Configure security policy
What this achieves
Section titled “What this achieves”Security settings control how people sign in to your workspace and what happens when they get it wrong. Several of these settings take effect for everyone the next time they sign in, so they are worth changing deliberately rather than experimentally.
Required role: Administrator.
- Go to Settings → Security.
- Under Password Policy, set the Minimum Length, the Password Expiry (days), and the character requirements.
- Under Session Management, set the Session Timeout (minutes) and Max Concurrent Sessions.
- Under Login Protection, set the Max Failed Attempts and Account Lock Duration (min).
- Set Require MFA for All Users if you want multi-factor authentication enforced.
- Add an IP Allowlist if you are restricting where people can sign in from.
- Select Save Changes.
Password policy
Section titled “Password policy”| Option | Description |
|---|---|
| Minimum Length | The shortest password permitted. |
| Password Expiry (days) | How long a password lasts. Set to 0 to disable expiry. |
| Require Uppercase | At least one uppercase character. |
| Require Number | At least one digit. |
| Require Special Character | At least one of !@#$%^&*. |
Zero disables expiry rather than expiring passwords immediately, which is the opposite of how the field reads at a glance. Confirm you have entered what you meant.
Forced expiry is contested practice: it produces predictable variations of the same password more often than it produces genuinely new ones. Decide it on your own security standard rather than by habit.
Sessions
Section titled “Sessions”| Option | Description |
|---|---|
| Session Timeout (minutes) | How long an idle session lasts. |
| Max Concurrent Sessions | How many sessions one user may hold, across devices. |
Concurrent sessions is per user across devices, so a person using a laptop and a phone is already using two. Set it to one and you will log people out of one device by using another.
Example: an HC Corp UK Ltd employee who checks payslips on a phone and works on a laptop needs at least two.
Login protection
Section titled “Login protection”Failed attempts and lock duration together decide what a mistyped password costs. Set the attempt count high enough to survive genuine typos and the lock duration short enough that a locked-out employee is not blocked for a working day.
An administrator can unlock an account without waiting for the duration to elapse.
Requiring MFA
Section titled “Requiring MFA”Require MFA for All Users obliges everyone to set up multi-factor authentication. Humavera warns plainly that all users will be required to set it up on their next login.
That is a change every person in your workspace meets, not a background setting. Tell people it is coming before you switch it on, or your support queue will tell you afterwards.
Example: switching this on at HC Corp UK Ltd means every employee meets an MFA setup step the next time they sign in — including warehouse staff signing in rarely, who will need help.
IP allowlist
Section titled “IP allowlist”The allowlist takes one CIDR block per line, and leaving it empty allows all IP addresses. An empty list is unrestricted, not blocked.
This is the setting most likely to lock you out of your own workspace. Verify your own address is covered before saving, and be certain about remote workers and anyone on a changing home connection.
A note on responsibility
Section titled “A note on responsibility”These settings describe what the controls do. What your organization is obliged to enforce — retention, access standards, or authentication requirements for regulated work — is a matter for your own security and legal advisers.
What happens next
Section titled “What happens next”Changes apply to the workspace on save. Password policy changes are met at the next password change; MFA is met at the next sign-in; session and IP rules apply immediately. Individual users manage their own two-factor setup in their own settings.
Related
Section titled “Related”© 2025-2026 Humavera Documentation - BPilot Ltd. All Rights Reserved