Cloud Platform enforces a security policy for passwords used to access the Cloud Platform user interface. This security policy determines how strong (resistant to guessing) user’s passwords must be.
The password strength policy applies only to the Cloud Platform user interface, and doesn’t apply to your Drupal websites.
Note
For password security policies in Site Factory, see Minimum password strength.
Cloud Platform applies several rules to test a password’s strength, based on the entropy (randomness) of the sequences in the password. All passwords used for accessing the Cloud Platform user interface must meet the following criteria:
As you type a new password, the Acquia password policy system tests and reports the password’s strength. If you try to create a password that doesn’t meet Acquia’s password strength requirements, Cloud Platform displays an error message describing why the password strength is insufficient.
The Cloud Platform user interface protects you from brute-force attacks by the following policies limiting the total number of sign-in attempts:
If you are blocked due to multiple failed sign-in attempts, you may request a new password by email to bypass the hour block window.