You are here: Security > Security Policies > Enabling security policies

Enabling security policies

Enable security policies for user authentication and session management to improve application security. You can control the strength of user IDs and passwords, manage session time-outs and the disabling of operator IDs, control the auditing of login events, and implement CAPTCHA and multi-factor authentication.

The password, lockout, audit, and operator disablement security policies are supported in offline-enabled applications. Multi-factor authentication policies are applied only when two-factor authentication is used in custom authentication policies and in application case flows. The operator disablement policy is not enforced unless the Disable Dormant Operators agent is enabled.

  1. Click Designer Studio > Org & Security > Authentication > Security Policies.
  2. Select Enable frequently required policies to enable the policies that control the strength of authenticators, manage session timeouts, control the auditing of login events, and implement CAPTCHA.
  3. If Enable frequently required policies is checked, define the following policies:
  4. If needed, define the two-factor authentication policies.

  5. If needed, define an operator disablement policy.

  6. Click Submit.