Managing Security Settings to prevent Lock-outs
Ripple’s security settings are designed to align with HIPAA-compliance standards by default. However, Site Admins have the flexibility to adjust these settings to better suit their team’s security needs.
Accessing Security Settings
To view and modify your site’s password and account security settings:
-
Click on the Site Admin tab (typically shown in red).
-
Select the Security module (highlighted in green).
-
Scroll down to the Passwords section (highlighted in purple).
Password Settings Options
Within the Passwords section, you can configure the following:
-
Password expiration frequency: Set how often (in months) users must change their passwords.
-
Password reuse policy: Decide whether users are allowed to reuse previous passwords.
-
Password complexity requirements: Adjust minimum requirements for password strength (e.g., length, special characters, numbers).
Additional Security Settings
On the Security page, you can also configure options related to:
-
Account lockout due to inactivity: Automatically lock accounts after a specified period of user inactivity.
-
Account lockout after failed login attempts: Set the number of failed attempts before an account is temporarily locked.
Important: Password Reset Links
-
Password reset links expire immediately once a new reset email is sent.
-
Each time a Site Admin sends a password reset email, a new link is generated, rendering all previously sent reset links invalid.