Skip to content

Security Settings

The Security Settings module provides configuration options for authentication, user access, and system security policies.

Navigation: Settings → Security

Overview

Security Settings control how users authenticate, manage their accounts, and access the system. These settings are critical for maintaining system security and ensuring appropriate access control.

Security Configuration Options

User Authentication and Access

  • User Login Settings - Configure login behavior, user self-service account management options, and authentication methods

User Registration and Account Recovery

  • Registration Settings - Configure user registration policies and account creation requirements
  • Password Reset Settings - Configure password reset functionality and account recovery procedures

Additional Security Headers

  • Security Headers - Configure HTTP security headers for enhanced browser security

Key Security Considerations

Authentication

  • Configure login options based on your organization's security requirements
  • Consider enabling external authentication (SSO, Azure AD) for enterprise deployments
  • Ensure at least one administrator has a backup authentication method

User Self-Service

  • Balance convenience with security by selectively enabling user self-service options
  • Restrict critical account changes (username, email) to administrative control
  • Allow non-critical changes (phone number) for user flexibility

Password Security

  • Implement strong password policies
  • Configure password reset procedures for account recovery
  • Consider multi-factor authentication for enhanced security

External Authentication

  • For enterprise environments, consider implementing Single Sign-On (SSO)
  • Test external authentication thoroughly before disabling local password login
  • Maintain backup authentication methods for administrators

Security Best Practices

  • Review all security settings during initial setup
  • Align security configuration with organizational policies and compliance requirements
  • Enable external authentication (SSO) for enterprise deployments
  • Regularly audit user accounts and access patterns
  • Implement password complexity requirements
  • Document security policies and configurations
  • Test security policy changes in non-production environments first