Skip to content

Configure security policy

Security settings control how people sign in to your workspace and what happens when they get it wrong. Several of these settings take effect for everyone the next time they sign in, so they are worth changing deliberately rather than experimentally.

Required role: Administrator.

  1. Go to Settings → Security.
  2. Under Password Policy, set the Minimum Length, the Password Expiry (days), and the character requirements.
  3. Under Session Management, set the Session Timeout (minutes) and Max Concurrent Sessions.
  4. Under Login Protection, set the Max Failed Attempts and Account Lock Duration (min).
  5. Set Require MFA for All Users if you want multi-factor authentication enforced.
  6. Add an IP Allowlist if you are restricting where people can sign in from.
  7. Select Save Changes.
OptionDescription
Minimum LengthThe shortest password permitted.
Password Expiry (days)How long a password lasts. Set to 0 to disable expiry.
Require UppercaseAt least one uppercase character.
Require NumberAt least one digit.
Require Special CharacterAt least one of !@#$%^&*.

Zero disables expiry rather than expiring passwords immediately, which is the opposite of how the field reads at a glance. Confirm you have entered what you meant.

Forced expiry is contested practice: it produces predictable variations of the same password more often than it produces genuinely new ones. Decide it on your own security standard rather than by habit.

OptionDescription
Session Timeout (minutes)How long an idle session lasts.
Max Concurrent SessionsHow many sessions one user may hold, across devices.

Concurrent sessions is per user across devices, so a person using a laptop and a phone is already using two. Set it to one and you will log people out of one device by using another.

Example: an HC Corp UK Ltd employee who checks payslips on a phone and works on a laptop needs at least two.

Failed attempts and lock duration together decide what a mistyped password costs. Set the attempt count high enough to survive genuine typos and the lock duration short enough that a locked-out employee is not blocked for a working day.

An administrator can unlock an account without waiting for the duration to elapse.

Require MFA for All Users obliges everyone to set up multi-factor authentication. Humavera warns plainly that all users will be required to set it up on their next login.

That is a change every person in your workspace meets, not a background setting. Tell people it is coming before you switch it on, or your support queue will tell you afterwards.

Example: switching this on at HC Corp UK Ltd means every employee meets an MFA setup step the next time they sign in — including warehouse staff signing in rarely, who will need help.

The allowlist takes one CIDR block per line, and leaving it empty allows all IP addresses. An empty list is unrestricted, not blocked.

This is the setting most likely to lock you out of your own workspace. Verify your own address is covered before saving, and be certain about remote workers and anyone on a changing home connection.

These settings describe what the controls do. What your organization is obliged to enforce — retention, access standards, or authentication requirements for regulated work — is a matter for your own security and legal advisers.

Changes apply to the workspace on save. Password policy changes are met at the next password change; MFA is met at the next sign-in; session and IP rules apply immediately. Individual users manage their own two-factor setup in their own settings.