--- title: "Enhance ProcessMaker Platform Security" slug: "enhance-processmaker-platform-security" updated: 2024-08-12T14:14:35Z published: 2024-08-12T14:14:35Z canonical: "docs.processmaker.com/enhance-processmaker-platform-security" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.processmaker.com/llms.txt > Use this file to discover all available pages before exploring further. # Enhance ProcessMaker Platform Security Follow security best practices to better secure your ProcessMaker Platform instance. ## Overview Follow these best practices to enhance security in your ProcessMaker Platform instance:​ - [Require all users to periodically reset passwords](/v1/docs/enhance-processmaker-platform-security#require-all-users-to-periodically-reset-passwords). - [Require all users to log on via SSO to ProcessMaker Platform](/v1/docs/enhance-processmaker-platform-security#require-all-users-to-log-on-via-sso-to-processmaker-platform). - [Verify all user accounts that run scripts](/v1/docs/enhance-processmaker-platform-security#verify-all-user-accounts-that-run-scripts). - [Identify invalid and blacklisted IP addresses](/v1/docs/enhance-processmaker-platform-security#identify-invalid-and-blacklisted-ip-addresses). ## Require All Users to Periodically Reset Passwords Require all users to periodically reset their passwords. [Enable the **User must change password at next login** toggle key in each user account to require tat user to change the password prior to next logging on to ProcessMaker Platform](/v1/docs/edit-a-user-account). ## Require All Users to Log On via SSO to ProcessMaker Platform Require all users to log on to your ProcessMaker Platform instance via Single Sign-On (SSO), OAuth, OKTA and/or two-factor authentication. Follow these guidelines: 1. [Configure SAML SSO](/v1/docs/sso-saml-settings) or another ProcessMaker Platform-supported SSO authentication protocol. 2. Instruct all users to authenticate via SSO to log on to your ProcessMaker Platform instance. ## Verify All User Accounts that Run Scripts Verify that all user accounts that run scripts are valid and appropriate. [Review the **Run script as** setting for all Scripts to determine which user's API client token to use with the ProcessMaker Platform REST API](/v1/docs/configure-a-script). ## Identify Invalid and Blacklisted IP Addresses Follow these guidelines to identify invalid and blacklisted IP addresses that access your ProcessMaker Platform instance: 1. Ask your Customer Success Manager to provide a list of all IP addresses that access your ProcessMaker Platform instance. 2. Identify the following from the list of IP addresses: - Identify which IP addresses on this list are invalid. - Identify which IP addresses are blacklisted. 3. Provide your Customer Success Manager an incident report.