Skip to main content

Organisation security

Written by Emily O'Shea

This setting requires Organisation Access permissions which currently can only be added internally by Trybe. Please contact your Onboarding Manager or Trybe Support ([email protected]) should you require access to this setting.

Once you have been granted access, to access your organisation security settings you can head to head to Settings > System > Organisation security.

These settings are Organisation wide settings. If there are multiple Trybe sites under your Organisation, when you set this up on one site, the same rule will apply to all sites linked to that Organisation. Please ensure you are in a position to make changes to settings that affect all sites within the organisation.

Here you will be able to enable additional security options because ensuring your site has good security measures in place is of high importance to us at Trybe!

Here you can set up "Password age policy" and "Enforce two factor authentication".

Password age policy

Here you can set the Maximum password age from the below options:

  • None (user will never be forced to update their password automatically)

  • 1 month (*the next time the user logs in after their password has reached a month they'll be asked to update their password)

  • 3 months*

  • 6 months*

  • 1 year*

Select "Save changes" and the changes will be put in place. When a users password has exceeded the Maximum password age as set up for your users, they will be asked to update their password when they next log in.

Please view the guide here for more info.

Enforce two factor authentication

Here you can toggle on whether or not you want all users within the Organisation to be required to use two factor authentication to access the system.

To do this simply click the toggle to enable enforcing two factor authentication and "Save changes".

If this is toggled on this will mean that when your users (all users across the whole organisation) next log into the system, if they do not yet have Two Factor Authentication set up, they will be forced to set this up on the next login attempt (if you don't click the "logout users" option so it is prompted sooner, see details below). They will not be able to log in until this is set up.

For example, this user has tried to log in after "Enforce two factor authentication" has been enabled, and this is the screen they see as they did not yet have 2FA set up...

As you can see the user has to "Complete 2FA set up" to continue. For more details on 2FA please view guide here.

Option to force all users to log out so they can set up their 2FA

When you enable two-factor authentication and "Save changes", then a pop up will appear for you to choose if you wish to logout all users now (across the whole organisation)...

You can "Confirm" if you want this to be actioned now. If you don't want to force log out all of your users then you can select "Cancel" instead.

At any other time you can select the "Logout users" button directly if you want to log out all users across your whole organisation...

Please note, once you select "Logout users" this will log out users across the whole organisation so please ensure you action this when the time is right for you and your team.

Users won't get logged out immediately, their token will get revoked, so if they try to use the application in a way that requires new data to be fetched from our API after you've confirmed the logout users modal, then they'll get redirected to the login page.

It will not log out users managed by SSO.

Did this answer your question?