Security Settings
Manage password, two-factor authentication, and session security
Security Settings
Protect your account with strong passwords, two-factor authentication, and session management.
Password Management
Changing Your Password
- Go to User Settings > Security
- Click Change Password
- Enter current password
- Enter new password (twice)
- Click Update Password
Password Requirements
Passwords must meet:
- Minimum 8 characters
- At least one uppercase letter
- At least one lowercase letter
- At least one number
- At least one special character
Password Best Practices
- Use a unique password for Securtea
- Consider using a password manager
- Don't share your password
- Change if you suspect compromise
If your organization uses SSO, password management is handled by your identity provider.
Two-Factor Authentication (2FA)
Why Use 2FA?
Two-factor authentication adds an extra layer of security:
- Something you know (password)
- Something you have (authenticator app)
Even if your password is compromised, 2FA protects your account.
Setting Up 2FA
- Go to User Settings > Security
- Find Two-Factor Authentication
- Click Enable 2FA
- Scan QR code with authenticator app
- Enter the 6-digit code
- Save backup codes
Authenticator Apps
Compatible apps include:
- Microsoft Authenticator
- Google Authenticator
- Authy
- 1Password
- Bitwarden
Backup Codes
When enabling 2FA, you receive backup codes:
- 10 one-time use codes
- Use if you lose access to authenticator
- Store securely (password manager, safe)
Regenerating Codes:
- Go to 2FA settings
- Click Regenerate Backup Codes
- Old codes are invalidated
- Save new codes
Disabling 2FA
To turn off 2FA:
- Go to Security settings
- Click Disable 2FA
- Enter a current 2FA code
- Confirm
Disabling 2FA reduces your account security. Only do this if necessary.
Session Management
Active Sessions
View all your active sessions:
| Column | Description |
|---|---|
| Device | Browser/device info |
| Location | Approximate location |
| Last Active | Recent activity |
| Current | This session indicator |
Ending Sessions
End a specific session:
- Find session in list
- Click End Session
- That session is logged out
End all other sessions:
- Click End All Other Sessions
- All sessions except current are logged out
Use this if you suspect unauthorized access.
Session Security
Sessions are secured with:
- Encrypted cookies
- 5-minute refresh interval
- Automatic expiration
- Cross-site protection
Connected Accounts
Viewing Connected Accounts
See accounts linked to your profile:
- Microsoft (if used for sign-in)
- SSO provider (if applicable)
Linking Accounts
Add additional sign-in methods:
- Click Link Account
- Choose provider (Microsoft)
- Authenticate with that provider
- Account is linked
Unlinking Accounts
Remove a connected account:
- Find account in list
- Click Unlink
- Confirm
You must have at least one sign-in method. You cannot unlink your only authentication method.
Security Events
Recent Activity
View recent security events:
- Sign-ins
- Password changes
- 2FA changes
- Failed sign-in attempts
Suspicious Activity
If you notice unfamiliar activity:
- End all other sessions immediately
- Change your password
- Enable or verify 2FA
- Contact support if needed
Organization Security Requirements
Your organization may enforce:
| Policy | Description |
|---|---|
| Required 2FA | Must enable two-factor |
| Password Policy | Minimum requirements |
| Session Timeout | Maximum session length |
| SSO Required | Must use SSO, no password |
Contact your organization admin about security policies.
Account Recovery
Forgot Password
If you forget your password:
- Click Forgot Password on sign-in
- Enter your email
- Receive reset link
- Create new password
Lost 2FA Access
If you lose access to your authenticator:
- Use a backup code
- Contact support with verification
- 2FA may be reset by admin
Locked Account
If your account is locked:
- Wait for lockout period (15 minutes)
- Contact support for immediate unlock
- Verify your identity
Best Practices
Regular Security Review
Periodically:
- Check active sessions
- Review security events
- Update password
- Verify recovery info
Device Security
Protect devices you use:
- Keep devices updated
- Use device passwords/biometrics
- Don't use public computers
- Sign out when done
What's Next?
- Profile Settings - Account information
- Notification Preferences - Alert settings
- SSO Configuration - Enterprise sign-in