Security Settings

Last Updated At: 2025-10-21 09:10:00

Overview of Security Settings

Security settings can manage all account-related security information under the login account, including passwords, phone numbers, emails, password rules, and log-in protection.

Feature Introduction

View General Information

Under the General Features, you can modify passwords, phone numbers, and emails.

  • Modify Password: To modify the password, you must enter the old password first. The new password should be entered twice and must be the same. Password rules can be set by the root account in the user settings. Password rules may include: a combination of uppercase and lowercase letters, digits, and certain English punctuation marks (such as . / \ _, excluding spaces), and should not contain the username. You can also set the minimum length of the password, the password expiration time, and the quantities of recently used passwords that cannot be repeated. Modifying the password through the console is suitable for scenarios where you remember the old password, the password is about to expire, or the password has been compromised. Modification restrictions: Requires the old password and the ability to log in to the console.
  • Modify Phone Number: To modify the phone number, you only need to enter the new phone number and the verification code. Scene for modifying the phone number: The old phone number is no longer in use and needs to be replaced with a new one. Modification restrictions: Must be able to log in to the console.
  • Modify Email: Modifying the email is similar to modifying the phone number, you only need to enter the new email and the phone number. Scene for modifying the email: The email is no longer in use and needs to be replaced with a new one. Modification restrictions: Must be able to log in to the console.

Sensitive Operation

Sensitive operations are used to set account protection policies and further enhance account security. When performing sensitive operations, a SMS verification code is required.
Enable conditions: Already integrated with an internal enterprise SMS gateway.
Enable Log-in Protection: When enabled, users will be prompted for identity verification before performing sensitive operations to ensure the security of your account.
Disable Log-in Protection: After disabling, login does not require mobile verification.
Suitable scenes for enabling sensitive operations: log-in protection recommended for industries with high confidentiality requirements such as government, finance, and banks.

Log-in Protection

Users can set the type of log-in protection in the security settings, which includes three types of identity authentication: phone number verification code, virtual MFA device, and third-party MFA device.
Virtual MFA Device: Implemented based on the Google Authenticator algorithm. Users need to download the Google Authenticator app as a client to obtain a token. Enter the token during log-in to complete the identity authentication.
Third-party MFA Device: MFA authentication tool provided by a third-party vendor. Users need to bind their account to the third-party system and download the client app. Enter the token from the client app during log-in to complete the identity authentication.