Security Policies for User Passwords and Pin Numbers in Cisco UCM
User-specific security parameters such as PIN number length (for Extension Mobility), password complexity and aging (i.e. for CCM User access) are applied in CUCM on a per-user basis using credential policies. The policies are defined under "User Management" ==> "Credential Policy", and assigned under "User Management" ==> "End Users".
The security parameters and enforcement levels available to the administrator are quite granular: in the example below, the following characteristics are set:
- minimum PIN length of 5 digits
- require a complex (i.e. non-trivial) sequence of digits
- disable EM login after 3 successive failures
This new security policy is applied on a per-credential, per-user basis. The credentials are now assigned under end user configuration. At the same time, users can be forced to change their pin number before Extension Mobility will be permitted - on attempted login, users are greeted with the message "[209] - Change PIN", and logon cannot proceed.
In addition to per-user assignment, a default credential policy is assigned to users when they are first provisioned. Default policy definitions are available under "User Management" ==> "Credential Policy Default". Changing the policy controls the security policy applied to users when they are created in CCM. Defining a new default policy requires:
- Creating the new policy (per the above)
- Assigning the policy to the appropriate default (End user pin/password, application password)
The default policy only effects new users - existing users will not be effected by the change. You'll still need to go back and change the policy for any existing users, either individually or using BAT.

Creating a new Credential Policy

Defining a default PIN number policy

Selecting credentials update under user configuration

Assigning PIN credentials policy to a user

Attempting to apply an invalid PIN number