The Security section provides features relating to user authentication, application access, and Single Sign On. Options configured here will affect the entire system.
Enforce Password Policy
If enabled, a variety of further password-related items are made available for configuration, and password expiry and length limits are enforced.
|
Require Uppercase Characters
If enabled, users must include a upper-case character when changing their password.
This option is only available if Enforce Password Policy is enabled.
|
Require Lowercase Characters
If enabled, users must include a lower-case character when changing their password.
This option is only available if Enforce Password Policy is enabled.
|
Require Number Characters
If enabled, users must include a numeric character when changing their password.
This option is only available if Enforce Password Policy is enabled.
|
Require Symbol Characters
If enabled, users must include a symbol-type character when changing their password.
This option is only available if Enforce Password Policy is enabled.
|
Password Expiration
The number of days a password is valid for before it needs to be changed by the user.
This option is only available if Enforce Password Policy is enabled.
|
Minimum Password Length
The minimum length of a password that can be set for users.
This option is only available if Enforce Password Policy is enabled.
|
Prevent Using Previous Passwords
If enabled, users cannot reuse a recent password when changing their password.
This option is only available if Enforce Password Policy is enabled.
|
Maximum Login Attempt Failures
How many failed login attempts a user can make before they are automatically temporarily locked out. It can range between 1 and 100 attempts.
|
Login Failure Lockout Duration
How long (in minutes) a user will be locked out for if they trigger the automated lock for failed login attempts. It can range between 1 and 60 minutes.
|
Accepted Origins
Scripting will accept external connections from any hostnames specified in this list. If no options are configured or it has a value of *, then all originating hostnames are permitted (global whitelist).
Note: If using an SSO authentication scheme, then this option must either be a globally whitelisted or include the SSO's origin. Failure to do so will cause login attempts to be rejected as from an untrusted origin.
|
Enable Password Reset Request
For security reasons, the user will be given no indication if they enter a non-existent username into the request. They will also see a notification that an email has been sent, even if it is waiting in the queue with non-functional mail credentials or a disabled Message Processing service.
|
Remember Me
If enabled, login details will be remembered following the next successful login.
|
Single Sign On Only
|
|