Set up account security¶
In the Admin Settings, you define the security requirements for all the accounts of your organization. These include the minimum password length, the validity period of passwords, sessions, and accounts, as well as two-factor authentication (2FA).
The following requirements must be met:
- ☑ You have admin rights.
Proceed as follows to set up account security:
- ► Open the Admin Settings view, see Section Admin Settings.
- ► Click on the Account Security tab, see Section Account Security tab.
-
► In the text field under MINIMUM PASSWORD LENGTH, enter the number of characters a password must contain at least.
Note
The value must be at least 10. For organizations with PCI DSS requirements, the value must be at least 12.
-
► In the text field under LOCK USER AFTER INACTIVITY (DAYS), enter the number of days after which an inactive account is locked.
Note
The value must be between 0 and 365.
-
► Enable or disable two-factor authentication for all users using the ENFORCE 2FA switch.
- ► In the text field under LOGIN RETRY LIMIT, enter the number of failed attempts after which an account is locked.
- ► In the text field under PASSWORD EXPIRY DURATION (DAYS), enter the number of days after which a new password must be set.
- ► In the text field under SESSION TIMEOUT (MINUTES), enter the number of minutes after which an inactive session is logged out.
- ► Click on the Save button.
- ➔ The settings are saved and apply to all the accounts of your organization.
Note
Using the Reset button, you reset all the values to the most recently saved values.
Note
For organizations with PCI DSS requirements, the LOCK USER AFTER INACTIVITY (DAYS), LOGIN RETRY LIMIT, and SESSION TIMEOUT (MINUTES) fields and the ENFORCE 2FA switch are locked.