Password & Security Settings
7 min
the password & security settings section allows users to manage their account authentication method and update their password to improve account security, engati supports multiple authentication methods with built in controls that prevent users from moving to a less secure authentication option \<font color="#a71010">password settings\</font> authentication methods engati supports the following authentication methods password only two factor authentication (2fa) using email otp two factor authentication (2fa) using an authenticator app (new) social login authentication security hierarchy authentication methods follow the security hierarchy below password only < 2fa (email otp) = 2fa (authenticator app) < social login users can only switch to an authentication method that maintains or improves their current security posture note downgrading to a less secure authentication method is not permitted change authentication mode the change authentication mode option has been relocated from the password settings section users can access authentication mode management from the updated account security settings area maximum invalid password attempts no of failed attempts prior to the portal user account being locked an email notification is shared upon locking of the account password update the previous password security section has been renamed to update password this section is now dedicated solely to changing the account password updating existing passwords managing password credentials updated password policy engati now follows nist password guidelines for newly created and updated passwords key changes include stronger password validation requirements improved password security standards better support for long passphrases important existing passwords created under the previous policy will continue to work however, any new password or password update must comply with the latest password policy requirements removed features the following settings are no longer available password expiry password history these options have been removed as part of the transition to nist aligned password management practices single sign on (sso) users authenticated through single sign on (sso) can only access their accounts using their configured sso provider logging in using email + password is no longer supported for sso enabled users if you face any issues or queries please reach out to us at support\@engati ai mailto\ support\@engati ai
