17.1 Passwords and Two-Factor Authentication
Key Takeaways
A password is the first factor for the email address you use to sign in. The default account policy is Strong: at least 10 characters and at least three of the four character types.
Two-factor authentication asks for a second factor from any authenticator app that follows OATH TOTP. Help does not require one app brand. NetSuite accepts a six-digit code for 30 seconds.
The standard role set up with mandatory two-factor authentication is Administrator. Other highly privileged roles are mandatory too, and that requirement cannot be removed.
You can skip 2FA setup up to five times. If the phone and the backup codes are both gone, an administrator resets 2FA in the User Access Reset Tool.
Forgot Your Password emails a link that expires in 60 minutes, then asks security questions. Without 2FA or those questions, an administrator has to reset access.
A password, a second factor, and a role rule
NetSuite sign-in starts with the email address and password on your user. The password is something you know. It is the first check that the person at the keyboard owns that email address. Two-factor authentication (2FA) asks for a second check, usually a short-lived code from an authenticator app. A role requirement decides whether that role can be used until 2FA is in place. The password still has to be correct.
A stolen password passes the first check. A lost phone fails the second check even when the password is right. A role that is not marked 2FA-required never asks for the code, even when another role on the same user does. Security questions, covered next, are a recovery control. You do not type them on an ordinary sign-in from a familiar browser.
What the password must satisfy
Help's password FAQ says accounts use a Strong password policy by default. An administrator changes that policy at Setup > Company > General Preferences. The password-settings topic lists four built-in policies:
- Weak, which Help does not recommend: minimum length of six characters.
- Medium: minimum length of eight characters, and at least two of the four character types.
- Strong: minimum length of 10 characters, and at least three of the four character types.
- Very strong: minimum length of 12 characters, and all four character types.
The four character types are uppercase letters, lowercase letters, numbers, and non-alphanumeric ASCII characters. An administrator can raise Minimum Password Length and cannot set it below the policy floor, so the default minimum is 10. Certain highly privileged roles must keep the Strong policy.
For the default, remember Strong: 10 characters and at least three of the four types. Very Strong is the stricter 12-character option that requires all four types.
Customer Center sits outside the account policy. Help sets an eight-character minimum for Customer Center roles and does not apply the account password policy to Customer Center sign-in or to customers who register on your website.
Under every policy, an administrator cannot allow a reused password, a new password that is not significantly different from the last one, an easy-to-guess value, or a non-ASCII character. On submit, NetSuite can also reject a password found in a leaked-password list. Password Criteria react as you type and do not replace that leaked-password check.
Password Expiration in Days sits on General Preferences, apart from the policy level. Allowed values are 1 through 365. The default is 180 days from your last password change. Employees who can view unencrypted credit card numbers or unencrypted ACH account numbers must change passwords every 90 days unless the company limit is shorter, because PCI rules take precedence.
While you know the current password, open Change Password in the Settings portlet, enter that password, confirm a new one, and save. Five consecutive wrong entries in Current Password lock you out for 30 minutes. The next sign-in uses the new password, and NetSuite emails you that it changed. Company policy stays on General Preferences.
When the password is forgotten
On the login page, enter your sign-in email, click Forgot Your Password, enter the email again, and continue. The link expires in 60 minutes. Start over if it expires. If no message arrives and the address on the screen is correct, contact an administrator.
You then answer security questions. Answers are not case-sensitive. Help allows 20 attempts to answer all three during this reset. Success opens the Change Password page. Confirmation goes to the requesting address. If you hold Administrator in that account, every Administrator there is copied. Administrators in any account where you hold that role are copied as well.
Self-service reset works only when you can still use 2FA or security questions. Otherwise an administrator resets the password, and Help says you must set up new security questions. The next section is where those three questions are created.
An administrator, or a role with Core Administration Permissions, uses the User Access Reset Tool at Setup > Users/Roles > User Management > User Access Reset Tool to send a reset email, clear security questions, unlock a user after five incorrect passwords, or reset 2FA. A multi-account password reset requires an administrator in every account. Core Administration Permissions alone cannot do that.
The second factor
If any role you hold is 2FA-required, the first sign-in with that role prompts you to enroll. You can skip up to five times. Enroll sooner rather than spend the skips. Any authenticator app that complies with OATH TOTP is acceptable. Help does not require one brand. The password FAQ names Google Authenticator, OKTA Verify, and Oracle Mobile Authenticator as examples. NetSuite accepts a six-digit code valid for 30 seconds.
OATH TOTP is the app standard. It is not the OAuth 2.0 Authorized Applications Management permission, which forces 2FA onto a role.
Backup codes replace the app when the phone is missing or you change apps. With no codes and no way to generate one, an administrator resets 2FA. You can generate a fresh set after the old codes are lost or used. The next 2FA-required sign-in then asks for new 2FA settings.
You may trust a device. Duration of Trusted Device defaults to Per session, with choices of 4, 6, 8, or 12 hours, or 1 to 30 days. Trust for a 2FA-required role applies across companies you can access. The trusted-device topic says the Settings portlet links to Manage Trusted Devices, where you can turn the challenge back on.
Which standard role is mandatory
The standard role set up with mandatory 2FA is Administrator, kept apart from CEO, Issue Administrator, and CFO. Administrator and other highly privileged roles require 2FA in production, sandbox, development, and Release Preview. That requirement is on by default and cannot be removed. It has applied in all accounts since 2018.2, and the roles show in the Mandatory 2FA column at Setup > Users/Roles > Two-Factor Authentication Roles.
Permissions that require 2FA include Access Token Management, OAuth 2.0 Authorized Applications Management, Core Administration Permissions, and the Two-Factor Authentication base permission. Marketing Administrator, Sales Administrator, Support Administrator, and System Administrator carry that base permission. Help also names single sign-on setup, Device ID Management, and viewing unencrypted credit cards or ACH account numbers. Employee Center, Partner Center, and Vendor Center can be marked 2FA-required. Customer Center cannot. Choosing Not required does not remove 2FA that a highly privileged permission already forces.
A SAML Single Sign-on role ignores the 2FA requirement because SAML takes precedence. Require 2FA for All Roles makes every user with any Employee role use 2FA, or a compliant passkey if passkeys are enabled, and it overwrites role-specific requirements. Web services and RESTlets are 2FA-required, and a 2FA-required role cannot call an API with user credentials alone.
| Control | What it checks | Where it is decided | If you lose it |
|---|---|---|---|
| Password | The secret for that email address | Settings portlet to change it; policy at Setup > Company > General Preferences | Forgot Your Password if 2FA or security questions still work; otherwise the User Access Reset Tool |
| Two-factor authentication | An authenticator-app code or a backup code | First sign-in with a 2FA-required role; any OATH TOTP app | Backup codes, or an administrator reset of 2FA |
| Role requirement | Whether that role can be used without 2FA | Administrator and other highly privileged roles are mandatory; other roles are marked on Two-Factor Authentication Roles | You may skip setup up to five times; store backup codes before the phone is the only copy |
A bookkeeper receives Administrator
Adding Administrator to a bookkeeper who has never seen a 2FA prompt makes the next sign-in with that role ask for setup. Skipping is allowed up to five times. If the phone and the backup codes are both gone, an administrator resets 2FA. Five wrong passwords lock access for 30 minutes, and that lock is neither a 2FA prompt nor a security question.
Which standard role does NetSuite set up with mandatory two-factor authentication?
CEO
Administrator
Issue Administrator
CFO
On the first sign-in with a role that requires two-factor authentication, how many times may you skip 2FA setup?
You cannot skip; enrollment is required on that first sign-in
Three times
Five times
Ten times, matching the password-reset attempt limit
What is the default password policy on a NetSuite account?
Strong: at least 10 characters and at least three of the four character types
Weak: a six-character minimum, which Help recommends for new accounts
Medium: at least eight characters and at least two of the four character types
Very strong: at least 12 characters and all four character types
Sections you finish are checked off in the contents.