab444/image-20260610-115327.png?cb=667177a45aa2c68b19f1f49056193c69)

2. Click**Save**. The new password requirements will be sent to your entire team.

* You can log in with your current password until you save the new requirements. If you last updated your password 28 days ago and set a 30-day expiration, you must update it when accessing Leapwork Flow after two days.

* To prompt all users to update their passwords quickly, set the **Days before expires** to a low number (e.g., two days). After everyone updates, reset the expiration to your organization's policy (e.g., every 90 days).

* On a user level, you can always go to **User management** , select the desired user, and click **Edit** , click on **Set new password** , and then either set a new password manually or choose the**Automatically create a password** checkbox select **Enforce this user to change their password on next login**.