Security administration

Authentication policy

Configure sign-in methods, MFA requirements, session lifetime, and password rules.

Loading
Platform policy
Global platform defaults

Tenant admins use their tenant ID. Platform admins can leave this blank for global defaults.

Values are saved in minutes. The API accepts 5 minutes up to 24 hours.

Require MFA for password login

Users without an active MFA factor cannot create a password session.

Sign-in methods
Provider availability for the selected policy scope.
Sign-in methods
Password

Required for administrator recovery.

Google

GOOGLE

Email OTP

EMAIL_OTP

Phone OTP

PHONE_OTP

Passkeys

WEBAUTHN

MFA factors
Allowed second-factor methods and passkey registration.
MFA factors
Authenticator app

TOTP

Email OTP

EMAIL_OTP

SMS OTP

SMS_OTP

Passkey

WEBAUTHN

Password rules
Policy validation used by signup and future password changes.
Uppercase and lowercase letters
Number
Symbol
Changes are audited immediately after save.