Enable security policies for user authentication and session management to improve application security. You can control the strength of user IDs and passwords, manage session time-outs and the disabling of operator IDs, control the auditing of login events, and implement CAPTCHA and multi-factor authentication.
Note: The password, lockout, audit, and operator disablement security policies are supported in offline-enabled applications. Multi-factor authentication policies are applied only when two-factor authentication is used in custom authentication policies and in application case flows. The operator disablement policy is not enforced unless the Disable Dormant Operators agent is enabled.
If needed, define the two-factor authentication policies.
If needed, define an operator disablement policy.