> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/administration/account/interface/security.md).

# Security

## **Overview**

This page allows admins to define settings for securing user accounts and monitoring user activities.

## **Activate WebGUI Auditing/Force Comments at Changes**

<figure><img src="/files/rytNJbkrXy9P77YXjTvz" alt=""><figcaption></figcaption></figure>

These functions enable auditing for changes, and can enable mandatory comments when changes are made. For the latter option to function, Auditing in general has to be activated.

## **Force Two-Factor Authentication**

<figure><img src="/files/h7nvwzTGkTF888cxv9oM" alt=""><figcaption></figcaption></figure>

The enforced two-factor authentication feature allows administrators to require all users to use two-factor authentication during login. This additional layer of security provides effective protection against unauthorized access, and significantly strengthens the overall security of accounts.

## **Minimum Password Length**

<figure><img src="/files/mrW8suRawhuDFKDsNos9" alt=""><figcaption></figcaption></figure>

Administrators can set a minimum password length, which will subsequently be enforced for all account users. By default, passwords must be at least 7 characters in length (with no option for a smaller number). Additionally, a universal requirement mandates the inclusion of upper case letters, lower case letters, special characters, and numbers.

## **Failed Login Attempts**

<figure><img src="/files/WB7bpepGrlQoOmX2DLRN" alt=""><figcaption></figcaption></figure>

Administrators can set the maximum number of failed login attempts for all users of the account. If this limit is exceeded, the user will be disabled and unable to log into the WebGUI.

To re-enable a disabled account, users must contact their account administrator or Link11 support.

## **Password Validity Period**

<figure><img src="/files/2uTHXK7tPXsVwOroA9KJ" alt=""><figcaption></figcaption></figure>

Administrators can set the duration after which a user's password expires. Before the password expiration, users receive notifications. If this setting is activated, the maximum lifespan of passwords is 365 days. This value can be set by administrators as required.&#x20;

If a password exceeds its defined lifespan without being changed, it's considered expired.&#x20;

Two weeks before a password expires, users will receive a warning in the WebGUI to update their password.&#x20;

<figure><img src="/files/O2uWdvlMLqXMoVdTowRP" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Users can change their password in the “Profile” settings under “Account”.
{% endhint %}

If a user fails to change their password before it expires, their access to the WebGUI will be disabled. To re-enable the account, users need to contact either the account admin or Link11 support.&#x20;

## **Notification on Password Change**

Administrators can set whether notifications should be sent out when a user password is changed. When activated, an email is sent out to the respective user's email address whenever the password of that user changes, whether initiated by them or otherwise. This email informs the user that their password has been changed, and to review and take action if this was unintentional.

<figure><img src="/files/oCxnkbt7LSZkuREhlbRs" alt=""><figcaption></figcaption></figure>

<br>
