Resetting your password - best practices

Last updated: September 14, 2026

This article explains how to choose a password for your Solidroad account that is secure and practical to use. It applies to every role, whether you are setting up your account for the first time, resetting a forgotten password or changing an existing one. To change a password, please go through the "Reset password" flow on the login page.

If your organisation uses single sign-on, see the section at the end, because you may not need a Solidroad password at all.


What makes a password strong

Length matters more than complexity. A longer password is harder to crack than a short one with symbols substituted in. Four or five unrelated words is a good target: correct-otter-vaulting-tuesday is stronger and easier to remember than P@ssw0rd1!.

Use a password that is unique to Solidroad. If you reuse a password, a breach at any other service puts your Solidroad account at risk too.

Avoid anything derived from information someone could look up or guess:

  • Your name, your team’s name or your employer’s name

  • Dates of birth, join dates or years

  • Keyboard patterns such as qwerty, 123456 or asdfgh

  • Simple character substitution (swapping a for @ or o for 0). This is a well-known trick and adds very little strength

  • A variation of a previous password, like adding a number to the end

Use a password manager

A password manager generates a unique, random password for every service and remembers it for you, so you never need to reuse or memorise anything. Most will also alert you if a stored password later appears in a data breach.

If your organisation provides one, use it. If not, several reputable options are free for personal use.

If your organisation uses SSO

If your workspace is configured for single sign-on, you sign in with your existing company credentials and do not maintain a separate Solidroad password. Ask your IT team whether SSO is available to you. It is usually the simplest and most secure option.

Why a password might be rejected

Solidroad checks new passwords against a public database of passwords exposed in past third-party breaches. If yours has appeared in one, you will be asked to choose another, even if it looks strong.

Your password is never sent to Solidroad or to the breach database in full. Our sign-in provider explains how this works in "Improved account security by checking for leaked passwords".


Related articles

If you have any further questions, contact the Solidroad team via the Help tab in the platform.