Difference between revisions of "Cloudwork.ID Settings"
Jump to navigation
Jump to search
Line 37: | Line 37: | ||
|Multifactor Methods || Control whether users can use SMS as an MFA option or not, this option is so school do not get charged extra for SMS cost listed in the [https://wiki.studentnet.net/index.php/2023_Cloudwork_pricing this documentation] | |Multifactor Methods || Control whether users can use SMS as an MFA option or not, this option is so school do not get charged extra for SMS cost listed in the [https://wiki.studentnet.net/index.php/2023_Cloudwork_pricing this documentation] | ||
|- | |- | ||
− | |Reject Compromised Passwords || Control | + | |Reject Compromised Passwords || Control when a user updates their password, whether to check the user's password against the dark web via HaveIBeenPwned's.facility. More information located [https://haveibeenpwned.com/Passwords here]. Compromised dataset is up to date using HaveIBeenPwned's online anonymous API. |
|- | |- | ||
|Compromised Password Threshold || If Reject Compromised Passwords is enabled, a limit can be set for how many times the password has been seen before the password a user sets gets rejected | |Compromised Password Threshold || If Reject Compromised Passwords is enabled, a limit can be set for how many times the password has been seen before the password a user sets gets rejected |
Revision as of 10:13, 30 July 2024
Contents
Cloudwork.ID Settings
Located in the Cloudwork Dashboard>Settings>CloudworkID Settings
Look and Feel
https://wiki.studentnet.net/index.php/CloudworkID_themes
Features
Field Name | Description |
---|---|
Cloudwork.ID Homepage | Configures whether users will be able to see the list of SSO Services available to them or will users only be able to their own account settings |
Passwords | Configure whether users will be allowed to update their password |
Recovery Information | Configure whether users will be allowed to update their Recovery Information |
Multifactor Authentication | Configure whether users can add or delete MFA options to their account |
Disable Multifactor | Configure whether users can disable MFA from their account, users can remove MFA options but must have at least one MFA option available if this option is active |
Users must enable MFA | Configure whether users must have MFA enabled before accessing any service |
Allow Passwordless Login | Configure whether users can set Passkey as an alternate login |
Let Users Configure Passwordless Login without enforcing MFA | Control whether users need to have MFA before setting up a Passkey |
Enable Trusted Devices | As a feature of Multifactor, Users have the option when logging in to select I trust this device, don't ask again. This means for the next 30 days the user will not have to use a code for MFA. |
Multifactor Authentication Whitelist | Enter IP Addresses or Address Ranges, so users logging in from specified IP Address/Range will not be prompted for MFA |
Multifactor Push Alert Actions | This option is specific to the CloudworkID Authenticator App both Custom and normal, control whether users can accept MFA prompts the notifications icon or need to launch the CloudworkID Authenticator App to accept MFA requests |
Multifactor Methods | Control whether users can use SMS as an MFA option or not, this option is so school do not get charged extra for SMS cost listed in the this documentation |
Reject Compromised Passwords | Control when a user updates their password, whether to check the user's password against the dark web via HaveIBeenPwned's.facility. More information located here. Compromised dataset is up to date using HaveIBeenPwned's online anonymous API. |
Compromised Password Threshold | If Reject Compromised Passwords is enabled, a limit can be set for how many times the password has been seen before the password a user sets gets rejected |
Session Length | Control how long a user can stay logged in before being asked to re-authenticate |
Password Settings
Field Name | Description |
---|---|
Minimum Password Length | Configures the minimum length a user can update or set their password |
Maximum Password Length | Configures the maximum length a user can update or set their password |
Require Complexity | Configure whether users will be required to follow password complexity rules when updating passwords. Further information on the specific conditions of password complexity can be found here |
Days before Password Expiry Prompt | Configure how many days before the password expiry occurs, does a user get asked to change their password |
Block number sequences | Configure whether users can have a sequence of numbers in their password, this option will not affect passwords that have already been set before the change was enabled |
Block personal details | Configure whether users can include in their password, account details such as username, name, email, sisid, etc. This option will not affect passwords that have already been set before the change was enabled |
Phrase block list | Enter into the field, phrases/words that should not be used in the user's password. This option will not affect passwords that have already been set before the change was enabled |
Account Recovery Settings
https://wiki.studentnet.net/index.php/Password_Recovery