Strengthened password policy for enhanced security

December 04, 2025
New
Autotask, Kaseya 365 Ops

Autotask has introduced updated password requirements to improve security and align with modern industry standards. These changes address vulnerabilities identified during recent penetration testing and ensure stronger protection for user accounts.

What’s changing

  • Minimum length increase: Passwords must now be at least 12 characters long (previously seven).
  • Complexity requirements maintained:
    • No spaces or single quotes (’)
    • At least one special character
    • Characters from at least two of the following groups: uppercase letters, lowercase letters, numbers
    • Must differ from your previous five passwords

Why this matters
Increasing the minimum password length makes accounts significantly harder to compromise, reducing the risk of unauthorized access. These updates also ensure continued alignment with OWASP and other industry best practices while reducing predictable password patterns.

What users need to do
All passwords must meet the new standards. Users creating new accounts or updating their passwords must use a 12-character password that satisfies all complexity requirements. Existing passwords that do not meet these requirements must be updated.

Learn more about strengthened passwords for Autotask and more in the 2025.6 release here.

One Complete Platform for IT & Security Management

Kaseya 365 is the all-in-one solution for managing, securing, and automating IT. With seamless integrations across critical IT functions, it simplifies operations, strengthens security, and boosts efficiency.

Is this email safe? INKY Smart Insights answers in seconds

Is this email safe? INKY Smart Insights answers in seconds

INKY Smart Insights gives IT teams a plain-language verdict with cited evidence on flagged emails, cutting manual investigation time from 10 minutes to 5 seconds.

Read now
Fake voicemails, real malware: Inside a 26,000-email SVG smuggling campaign

Fake voicemails, real malware: Inside a 26,000-email SVG smuggling campaign

Attackers disguised malicious JavaScript as voicemail attachments across 26,589 emails targeting 5,527 organizations. Here's how the SVG smuggling campaign worked — and how INKY caught every one.

Read now
What sets the world's top MSPs apart?

What sets the world's top MSPs apart?

Three-quarters of MSP 501 winners list security as a top revenue driver. We asked a six-time honoree what it actually takes to make the list — here's what separates the best from the rest.

Read now