Introduction

In response to rising security threats across the HR software industry, JazzHR is rolling out a new 90-day password reset policy which took effect on Tuesday, April 8, 2025. This update is part of JazzHR’s continued efforts to keep your candidate data, company information, and user credentials secure.

If you're an account admin, this article will walk you through what’s changing, why it matters, and how to communicate the update to your team using a ready-to-send internal email template.

TL;DR

  • All JazzHR users will be prompted to reset their password as of April 8, 2025
  • A new 90-day recurring password expiration policy will be enforced
  • Admins should remind users about credential hygiene and share secure password practices

What’s Changing

As of April 8, 2025, all JazzHR users are now required to:

  • Create a new password at their next login
  • Automatically reset their account password every 90 days

This change is in response to a 30%+ increase in phishing and credential theft across the HR SaaS industry and reflects a growing need for proactive password hygiene.

Regularly rotating passwords reduces the risk of compromised credentials being exploited over time.

🔒
Expert Tip: Reusing passwords - even slightly modified ones - across personal and work accounts creates a major security risk.

Always use a unique, strong password for each account to limit exposure in the event of a breach.

Why Password Hygiene Matters

Passwords are your first line of defense. Even with secure infrastructure, a weak or stolen password can put your data, your job candidates, and your company at risk.

JazzHR is strengthening its backend protections, but organizations are ultimately responsible for ensuring that user credentials are:

  • Kept private and secure
  • Monitored for unauthorized access
  • Updated immediately if compromised

Best Practices for Strong Passwords

To help your team stay secure, train them to use the following best practices:

  • Use 12 or more characters
  • Include upper and lowercase letters, numbers, and special characters
  • Avoid names, birthdates, or repeated patterns
  • Never reuse passwords from other tools or websites
  • Use a password manager to store and generate strong credentials
💡
Expert Tip: If your organization supports it, consider enabling Single Sign-On (SSO) for simpler, more secure access. SSO reduces phishing risk and minimizes password fatigue.

Notify Your Team with this Email Template

Use this copy-paste email template to share the JazzHR password update with your hiring team and internal stakeholders:

Subject: Action Required: JazzHR Password Reset Policy Update

Body:

Hi Team,

As of April 8, 2025, JazzHR has implemented a new password policy to improve account security.

All users will be prompted to create a new password the next time they log in and will be required to reset their password every 90 days going forward.

This is part of a broader industry-wide shift to protect against phishing attacks and credential theft. Please make sure your new password is strong and unique.

Tips for choosing a secure password:

  • Use at least 12 characters
  • Include upper and lowercase letters, numbers, and symbols
  • Avoid birthdays, names, or repeated passwords

You can read more here: Read the full guide →

Thank you for doing your part to help us stay secure.

— Your Admin Team


Final Thoughts

Cybersecurity is a shared responsibility, and small habits - like better passwords - make a big impact. JazzHR’s 90-day password policy may be a small change, but it’s a meaningful one.

By combining this update with smart credential management and tools like SSO, your team can stay protected while accessing everything JazzHR has to offer.