I can not stress this enough, ONLY do this is you enable SSL access, and only allow access VIA SSL! Otherwise passwords as strong as they may be can easily be compromised if users are using public wifi access. You should be using ssl for all passwords on the web anyway...