Settings
Authentication
The two-factor authentication and password policy settings, and what each of them changes.
Definition: The Authentication page sets how members prove their identity when they log in with a Leexi password: mandatory second factor and minimum password complexity. It is under
Settings > Company > Authentication and is restricted to people allowed to change company settings (System admin, Super admin). Its settings apply to the whole company, with no exception per team.Two-factor authentication
| Setting | Options | Default | Requires | Effect |
|---|---|---|---|---|
| Two-factor authentication enforced for the whole company | Switch | Disabled | Restricted to people allowed to change company settings | Each member must set up a second factor (authenticator app) before accessing their workspace, and can no longer disable it from My account. A confirmation is requested on every change. Does not apply to Google, Microsoft and SSO logins: the second factor is then handled by the identity provider. |
Password policy
These requirements apply when a Leexi password is created or renewed. They do not force a reset of existing passwords.
| Setting | Options | Default | Requires | Effect |
|---|---|---|---|---|
| Minimum length (characters) | Whole number from 8 to 64 | 8 | Restricted to people allowed to change company settings | Minimum length of a new password. A value out of bounds is brought back to the nearest bound. |
| At least one uppercase letter (ABC...) | Switch | Disabled | Restricted to people allowed to change company settings | Requires an uppercase letter. |
| At least one number (123...) | Switch | Disabled | Restricted to people allowed to change company settings | Requires a number. |
| At least one special character (!#$...) | Switch | Disabled | Restricted to people allowed to change company settings | Requires a special character. |
Priority of enforced SSO
When SSO login enforced is enabled on SSO / SCIM, members no longer log in with a Leexi password. The two-factor authentication switch is then greyed out and the password policy no longer has any effect: authentication is fully delegated to your identity provider.