--- title: "Log-In Options Settings" slug: "log-in-options-settings" updated: 2025-12-22T21:04:15Z published: 2025-12-22T21:04:15Z canonical: "docs.processmaker.com/log-in-options-settings" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.processmaker.com/llms.txt > Use this file to discover all available pages before exploring further. # Log-In Options Settings > [!TIP] > [**Plan Availability:**](https://www.processmaker.com/products/pricing/) ![Professional](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Standard.png)![Professional](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Professional.png)![Enterprise](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Enterprise.png) Login settings provide a secure and reliable authentication experience by allowing administrators to manage user access and enforce security measures. As an administrator, you can: - Enforce password policies to maintain security standards. - Enable and configure two-factor authentication (2FA) for added protection. --- ## View the Log-In Options **Permissions** Your user account or group membership must have the "Settings: View Settings" permission to view Password Policies unless your user account has the **Make this user a Super Admin** setting selected. See the [Settings](/v1/docs/permission-descriptions-for-users-and-groups#settings) permissions or ask your Administrator for assistance. Follow these steps to view the **Log-In Options** settings: 1. Ensure that you are [logged on](/v1/docs/participant-basics#log-on-to-processmaker-platform) to ProcessMaker Platform. 2. Click the **Admin** option from the top menu to view the **Users** page. 3. Click the **Settings** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/240fdcc8-4f29-4260-be16-4fcb45747d8f.png) from the left sidebar to view all settings. 4. From the **Settings** panel on the left, expand the **Log-in & Auth** section. 5. Select **Log-In Options** to view the following details: - **Setting:** The **Setting** column displays the Log-In Options Setting name. - **Configuration:** The **Configuration** column displays the setting value and how it is configured. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/6f722cc8-02bf-4d0f-8066-97c23d5d27d2.png) --- ## Configure the Log-In Options **Permissions** Your user account or group membership must have the "Settings: Update Settings" permission to edit settings from the **Log-In Options** tab unless your user account has the **Make this user a Super Admin** setting selected. See the [Settings](/v1/docs/permission-descriptions-for-users-and-groups#settings) permissions or ask your Administrator for assistance. The following settings can be configured in the **Log-In Options** tab: - [Set password policies](/v1/docs/log-in-options-settings#set-password-policies). - [Enable two-factor authentication](/v1/docs/log-in-options-settings#enable-twofactor-authentication). --- ### Set Password Policies Follow these steps to enable a user to change their password: 1. Enable the **Password Set By User** toggle key to allow users to change their passwords. When this setting is enabled, users are able to [change their passwords when editing their user profile.](/v1/docs/profile-settings#change-your-log-on-information) ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/de5e1f30-e895-4f93-9542-67ed6af031f6.png) 2. If this setting is toggled off, users won't have the option to update their password while editing their user profile. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/a5a5ec23-64bc-4eab-be21-10b0f31a658d.png) > [!NOTE] > Note: > > This setting applies to all users except Super Admins. Users with [Super Admin permissions](/v1/docs/edit-a-user-account#edit-user-permissions) will always have the ability to change passwords. 3. Enable the **Numeric Characters** toggle key to allow numeric characters in passwords. 4. Enable the **Uppercase Characters** toggle key to allow uppercase characters. 5. Enable the **Special Characters** toggle key to allow special characters. 6. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/0cdbff17-8e86-495f-a5f2-b7963e1ecec3.png) for the **Maximum Length** setting to set the maximum password length. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/7846f7fc-fbed-438f-84df-98607d9f63fd.png) 7. Enter the maximum number of characters allowed for the password, and click **Save**. 8. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/0cdbff17-8e86-495f-a5f2-b7963e1ecec3.png) for the **Minimum Length** setting to set the minimum password length. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/708febcb-1ae4-4402-bedd-7b9ade7bd02b.png) 9. Enter the minimum number of characters allowed for the password, and click **Save**. 10. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/0cdbff17-8e86-495f-a5f2-b7963e1ecec3.png) for the **Password Expiration** setting. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/a18ebbe3-085e-4c58-8e58-7ac8e5720afe.png) 11. Enter the number of days after which a password will expire, and click **Save**. 12. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/0cdbff17-8e86-495f-a5f2-b7963e1ecec3.png) for the **Login Failed** setting. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/21a7f6ab-3422-4a26-8cbb-70ccadd693f9.png) 13. Enter a number of consecutive unsuccessful login attempts before blocking the login action, and click **Save**. --- ### Enable Two-Factor Authentication Enhance login security by enabling two-factor authentication for user verification. Follow these steps to set up two-factor authentication (2FA): 1. Enable the **Require Two Step Authentication** toggle key. 2. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/0cdbff17-8e86-495f-a5f2-b7963e1ecec3.png) for the **Two Step Authentication Method** setting. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/4dc0aee5-9368-4010-a62a-c57483c68fb5.png) 3. Select one or more authentication methods: - Select **By email** to send the code to your account email. An email address must be configured in user properties. - Select **By message to p****hone number** to send the code to your account phone number. A phone number must be configured in [user properties](/v1/docs/edit-a-user-account#edit-general-information). - Select **Authenticator App** to send the code to an authenticator app such as [Google Authenticator](https://support.google.com/accounts/answer/1066447?hl=en&co=GENIE.Platform%3DAndroid). > [!NOTE] > Code Validity > > The length and validity of the security code depend on the selected 2FA method. > > - When 2FA codes are delivered via **Email or SMS**, users receive an **8-digit code** that is valid for **5 minutes**. This extended validity accounts for potential delivery delays caused by background processing, external providers, or email and mobile carriers. > - When using an **authenticator app** (such as Google Authenticator), users receive a **6-digit code** that is valid for **1 minute**, following standard industry practices since the code is generated locally on the user’s device. 4. Click **Save** to save all changes. > [!NOTE] > Two-factor authentication must also be enabled in [**group-level settings**](/v1/docs/edit-a-group#edit-group-settings). > [!WARNING] > **Two-Factor Authentication for SSO and Active Directory Users** > > - If [SSO is enabled](/v1/docs/sso-settings), the Two-Factor Authentication setting is bypassed for SSO users, allowing them to log in without it. > - Additionally, Two-Factor Authentication is also bypassed when users authenticate against Active Directory. > - Non-SSO and non-Active Directory users must still enter two-factor verification codes to log in.