You are here: Home / Extras / Settings / Basic settings / Security

Settings
Security
Password Policies
Password policies are managed via the Security tab in the Basic Settings. These configurations govern the requirements for creating and validating user passwords and serve to protect the entire system from unauthorized access.
- Passwords expire: If this is set to “never,” the passwords assigned to users remain valid indefinitely. In addition, you can set different time intervals for when the password must be changed.
- Minimum password length: The minimum password length is set to 6 characters by default in the system and must not be shorter than this value.
- Passwords must contain both uppercase and lowercase letters: If the option requiring the use of both uppercase and lowercase letters is enabled, the system enforces a combination of uppercase and lowercase letters whenever a password is changed.
- Passwords must contain special characters: To further enhance the security of your passwords, you can enable the requirement to use special characters. This requires users to include at least one special character in their password.
Two-factor authentication
Two-factor authentication (2FA) is an important security measure that significantly improves the protection of your user accounts. It adds an additional layer of security over the conventional combination of client name, user name and password.
- allow: By selecting this option, you allow individual users to activate two-factor authentication independently for their respective user account. This offers a flexible solution where each user can decide for themselves whether they want to use the additional security layer.
- force: The “Force” option can be used to activate 2FA for all users. By setting this option, all users who do not have an active 2FA will be logged out overnight and forced to set up 2FA the next time they log in. If the option is active, the last active 2FA method cannot be deleted.
Please note that the administrative right “User management” must be activated for all users in order to enforce 2FA. - prevent: If you select this option, two-factor authentication is deactivated system-wide. This means that no users have the option to set up or use 2FA for their accounts. If this option is selected later, all existing 2FAs will be deleted.
If the “Enable ‘Remember this device for 30 days’ option” is selected, when the second factor is requested, the system ensures that the user will not have to re-enter the second factor for the next 30 days when using their current device (browser). After 30 days have passed, or if you use a different device (browser), you must re-enter the second factor. The 30 days are also reset for the user if the 2FA is changed in the user settings or the password is changed.

Entry
Dashboard
Contacts
Properties
Email
Calendar
Tasks
Acquisition Cockpit
Audit-proof mail archiving
Automatic brochure dispatch
Billing
Groups
Intranet
Marketing Box
Multi Property module
Multilingual Module
onOffice sync
Presentation PDFs
Process manager
Project Management
Property value analyses
Enquiry Manager
Showcase TV
Smart site 2.0
Statistic Tab
Statistics toolbox
Success Cockpit
Time Tracking
Address from clipboard
Text block
Customer communication
External Tools
Favorite links
Calculating with formulas
Mass update
onOffice-MLS
Portals
Property import
Quick Access
Settings
Templates
Step by step


