Please be aware of an update to the password policy for Local Users in Dremio Cloud. This notice applies to organisations that have Local Users — accounts that authenticate with passwords managed directly in Dremio (typically used for contractors, external partners, or testing and development environments).
These changes are already in effect.
WHAT'S CHANGING
When a Local User sets or resets their password, they will now be required to meet stronger password requirements, including a minimum length of 15 characters, greater character complexity, and additional safety checks such as restrictions on reuse and personal identifiers (e.g. email address).
Additionally, accounts will be locked after 5 consecutive failed sign-in attempts, with a self-service unlock flow via email.
For the full details, see the Local Users section of our documentation:
https://docs.dremio.com/dremio-cloud/admin/users#local-users
IMPORTANT: WHO IS AFFECTED
• Existing Local Users are NOT immediately impacted. Users whose passwords were set under the previous policy can continue to sign in without interruption.
• The new requirements apply the next time a Local User sets or resets their password.
• SSO Users and Service Users are not affected by this change.
RECOMMENDED ACTIONS
1. Share this notice with administrators who manage Local Users in your organization.
2. Inform your Local Users of the new password requirements so they are prepared when they next reset their password.
3. If you use Local Users for contractors or external partners, ensure they are aware of the updated policy.
If you have any questions, please reach out to Dremio Support at https://support.dremio.com.