Security settings
Set the password rules, two-factor authentication requirement and sign-in behaviour for everyone in your organisation.
Set the password rules, two-factor authentication requirement and sign-in behaviour for everyone in your organisation.
The Security page is where an administrator controls how people in your organisation sign in. It covers the password rules, whether everyone must use two-factor authentication, and which verification methods they can choose. Only users with the System Admin role can open it. Anyone else who tries sees an Access Denied page with the message "Only admins can manage security settings."
Go to Settings and open Security. If your organisation belongs to a company group, a Company selector appears at the top of the page. Choose the company you want to configure and every setting below applies to that company only.
Password policy
The Password Policy card sets the rules for passwords chosen by users in your organisation. Nothing on this card takes effect until you click Save at the top right of the page. You will see "Saved successfully" when it has worked.
- Change the settings you want on the Password Policy card.
- Click Save.
The options are:
- Minimum Length: the fewest characters a password can have. Enter a whole number from 12 to 128. The default is 12, which is also the lowest value allowed. If you clear the box, it goes back to 12.
- Require Uppercase Letter: on by default.
- Require Lowercase Letter: on by default.
- Require Number: on by default.
- Require Symbol: on by default. This means at least one character that is not a letter or a number.
- The switch beside the text "Reject passwords found in known data breaches (via Have I Been Pwned)." It is on by default and is saved with the rest of the policy. It has no heading of its own, only that line of text.
- Password Expiry (Days): how many days a password lasts before the user must change it. Enter a whole number from 0 to 365. The default is 0, which means passwords never expire.
What the password rules affect
The rules apply when someone next sets or changes a password: accepting an invitation, resetting a forgotten password, or changing it from their account. Existing passwords are not checked against the new rules, and nobody is signed out because you saved a change.
The uppercase and lowercase switches work as a pair. The mixed-case rule is only applied when both are on. Turning off only one of them means mixed case is not asked for at all.
The change password form inside the app is stricter than your settings. It always asks for at least 12 characters and no more than 100, with an uppercase letter, a lowercase letter, a number and a special character, whatever you have switched off on this page. Loosening the policy does not relax that form. Tightening it does apply, for example a minimum length of 16.
Password expiry
A password expires when the time since it was last changed passes your Password Expiry (Days) value. The check runs whenever the user does something in the app, so it catches people who are already signed in as well as people signing in fresh.
When a password has expired, the user is sent to a page headed "Your password has expired", with the text "For security, please set a new password to continue." They enter their Current password, a New password and Confirm new password, then click Change password. The new password must be different from the current one. Once it is accepted they see "Password changed successfully. Please log in again." and are signed out.
Before you set a value:
- Lowering the number takes effect straight away. If you change 365 to 90, everyone whose password is more than 90 days old is asked to change it on their next action.
- Users with no recorded password change date, such as migrated users, are not treated as expired. Their clock starts from their next successful sign-in, so switching expiry on does not lock them out.
- Setting the value back to 0 stops expiry for everyone.
Two-factor authentication policy
The Two-factor authentication policy card controls whether two-factor authentication is compulsory. Unlike the password card, its controls save the moment you use them and show "MFA policy updated." The Save button is not needed for these.
- Require two-factor authentication for all users: a switch, off by default.
- Verification methods staff may use: two tick boxes, Authenticator app and Email. Both are ticked by default. You cannot untick the last one. If you try, you get the message "Keep at least one method enabled."
Under the methods is the line "Anyone already set up with a method you turn off keeps using it until they change it." Removing a method only stops people from choosing it when they set up from that point on. A person who tries to add a method you have removed is refused with the message "That verification method is not permitted by your organisation".
Who is affected
With the switch on, every user in the organisation must have two-factor authentication. That includes Members, Recruiters, hiring managers and every other role.
Users with the Admin, HR or Group Admin role must use two-factor authentication whatever this switch says. If you are one of them, the card shows "Platform-mandated for Admin, HR, and Group Admin roles". Until they enrol they are blocked from protected pages and taken to the setup screen, so you cannot turn it off for those roles.
What users see
There is no grace period. As soon as you turn the requirement on, a user who has not set up two-factor authentication is redirected to a page called "Set up two-factor authentication" the next time they open a page in the app. It says "Your organisation requires two-factor authentication. Please set it up to continue." There is no option to skip it. They click Enable two-factor authentication, then:
- Under Choose how to verify, pick Authenticator app or Email. Only methods you have allowed are offered.
- For an authenticator app, scan the QR code (or type in the code shown) and enter the 6-digit code. For email, enter the 6-digit code sent to their work email address. A fresh email code can be requested with Send a new code.
- Save the recovery codes shown, tick I have saved my recovery codes, and click Continue to app.
From then on they enter a code each time they sign in. Users who already had two-factor authentication set up notice nothing.
While the requirement is on, ordinary users cannot switch two-factor authentication off or remove their methods. The buttons are hidden and their profile shows "Two-factor authentication is required by your organisation." Admin, HR and Group Admin users can add and remove individual methods but always keep at least one. The step-by-step for users is in the article "Setting up two-factor authentication".
Turning the requirement off
Switching Require two-factor authentication for all users off does not remove anyone's setup. Everyone keeps signing in with a code. Users outside the Admin, HR and Group Admin roles can then remove their methods themselves from their profile if they want to.
Sessions and staying signed in
This page has no setting for session length or inactivity timeouts, so behaviour is the same for every organisation.
- On the sign-in page users see a tick box, Remember me for 30 days, unticked by default. Ticked, they stay signed in for up to 30 days. Unticked, they are signed out when they close the browser.
- Someone who has been inactive for too long sees "Session Expired" with "Your session has expired due to inactivity. Please log in again."
- Changing a password ends every signed-in session for that user, on all devices. This includes replacing an expired password.
Single sign-on and other cards on this page
If single sign-on is part of your plan, the page also has a Single sign-on card, a Group SSO domain routing card for company groups, and an Enforce single sign-on card. The last has a switch labelled Require single sign-on for all users. When it is on, users must sign in through your SSO provider and password login is turned off.
The settings for hiding candidate CVs from Members and letting Hiring Managers add a CV used to sit on this page. They are now under Roles & Permissions. In their place you will see "Security permissions have moved to Roles & Permissions." with a Go to Roles & Permissions link. The article "Understanding roles and permissions" covers that page.