Configure sign-in and security settings
Tightening how Authors sign in reduces the risk of compromised accounts and keeps your subscriber data protected. As an admin you can set password rules, require two-factor authentication (2FA), and control how long an inactive session stays open.
Before you begin
- You need an admin role with permission to manage account or security settings.
- Look for the security or authentication area under your account or admin settings (confirm the exact steps in your account).
- Decide your target policy in advance: minimum password length and complexity, whether 2FA is required for everyone, and how many minutes of inactivity should end a session.
- If you plan to use SSO with Microsoft Entra ID, review that setup first, since single sign-on changes how these password and 2FA rules apply.
Steps
- Open your account or admin settings and go to the sign-in or security section.
- Under password rules, set the minimum length, required character types, and expiry or reuse limits, then save.
- Turn on two-factor authentication. Choose whether it is required for all Authors or optional, and pick the allowed methods (for example, an authenticator app) (confirm the exact steps in your account).
- Set the session timeout to the number of minutes of inactivity after which Authors must sign in again.
- Save your changes and, if prompted, confirm that the new rules apply to existing Authors.
Result
New rules take effect on the next sign-in. Authors below the password standard are prompted to update their password, and any enrolled Authors are asked to complete 2FA. Inactive sessions now end at your chosen timeout.
Related
Canonical terms: Author, Edition, Folder (Project Folder), Broadcast. See the Glossary.