Administration
Securing your organisation's account
Second factor, devices, single sign-on and what to check when something feels off.
In an account holding signed contracts and evidence with probative value, security is not an optional setting you look at in year two. Three things are worth settling in the first month, and one is worth knowing how to check when a doubt arises.
Two-factor authentication
It is the measure that removes the most risk for the least effort. A password leaked somewhere else stops being enough to get in. For accounts with administration rights it is not negotiable: those are the ones that can change the whole organisation's configuration.
Passkeys
They replace the password with the device's fingerprint or face. There is nothing to remember and nothing to leak, and they cannot be phished with a fake email because they are bound to the real domain. If your team uses modern phones or laptops, it is the most convenient and the most secure route at once.
Single sign-on
If your company already runs a corporate identity system, connecting the platform to it avoids the classic problem: someone leaves, their email is removed and this account is forgotten. With single sign-on, there is only one offboarding to do.
Watch out
Before enabling single sign-on, make sure at least one administrator keeps direct access. If the connection fails and nobody can get in another way, recovering access is a great deal slower.
When something feels off
- 1
Check the devices with an open session
One you do not recognise can be signed out from there, changing nothing else.
- 2
Review the audit log
Who logged in, from where and what changed. That is what turns a suspicion into a fact.
- 3
Change the password and enable two-factor
In that order: changing it without a second factor leaves the door just as open.
Frequently asked questions
›Can I require two-factor for the whole team?
Yes, it can be enforced by organisation policy. For administration accounts it should always be mandatory.
›What if someone loses the phone with their second factor?
An administrator can reset it for them. Which is why it matters that more than one person holds that permission.
›Does an external participant need two-factor?
They have no account, so it does not apply. Their access is a personal link, and on advanced signatures they are verified with the SMS code.
›Can I enforce a minimum password length?
Yes, there is a password policy configurable per organisation.
A real case
The situation
An administrator gets a sign-in alert from a country where they have nobody.
What you do
- Opens the device list and signs out the session she does not recognise
- Reviews the log for what that session did
- Requires two-factor on every account with administration rights
What you get
She knows exactly what was touched and closes the door the same day, instead of wondering for a week.
The situation
There is one administrator and they are on holiday.
What you do
- Names two administrators from the start
What you get
The account does not depend on one person.
The situation
Nobody has reviewed who has access in years.
What you do
- Schedules a periodic review
What you get
Access reflects today's organisation.
The situation
The second factor is switched off.
What you do
- Turns it on with advance notice
What you get
The account is protected without blocking anyone.
The situation
A security notice arrives and nobody reads it.
What you do
- Addresses notices to more than one person
What you get
The notice reaches somebody who can act.
The situation
An account is shared between several people.
What you do
- Gives each one their own account
What you get
The log says who did what.
This article answers
- enable two-factor authentication
- securing my organisation's account
- set up single sign-on SSO
- sign out of a lost device
- company password policy