Organization Settings: Security Tab
The Security tab sets portal-wide session, password and account-communication defaults. Go to Setup > Manage > Organization Settings and open the Security tab.
General Settings
| Field | Notes |
|---|
| Session Timeout | How long users stay logged in before the server ends the session. |
| Cookie Policy | Private is recommended for highest security. Shared relaxes the rules and allows Magentrix pages to be placed in an iframe on other websites. |
| Enable Maintenance Mode | Puts the portal into maintenance mode. See the warning below. |
| Under Maintenance Message | The message shown to users while maintenance mode is on. |
| File Upload Allowed Extensions | A list of accepted file types. Type an extension and press Enter to add it. |
| Re-Enable User Upon Login | Host only. Administrators do not see this field. |
Maintenance mode logs everyone out. Enabling it terminates all user sessions and puts the application into maintenance mode for as long as the flag is set. Tell your users in advance.
Keep the upload allowlist tight. Anything executable or web-renderable is a common source of security incidents. Review the list periodically rather than adding to it ad hoc.
Password Settings
| Field | Notes |
|---|
| Minimum Password Length | The shortest password a user may set. |
| Password Complexity | Low - no restrictions. Medium - must include a number and capital letters. High - must also include special characters. |
| Password Expires | How long a password remains valid before the user must change it. |
| Remember Password History | How many previous passwords are remembered and blocked from reuse. |
| Maximum Invalid Login Attempts | Failed attempts allowed before lockout. |
| Lockout Period | Minutes a user is locked out after too many failed attempts. |
| Forgot Password Behavior | How the portal handles a password-recovery request. |
| Use Preset Security Questions | Presents a dropdown of preset security questions as a recovery option. |
Email Communication Settings
The templates the platform uses for account lifecycle email. Each points at a template from Email Templates.
| Template | Used for |
|---|
| New User Template | Notifying new users. |
| Activation Template | Activating new community users when a verification step is required. |
| Forgot Password Template | The password-recovery flow started from the Forgot Password page. |
| Reset Password Template | When an administrator resets a password for a user. |
Templates must be marked Ready to use before an automation will pick them up. If a template does not appear in these pickers, check its ready state first.
New User Activation Reminder Settings
Reminds new users who have not logged in after a set number of days from their activation date.
| Field | Notes |
|---|
| Enable Reminders | The master switch. The three fields below appear only when it is on. |
| Reminder Email Template | The template used for the reminder. |
| First Reminder | Days before the first reminder is sent. Can be overridden per user role. |
| Second Reminder | Days before the second reminder is sent. Can be overridden per user role. |
See More
<< Application Tab | Members Tab >>