# Password Policy Recommendations
# Introduction
The Ability Platform allows our customers to use their own identity provider. In this case, ABB cannot configure and enforce the policies used for the user accounts configured. For this reason, we strongly recommend to the Businesses to make this a topic when onboarding their customers.
# Recommendations for Password Policy and Multi-Factor Authentication:
- ABB has for its own user account in ABB Azure AD a password policy but more importantly, a policy that enforces the use of Multi-Factor Authentication (MFA) on internet-facing applications. We strongly recommend using the same for our customers.
- For passwords, a common practice is to use a minimum of 8 characters (15 for privileged accounts).
- Also, a common practice is to have a combination of lower case and upper case characters as well as to have a number and a special character.
- Last but not least, we shall urge our customers to use Multi-Factor Authentication by default, but surely for Administrator Accounts.