Skip to main content

App passwords

Applies to: identity 0.24 · Checked: 25.09.2026

A mail program such as Thunderbird or a phone's built-in mail often cannot sign in through the sign-in page. For it, a person creates an app password. Their own password stays with them and never goes into the program.

Turning it on​

It is off by default. An administrator turns it on in the identity console /admin: the policies section, the App passwords card, the Allow app passwords box. Turning it off takes effect at once: nobody can create one, and existing ones stop working.

How a person creates one​

The Security tab of the portal /me shows an App passwords card. The person names the program and ticks what the password may do:

  • reading mail — access to the mailbox;
  • sending mail — sending through the server.

The password is shown once, in groups of four characters. The spaces need not be typed. The table shows when each password was created and last used. Revoke turns one password off; the others keep working.

Worth knowing​

  • The password is for mail only. It does not sign in to the portal, the messenger or a console.
  • Twenty passwords per person at most.
  • Wrong attempts count together with those of the person's own password. Past the threshold the account is locked for the time set in the credential policy.
  • A password works only while the account is active. A leaver or a disabled account cannot use it.
  • Every check, every creation and every revocation is in the security event log.