Password settings
Password settings
School settings → Password is where you set the school-wide rules that govern member passwords — the default password given to new accounts, minimum length and complexity, password expiry, and who is allowed to reset or change a password. Two-factor authentication toggles live on this same page but are covered in their own doc — see Require MFA for staff and students.
Step 1 — Open School settings → Password {#step-1}
Select School settings in the sidebar, then the Password tab. You must be an admin for the current school.
Step 2 — Set the school's default passwords {#step-2}
- Default learner password and Default mentor password — the password given to accounts when they're reset to default (see Reset passwords). Each field shows whether a default is already set.
- Both fields load blank — leave one blank to keep the current default; type a new value only when you want to change it. The stored value is never shown back to you.
- Also update existing members who still have the old default password — tick this if, when you change a default, you also want every member still using the old default password moved over to the new one. Leave it unticked to only apply the new default going forward (e.g. to members reset afterwards); everyone already on the old default keeps it until they're next reset.
Keep your default password syncing to Google/Entra/AD: for some schools set up a while ago, the stored default can still reset users in the app but can no longer be pushed to your connected platforms. A reset still works, but the new default won't reach Google/Entra/AD, and the notifications bell asks you to re-save it. Re-entering the default learner and/or mentor password here and saving restores full syncing (and clears the notice). It doesn't change any current passwords on its own. See Reset passwords → Keeping the default in sync.
Step 3 — Set minimum length and complexity {#step-3}
- Min length (learners) and Min length (mentors) — the minimum number of characters required. Leave a field blank to fall back to the system default of 8 characters.
- Require complex learner passwords — when on, a learner's password must contain an uppercase letter, a lowercase letter, and a number. Mentor and other staff passwords always require this same complexity — it isn't a separate toggle.
- These rules apply whenever a member sets or changes their own password (My profile), and when an admin sets one for them from the user's edit page. A short list of very common passwords (e.g. "password123") is always blocked regardless of these settings.
Step 4 — Set password expiry {#step-4}
Password expiry days (learners) and Password expiry days (mentors) set the number of days a password is valid for that group before it must be changed. Leave either blank if you don't want that group's passwords to expire.
Step 5 — Control who can reset or change passwords {#step-5}
- Mentors can reset passwords — turns on the Reset passwords page and the related bulk actions for mentors (teachers) at this school, so they can reset passwords for their own pupils without needing an admin. See Reset passwords.
- Disable student passwords — turns off every student's ability to change their own password, school-wide. This is the same setting described in Reset passwords → Control who can change their password; you can still turn it off for an individual student, or in bulk, from the Users page — but this school setting overrides those when it's on.
Step 5a — Disable passwords for specific year groups {#step-5a}
Below the toggles in Step 5, Disable passwords for specific year groups lets you turn off self-service password changes for one or more year groups instead of the whole school — for example, disabling it for younger pupils while older year groups keep the ability to change their own password.
- Tick the year groups you want to disable, then select Save year-group password settings. The change applies to every current student in those year groups immediately.
- It's ignored while "Disable student passwords" (all students) is on — that setting already covers every student, so the year-group list has nothing left to add until it's turned off.
- A student added to, or moved into, a disabled year group later (by a MIS/Wonde/AD sync, or by editing their record) is picked up automatically — there's no need to re-save this setting.
- This sets the same per-user "Password change" switch shown on a student's edit page and in the Users bulk actions — see Reset passwords → Control who can change their password. A student's edit page names "this year group" as the reason when it's the year-group rule keeping their switch locked. Disabling a student manually (per-user or in bulk) always takes precedence and isn't undone by later changing this list.
Two-factor authentication {#step-6}
The Enable 2FA for new staff / Enable 2FA for new students toggles and the 2FA whitelist also live on this page, directly below the password settings. They're covered fully in Require MFA for staff and students so this doc doesn't repeat them.
Looking for QR code login?
QR code login is switched on from its own tab — School settings → QR login — not this Password tab. See QR code login for enabling it and generating codes for pupils.
Step 7 — Save {#step-7}
Select Save password settings. Because this can update existing members' passwords, you'll be asked to confirm before it applies.