Open Settings > Authentication. This area requires Full Access and Manage Settings.
The Security Policy card controls baseline authenticated workspace access.
Select Save Session Policy after editing the values.
Enable enforcement to apply the configured password policy. Set Minimum Length and the available requirements for uppercase letters, lowercase letters, numbers, symbols, spaces, common-password blocking, and blocking names or company terms. Select Save Password Policy.
The workspace policy can require authenticator-app MFA before protected access. Roles may also require MFA independently. A workspace-level optional setting does not necessarily remove a role-level requirement.
Keep a qualified administrator able to access the workspace. Security changes can affect active users; do not treat them as personal preferences.