Security settings
Require two-factor sign-in, set the session length, restrict the console to your network, and give new API keys a default expiry.
The Security tab under Settings sets the rules for signing in to your organization's console. The rules are enforced on every console request for the organization, not only shown. Changing them needs the owner or admin role. Other roles can read the tab.
These rules apply to people using the console. API keys are not affected: a key has its own IP allow-list and expiry, set on the key. See API keys.
Your own sign-in
The box at the top of the tab is about you, not the organization. It says whether your current session used a second factor, and when you signed in. Every member sees it and can use its links:
- Add an authenticator app
- Add a passkey or security key
- Create recovery codes
- Manage sign-in methods, when it is available, opens your account's sign-in methods in a new tab.
Each of the first three takes you to the sign-in page to register that method. Afterwards you are asked to sign in once more so that the new method is used, and you return to where you were.
A passkey or security key is offered as a second factor alongside your password, not in place of it.
Require two-factor authentication
Tick Require two-factor authentication for every member and press Save security settings.
From then on, a member who signed in without an authenticator app, a passkey or a security key is asked to sign in with one before they can use this organization.
You have to be signed in with a second factor yourself before you can turn this on. Until you are, the checkbox is disabled, and the text under it offers two links: set one up, or sign in with yours if you already have one.
Session length
Console session lifetime (hours) is how long a member can use the organization after signing in. It takes 1 to 720 hours and is measured from when the member last signed in. After that, the member signs in again. Enter 0 for the default of 12 hours.
Console IP allow-list
Console IP allow-list restricts the console for this organization to the addresses you list. Enter one IP address or CIDR range per line. Leave it empty to allow any address.
The field tells you when a line is not an IP address or a range, and the settings cannot be saved until you fix it.
Default API key expiry
Default API key expiry (days) is given to every new key that is created without an expiry of its own. Enter 0 and keys do not expire unless an expiry is set on the key.
Saving
Press Save security settings. The tab confirms with "Security settings saved."
A setting that would lock you out is refused. You cannot require two-factor sign-in from a session that did not use a second factor, and you cannot save an allow-list that leaves out the address you are connecting from. Fix the cause, then save again. Error codes are listed in the errors reference.
What a member sees when a rule refuses them
When one of these rules refuses a member's session, the console shows a single panel in place of the organization's screens. The panel names the organization and the one step that fixes it.
| Panel title | Why | What to do |
|---|---|---|
| This organization requires two-factor sign-in | The session did not use a second factor. | Press Sign in with two-factor if you already have one. Otherwise press Set up an authenticator app or Set up a passkey or security key. It takes a minute, and you are asked to sign in with it straight after. |
| Sign in again to continue | The sign-in is older than the session length. | Press Sign in again. |
| Not available from this network | Your address is not on the allow-list. | Connect from your organization's network or VPN, or ask one of its owners to add your address. |
The rules of one organization do not affect the others. Your other organizations stay available from the organization selector in the top bar, and you can still create a new one. See organization settings.
Related
- To have people sign in through your own identity provider, see single sign-on and SCIM.
Organization settings
Create an organization, keep its profile and billing details current, manage members and roles, transfer ownership, and close it.
Single sign-on and SCIM
Connect your SAML or OIDC identity provider, verify your email domains, map groups to roles, enforce single sign-on and provision members from your directory.