Configuring MFA, Password Rules, and Session Timeouts

Open Settings > Authentication. This area requires Full Access and Manage Settings.

The Security Policy card controls baseline authenticated workspace access.

Session Timeout

  • Enable session timeout policy: activates idle and maximum-session limits.
  • Idle: inactivity minutes before sign-out; the form supports 5โ€“240 minutes.
  • Warning: warning interval in minutes; it must be shorter than the idle timeout.
  • Max Hrs: maximum session duration, from 1โ€“24 hours.

Select Save Session Policy after editing the values.

Passwords

Enable enforcement to apply the configured password policy. Set Minimum Length and the available requirements for uppercase letters, lowercase letters, numbers, symbols, spaces, common-password blocking, and blocking names or company terms. Select Save Password Policy.

Multi-Factor Authentication

The workspace policy can require authenticator-app MFA before protected access. Roles may also require MFA independently. A workspace-level optional setting does not necessarily remove a role-level requirement.

Roll out changes

  1. Confirm affected users and administrators can satisfy the intended sign-in requirements.
  2. Change the relevant control and follow any confirmation.
  3. Save the associated policy fields.
  4. Verify sign-in and session behavior before wider rollout.

Keep a qualified administrator able to access the workspace. Security changes can affect active users; do not treat them as personal preferences.