Skip to main content

Password security changes from 05.10.26

Configure password security settings, manage password expiry policies, and understand user onboarding changes in Newbridge Backoffice.

Written by Xanthe Jackson

Newbridge Backoffice is introducing a consistent password policy across the platform wherever users create or change passwords. The update also strengthens account security, improves user onboarding, and provides additional protection against repeated or suspicious login and password reset activity.

⚠️ Important: These changes take effect on 5 October 2026 and help protect user accounts while improving account security across your organisation.

What’s changing

  • A single password policy wherever a password is created or changed.

  • New passwords must be at least 12 characters long and include uppercase and lowercase letters, a number and a symbol.

  • Common, compromised or identity-related passwords will be rejected.

  • New users will receive an invitation link and set their own password. Administrators will no longer choose or receive passwords for other users.

  • Additional protection will be added to login, password-reset and invitation attempts.

  • Administrators will be able to manage an optional, company-wide password expiry policy for users.

  • Additional safeguards against suspicious or automated activity. Enhanced safeguards may temporarily restrict repeated requests if suspicious activity is detected. If access is temporarily restricted, wait before trying again or contact your administrator or support team for assistance.

What do you need to do?

No action is required before 5th October.

From 5th October 2026, new users will need to set a secure password. An organisation’s administrator will decide whether password expiry should be enabled. If password expiry is enabled, users with an expired password will be prompted to securely change it before they can continue using the Backoffice.


New password requirements

The new password requirements apply when a password is created or changed.

New passwords must:

  • Be at least 12 characters long.

  • Include uppercase and lowercase letters.

  • Include at least one number.

  • Include at least one symbol.

  • Not be a common password.

  • Not be a known compromised password.

  • Not be too similar to the user's name, username, or email address.

There is no maximum password length. Users can continue to paste passwords and use password managers.


Password expiry policy

Password expiry is disabled by default.

An organisation’s administrator can decide whether password expiry should be enabled. If password expiry is enabled, users with an expired password will be prompted to securely change it before they can continue using the Backoffice.

Configure password expiry settings

  1. Go to the Newbridge Backoffice login page.

  2. Enter your username and password, then select Log in.

  3. Select Users from the left-hand menu.

  4. Select Password Policy.

  5. Review the available password expiry options:

    • No expiry: Passwords never expire and do not need to be reset.

    • 3 months: Users must reset their password every 3 months.

    • 6 months: Users must reset their password every 6 months.

    • 1 year: Users must reset their password every year.

  6. Select the required password expiry policy.

  7. Select Save.

What happens after saving the password policy?

  • The selected password policy applies whenever a password is created or changed.

  • Existing passwords continue to work unless a password change is required.

  • Password expiry is not automatically enabled by the release and must be configured by your organisation.

  • Each organisation can choose whether passwords should expire and how often users must reset them.


Manage new user onboarding

The onboarding experience has been updated to improve security and privacy for new users. When a new user is created:

  • The user receives an invitation link by email.

  • The user completes their own account setup.

  • The user creates their own password during onboarding.

  • Administrators can no longer set passwords on behalf of users.

  • Administrators no longer receive or view user passwords.

This ensures that passwords remain private and are known only to the account holder.

New users should complete account setup using the invitation link they receive.

During the setup process, they will create a password that meets the new security requirements.


Manage expired passwords

If password expiry has been enabled and a user's password expires:

  1. The user is directed to a secure password change page.

  2. The user must create a new password that meets the current password requirements.

  3. Access to Newbridge Backoffice is restored immediately after the password has been successfully changed.

When a password has expired, users cannot continue using Newbridge Backoffice until they have successfully reset their password. The password change process takes place on a secure, authenticated page to protect account security.


Frequently asked questions

Why are password requirements changing?

Newbridge Backoffice is introducing a consistent password policy wherever users create or change passwords. The update also improves new user onboarding and adds protection against repeated or suspicious login and password reset activity.

When do these changes take effect?

The changes take effect on 5 October 2026.

Will my current password stop working?

No. The new requirements only apply when a password is created or changed.

Password expiry is disabled by default, so the release does not automatically require all users to change their passwords.

What happens when my password expires?

Users are directed to a secure, authenticated password-change page. After successfully changing their password, they can continue using the Backoffice.

Did this answer your question?