This setting requires Organisation Access permissions which currently can only be added internally by Trybe. Please contact your Onboarding Manager or Trybe Support ([email protected]) should you require access to this setting.
Once you have been granted access, to access your organisation security settings you can head to head to Settings > System > Organisation security.
These settings are Organisation wide settings. If there are multiple Trybe sites under your Organisation, when you set this up on one site, the same rule will apply to all sites linked to that Organisation. Please ensure you are in a position to make changes to settings that affect all sites within the organisation.
Here you will be able to enable additional security options because ensuring your site has good security measures in place is of high importance to us at Trybe!
Here you can set up "Password age policy" and "Enforce two factor authentication".
Password age policy
Here you can set the Maximum password age from the below options:
None (user will never be forced to update their password automatically)
1 month (*the next time the user logs in after their password has reached a month they'll be asked to update their password)
3 months*
6 months*
1 year*
Select "Save changes" and the changes will be put in place. When a users password has exceeded the Maximum password age as set up for your users, they will be asked to update their password when they next log in.
Please view the guide here for more info.
Enforce two factor authentication
Here you can toggle on whether or not you want all users within the Organisation to be required to use two factor authentication to access the system.
To do this simply click the toggle to enable enforcing two factor authentication and "Save changes".
If this is toggled on this will mean that when your users (all users across the whole organisation) next log into the system, if they do not yet have Two Factor Authentication set up, they will be forced to set this up on the next login attempt. They will not be able to log in until this is set up.
For example, this user has tried to log in after "Enforce two factor authentication" has been enabled, and this is the screen they see as they did not yet have 2FA set up...
As you can see the user has to "Complete 2FA set up" to continue. For more details on 2FA please view guide here.