---
title: Password & Security Settings
slug: password-and-security-settings
docTags: 
createdAt: 2022-05-11T08:50:52.000Z
---

The Password & Security Settings section allows users to manage their account authentication method and update their password.

To improve account security, Engati supports multiple authentication methods with built-in controls that prevent users from moving to a less secure authentication option.

## <font color="#a71010">Password Settings</font>

### Authentication Methods

Engati supports the following authentication methods:

- Password Only
- Two-Factor Authentication (2FA) using Email OTP
- Two-Factor Authentication (2FA) using an Authenticator App (New)
- Social Login

### Authentication Security Hierarchy

Authentication methods follow the security hierarchy below:

Password Only \< 2FA (Email OTP) = 2FA (Authenticator App) \< Social Login

Users can only switch to an authentication method that maintains or improves their current security posture.

**Note: Downgrading to a less secure authentication method is not permitted.**

### Change Authentication Mode

The Change Authentication Mode option has been relocated from the Password Settings section.

Users can access Authentication Mode management from the updated Account Security settings area.

![](https://api.archbee.com/api/optimize/FEqjvWZnyymr_PEhXLLlG/KRCsOg2endklhySn-hbdo_account-security.png)

**Maximum Invalid Password Attempts** : No. of failed attempts prior to the portal user account being locked. An email notification is shared upon locking of the account.

## Password Update

The previous **Password Security** section has been renamed t&#x6F;**&#x20;Update Password**.

This section is now dedicated solely to:

- Changing the account password
- Updating existing passwords
- Managing password credentials

![](https://api.archbee.com/api/optimize/FEqjvWZnyymr_PEhXLLlG/h19ul9qtMsBbD8my-0mXh_update-password.png)

![](https://api.archbee.com/api/optimize/FEqjvWZnyymr_PEhXLLlG/a8xZWwZF_pR-olSQt8RY6_password-update.png)

## Updated Password Policy

Engati now follows NIST Password Guidelines for newly created and updated passwords.

Key changes include:

- Stronger password validation requirements
- Improved password security standards
- Better support for long passphrases

### Important

Existing passwords created under the previous policy will continue to work.

However, any new password or password update must comply with the latest password policy requirements.

## Removed Features

The following settings are no longer available:

- Password Expiry
- Password History

These options have been removed as part of the transition to NIST-aligned password management practices.

## Single Sign-On (SSO)

Users authenticated through Single Sign-On (SSO) can only access their accounts using their configured SSO provider.

Logging in using Email + Password is no longer supported for SSO-enabled users.

If you face any issues or queries please reach out to us at [support@engati.ai](mailto\:support@engati.ai).
