Changing Individual User Passwords
Standard Password Change Process To change a user's password in Sage 100, follow these basic steps:
- Log into Sage 100 with appropriate administrative privileges
- Navigate to Library Master module
- Select Main menu, then User Maintenance
- Select the specific user
- Locate the Password field and enter the new password
- Enter the same password in the Confirm Password field
- Click the Accept button to save changes
Administrator Password Management
The Administrator account in Sage 100 holds special significance as it's used for critical functions like setting up users, companies, and roles. It's also required during version upgrades.
Resetting Lost Administrator Password If you need to reset a lost administrator password, follow this procedure:
- Contact Sage Support with a valid support agreement
- Create a support ticket online or call (800) 854-3415
- Complete the Employee Declaration form
- Include your Support Ticket Number on the form
- Submit the form via fax or email to tools.na@sage.com
- Call Sage Support to complete the interactive reset process
Implementing Unified Login
Unified Login is a recommended security feature that synchronizes Sage 100 passwords with Windows authentication credentials.
Benefits of Unified Login:
- Synchronizes network and Sage 100 access control
- Enforces organizational password policies
- Reduces password management overhead
- Minimizes password sharing risks
- Enables immediate user access termination
Setting Up Unified Login:
- Configure user accounts in Windows
- Enter the Windows login name in User Maintenance
- Enable Unified Login feature
- Map Sage 100 users to Windows credentials
- Test authentication process
Password Security Best Practices
Password Creation Guidelines:
- Use minimum 16 characters
- Combine uppercase and lowercase letters
- Include numbers and special symbols
- Avoid personal information
- Create unique passwords for each account
Strong Password Examples:
- Random word combinations: "Mixture-Pie-Met-State-Planning6"
- Acronym-based: "I1g2tD2eSccWmbfA!"
- Character substitution: "Ch3e5e_s0fA!Mot0rcYc1E-5ap1iNg"
Additional Security Measures
Role-Based Security:
- Configure ODBC security settings
- Assign appropriate permission levels
- Restrict access to sensitive data tables
- Implement field-level security controls
Network Security:
- Limit direct access to Sage 100 network shares
- Use remote desktop solutions
- Implement Terminal Server or Citrix
- Publish Sage 100 as RemoteApp[6]
Regular Password Maintenance
Scheduled Password Updates:
- Change passwords every 90 days
- Maintain password history
- Enforce password complexity requirements
- Document password change procedures
- Train users on security protocols
Mobile Access Security
Mobile Security Guidelines:
- Install security updates promptly
- Verify email links before clicking
- Read URLs right to left for authenticity
- Validate unusual requests through separate channels
- Prohibit password sharing via email
Password Manager Integration
Consider implementing a password manager to enhance security:
- Generates strong random passwords
- Securely stores credentials
- Provides easy access across devices
- Enables automatic password updates
- Supports multi-factor authentication
Employee Training
Security Awareness:
- Conduct regular security training
- Simulate phishing attempts
- Review password policies
- Document security procedures
- Monitor compliance
Backup and Recovery
Security Backup Procedures:
- Maintain regular system backups
- Test restoration procedures
- Document recovery processes
- Store backups securely
- Verify backup integrity
Multi-Factor Authentication
Implementing multi-factor authentication adds an extra layer of security:
- Requires additional verification
- Uses biometric authentication
- Implements phone verification
- Reduces unauthorized access
- Monitors login attempts
By following these comprehensive guidelines and implementing strong password policies, organizations can significantly enhance their Sage 100 security posture and protect sensitive financial data from unauthorized access. Regular review and updates of these security measures ensure continued protection against evolving cyber threats.
Remember that security is an ongoing process, and staying current with the latest security practices and updates is crucial for maintaining a robust security framework for your Sage 100 implementation.
Citations: [1] https://www.acutedata.com/how-to-manually-change-a-users-password-in-sage-100/ [2] https://www.caserv.com/2020/09/03/sage-100cloud-what-is-the-admin-password-and-how-to-change-it/ [3] https://www.keepersecurity.com/blog/2024/08/30/best-practices-for-creating-strong-passwords-youll-remember/ [4] https://www.youtube.com/watch?v=nPX523_WbNM [5] https://www.eccu.edu/blog/technology/the-importance-of-strong-secure-passwords/ [6] https://s-consult.com/2022/06/02/best-practices-for-sage100-sescurity/ [7] https://www.greytrix.com/blogs/sagecrm/2022/10/03/steps-to-be-followed-after-change-of-sage-crm-or-sage-100-applications-password/ [8] https://edu.gcfglobal.org/en/internetsafety/creating-strong-passwords/1/ [9] https://fixedassetexperts.com/blog/5-password-tips-improve-sage-fixed-assets-cybersecurity/ [10] https://scanco.com/6-tips-to-keep-your-sage-100-mobile-data-secure-2/