Nothing on this screen is enforced by the screen itself — every rule is applied by the server on
every sign-in and every password change. What this screen does is describe the numbers, so an
organisation that has never opened it is not an organisation with no policy: it is running on the
product’s own defaults until somebody changes them.
What a password has to be
Minimum length, and which character classes are required — a capital letter, a lower-case letter, a digit, a symbol.What it may not be again
How many previous passwords are remembered, and the shortest time a new one must be kept before being changed again — without a minimum age, someone can cycle through their history in a minute and land back on the password you were stopping them reusing. Passwords can also be set to expire after a number of days; left at zero, they never do.When somebody guesses
How many failed attempts lock an account, and for how long. Locking the wait can also double on each repeat failure, up to a day, for the ordinary case where the same person still hasn’t found their password. An administrator clears a lockout from people and access, and doing so writes an audit row naming who cleared whose.Whether a password is enough
Two-step sign-in, for anybody signing in with a password:
Start with Anybody may turn it on rather than moving straight to Everybody: the middle
setting is what lets people enrol in their own time, ahead of the day it becomes required for
everyone.
Enrolling shows a QR code for an authenticator app and a set of recovery codes, shown once, on the
way in — not on a screen you have to sign in again to find. Each recovery code signs in once, and
is the way back from a lost phone that doesn’t need an administrator.
This governs password sign-ins only. Somebody arriving through an identity provider is not asked
again here — their second factor lives with their provider, administered by their own security
team. See identity providers.

