Password requirements
Profound checks the password when a user creates an account, accepts an invitation, resets their password, or changes it in their account settings. A password must:- Be at least 12 characters long.
- Be secure.
- Not match a password the user has used in Profound before.
MFA isn’t currently available for password sign-in. To require a second factor, set up Enterprise SSO and enforce MFA in your IdP.
Change or reset a password
To change a password, open Settings from the organization name menu at the top left of the screen, then select Account > Profile and update Password. Profound asks for the current password, and the new password must differ from it. The Password row appears only when your current session started with a password. If you signed in through SSO, the row is hidden even if your account has a password. To reset a forgotten password, select Forgot password? on the sign-in page, and Profound emails you a reset link.What makes a password secure
A secure password is long and hard to predict. Profound treats the following as easy to guess, even when they meet the length requirement:- Dictionary words, names, and well-known passwords such as
password1234. - Personal details such as a birthday, a username, or part of an email address.
- Keyboard patterns such as
qwertyuiop, sequences such as123456789012, and repeated characters such asaaaaaaaaaaaa. - Simple variations of any of these, such as capitalizing the first letter, swapping letters for similar-looking symbols, or adding a number at the end.
Sign-in when SSO is enabled
When a user enters their email address on the sign-in page, Profound checks the sign-in policy for that address before asking for a password:- SSO required: users whose email domain is one of your organization’s verified domains go straight to your IdP.
- SSO optional: if your organization has an SSO connection but doesn’t require it, users choose Continue with SSO or Continue with password.
- Other domains: users whose email domain isn’t one of your verified domains, such as agency or contractor accounts, keep signing in with an email address and password. Learn how to provision these users alongside your directory in Directory Sync.
Controls your identity provider handles
With Enterprise SSO, your IdP authenticates the user and Profound accepts the result. Profound doesn’t configure, enforce, or verify any of the following, so set them up in your IdP:- MFA.
- Managed-device requirements: use your IdP’s conditional access or device trust policies.
- Network or location restrictions: use your IdP’s conditional access policies.
- Password rules for SSO users: length, history, expiry, and lockout policies.