Sign-in security settings control inactive-session timeouts and whether users identify themselves with an email address or another username.
Open Security settings #
Browse to Admin System Preferences Settings Security.
Notice: System administration access is required. Changes affect how users sign in, so plan them before updating an established account.
Open the security settings #
Open Admin, System, then Security. The page can also include single sign-on settings, which are covered separately.
Set the inactive-session timeout #
- Find the idle-session or session-timeout setting.
- Enter the allowed number of inactive minutes. The current screen accepts values from 5 through 480 minutes.
- Select Save.
A shorter timeout reduces unattended access but can interrupt users who leave an unsaved form open. Ask users to save before stepping away from the application.
Use email addresses as usernames #
Turn on Use email address as the username when the organization wants email addresses to be the standard login identifier.
Before changing an existing account:
- Confirm that every active employee has a unique, current email address.
- Review invitation and employee-creation procedures.
- Tell users which value to enter on the sign-in page.
- Save the change.
- Test with a non-administrator user.
Understand how other access settings work together #
Security roles control the screens and reports a user can access after sign-in. Employee account settings control whether the login is active and which roles are assigned.
Single sign-on is configured separately. See Configure single sign-on.