Skip to main content

What Are the 4M Password and Login Policies?

Learn how advanced security policies affect your account.

N
Written by Nicole Heger
Updated over 3 weeks ago

This article explains the current security, password, and session policies in the 4Map platform and what Admins should expect, including how to manage locked accounts and support users who experience login issues. These updates help ensure compliance with Department of Transportation (DOT) security standards while maintaining a predictable experience for your teams.

As adoption of 4M grows, the platform enforces standardized security controls designed to:

  • Protect customer data and infrastructure designs

  • Reduce the risk of unauthorized or unattended access

  • Support compliance with DOT security


Password Requirements

Password Complexity

When creating or updating a password, users must meet the following requirements:

  • Minimum 16 characters

  • Includes:

    • Uppercase letters

    • Lowercase letters

    • Numbers

    • Special characters

Password Expiration

To maintain account security:

  • Passwords must be updated every 60 days

  • Users receive prompts as their password approaches expiration

  • Expired passwords must be updated before access is restored


Failed Login Attempts and Account Lockout (Admin-Specific)

To prevent unauthorized login attempts, 4M enforces a login attempt limit.

Lockout Policy

  • An account is automatically locked after 5 failed login attempts within 10 minutes

  • The lockout lasts for at least 15 minutes

  • During lockout, the user cannot attempt to log in and will see a lockout message

This policy applies to all password-based logins. Note that the amount of failed attempts and the lockout time is configurable by organization; get in touch with your Customer Success Manager to customize this for your team.

Admin Override: Unlocking a User Account

As an Admin, you can manually unlock a user account:

  • Unlocking immediately restores the user’s ability to log in

  • The failed-attempt counter is reset

  • The lockout timer is cleared

This allows Admins to quickly resolve access issues for users who were locked out unintentionally (for example, due to a mistyped password or credential manager issue).


What Admins Should Communicate to Users

You may want to proactively remind users that:

  • Password updates are required regularly

  • Repeated failed login attempts can temporarily lock their account

  • Admins can assist if they become locked out

Need Help or Want More Control?

If your organization is interested in Single Sign-On (SSO) or additional security controls, please contact your 4M Customer Success Manager to discuss available options.

Did this answer your question?