Platform
Security Policies
Review and update password, lockout, and session rules with a recorded reason.
What this menu does
Apply one controlled platform security policy to supported authentication flows.
Where to find it
Platform Admin navigation: Accounts & Security → Security Policies.
When to use it
- Review the current authentication policy.
- Change password length or complexity.
- Adjust failed-login lockout or session timeout.
- Control first-login password change.
Before you begin
- Sign in to Platform Admin.
- The account must be allowed to view this menu.
Page regions
- 01Read-only policy summary
- 02Edit mode
- 03Password policy fields
- 04Lockout and session fields
- 05First-login switch
- 06Save reason
Supported operations
Review the policy
- 1
Open Security Policies.
- 2
Review minimum password length and complexity.
- 3
Review failed-login threshold, lock duration, session timeout, and first-login password change.
- 4
Do not enter edit mode when no approved change is needed.
The active policy remains unchanged.
Update the policy
- 1
Select Edit security policy.
- 2
Change only the approved fields.
- 3
Enter a save reason explaining the business or security need.
- 4
Save and verify the read-only summary after the page exits edit mode.
The policy is saved with its reason and updated timestamp.
Business rules and fields
- The default page is read-only.
- Saving requires a reason.
- Stronger policies can affect future logins and currently active sessions according to the configured timeout.
- Cancel exits edit mode without saving.
States you may see
What happens next
- Supported authentication flows use the saved policy and the change remains auditable.
Common problems
The menu or action is missing.
The account does not have the required platform access or the item is not available in the current state.
Ask a platform administrator to verify the account role and the record status.
A save or load action fails.
The session may have expired, validation may have failed, or the service is temporarily unavailable.
Keep the shown request identifier if present, refresh once, correct highlighted fields, and retry. Escalate with the request identifier if it repeats.