Configure Account & Security policies

Use Account & Security to set ID and password rules for new or updated accounts. You can also choose how long users stay signed in and how many simultaneous sign-ins are allowed.


Before you begin

  • Required role: administrator
  • Configure attack detection, automatic blocks, and new-device approval separately under Security Settings.

Open Account & Security

  1. Open the administrator page.
  2. Select User Management from the left menu.
  3. Select Account & Security from the submenu.

The page contains Login ID format, Password rules, and Session policy cards. Select the arrow on a card to expand its settings.

Account & Security page with the Login ID format, Password rules, and Session policy cards

Set the login ID format

OptionApplied rule
IDEnter 4–100 characters using letters, digits, _ . @ -. Start with a letter or digit. Email addresses are also accepted.
Email address onlyUse an email address such as name@example.com as the login ID.

Select Update to save. The format applies to future sign-ups, accounts added by an administrator, and ID changes. Existing IDs stay the same and can still be used to sign in.

Set password rules

Length and rotation

ItemProduct defaultRange and behavior
Minimum length (characters)84–128 characters
Change interval (days)00–3650 days. Set 0 for no expiration.
Reuse prevention count00–12 passwords. Set 0 to allow reuse.

Requirements

ItemProduct default
Require a letter (any case)On
Require an uppercase letterOff
Require a lowercase letterOff
Require a digitOn
Require a special characterOn
Must not contain the login IDOff

Requiring an uppercase or lowercase letter also enables Require a letter (any case). Stricter rules apply to future sign-ups and password setup or changes. Current passwords do not change immediately.

Set the session policy

Set how long users stay signed in and how many simultaneous sign-ins your organization allows.

ItemProduct defaultDescription
Access token lifetime (minutes)30 minutes5–1440 minutes. A shorter lifetime reduces how long a stolen token remains valid.
Session lifetime (days)7 days1–365 days. How long users stay signed in without activity when they have not selected Remember me.
Concurrent sign-ins51–100 devices. The oldest session is signed out when the limit is exceeded.
Remember meOnShows the Remember me option on the sign-in screen.
Remember-me lifetime (days)30 days1–365 days. How long users stay signed in without activity when they have selected Remember me.

If the server has its own settings, they take priority over the product defaults until you first save this policy.

Changes apply when a user next signs in or their sign-in session is renewed. Access tokens already issued remain valid until they expire. To apply different settings to one user, edit their account under Users.