How can we help?
Print

Categories:

Admin

User Management

Complex Passwords and Two-Factor Authentication (TFA) in Pelican

Protecting user accounts and data on your Pelican site is crucial. Implementing Complex Passwords and Two-Factor Authentication (TFA) enhances security by requiring multiple layers of authentication. This guide walks you through enabling Text Message Two-Factor Authentication (TFA) and enforcing Complex Passwords in the Pelican Connect app.

Enabling Two-Factor Authentication (TFA) and Complex Passwords

To activate Enhanced Security Measures, you must have administrative privileges on the Pelican site.

Step-by-Step Setup:

1

Log into Your Pelican Site

  • Access your Pelican site using your credentials.

3

Navigate to User Management

  • Click on the Admin tab.
  • Select User Management

4

Navigate to Security Settings

  • Click the Menu icon.
  • Choose Security Settings.

4

Configure Security Requirements

  • Complex Passwords:
    • Set a minimum password length (8-16 characters).
    • Enforce password complexity, requiring:
    • Uppercase and lowercase letters
    • Letters and numbers
    • Special characters
  • Two-Factor Authentication (TFA):
    • Required: Enforces TFA for all users.
    • User Settable: Allows users to opt in for added security.

5

Setting Up TFA for Users

  • Users with TFA enabled must add their phone number in their profile to receive authentication codes via SMS.

Additional Considerations

For Existing Users:

  • Security changes do not automatically apply to users who have already logged in.

  • To enforce new settings, administrators should reach out to the user and have them reset their password OR delete and re-add the user to force a complex password reset.

User Profile Management:

  • Users can update their passwords and phone numbers in User Profile Settings.

Consistency Across Multiple Sites:

  • If managing multiple Pelican sites, ensure uniform security settings for seamless user access and administration.

By implementing TFA and Complex Passwords, you significantly enhance security, protecting your Pelican site from unauthorized access and ensuring a safer user experience.

Table of Contents