Note: A Pro Plan subscription is required to use this feature.
How to Configure
-
Log in to TrustLogin,
open the "Admin Page > Security > Security Policy" menu, and click the "Edit" button.
- Turn ON (shown in green) the items you want to enable, set the values for each, and click the "Save" button to save.
Note: Each enabled setting takes effect as soon as you click the "Save" button.
Depending on the settings, you may be forcibly logged out.
Please check the configuration instructions for each feature below before making changes.
-
Password Rules
For each customer (company ID), you can change the "number of characters" (between 8 and 99 characters)
and "character types" (uppercase letters, lowercase letters, numbers, symbols) used for TrustLogin password authentication.Turning on the Password Rules toggle applies these settings.
If turned off, the standard rule of "8 or more characters including uppercase and lowercase letters, numbers, and symbols" applies.Note: After enabling this feature, it will apply starting from a new member's initial password setup
Note: If turned off, the default rule of "8 or more characters including uppercase letters, lowercase letters, numbers, and symbols" applies.
and any subsequent password reset. Users who have already set a password will not be forced to reset their password.
Note: If you want this to apply to users who have already set a password, shorten the "Password Expiration" setting described below
so that the current password expires, then handle it accordingly.
After doing so, please restore the password expiration period to its original value.
-
Session Expiration
Set the session expiration for the browser (PC and mobile) and the mobile app separately, in hours or minutes.
You can set it between 1 hour and 720 hours, or between 1 minute and 720 minutes.
The default is 8 hours from the last access for the browser, and 24 hours from login for the mobile app.
Note: Session information is stored in a cookie. -
Password Expiration
Note: From the moment you enable this setting, expiration will be determined based on the last login date and the last password change date,
and it will take effect immediately. Users who have already passed the expiration date will be forcibly redirected to the password change screen,
so please be careful.
Note: This does not mean that the policy is applied X days after enabling this setting.
You will need to change your TrustLogin login password at the specified interval.
(Set in days, between 1 and 365 days)
You can also set the number of days for notification before the change deadline. (Set in days, between 1 and 30 days)
When the change deadline arrives, users will be required to enter a new password when logging in.
If a user changes their own password before the deadline, the expiration count restarts from that point.
"Password History Management (times)" prevents users from setting a password identical to one used in a specified number of past instances (set between 1 and 24 times).
If this setting is off, the password will not expire and password history will not be managed.
-
Suspend Unused Accounts
If a user does not perform SSO or log in for a specified period, their account status will automatically be suspended (set in days, between 31 and 365 days). By default, automatic suspension is disabled.
If an account is created (invited by an administrator) but never completes registration, it will be suspended after the period elapses.
Example: If you set the unused account suspension period to 90 days, any user who has not logged in for the past 90 days will be suspended immediately.
Note: Active Directory Integration and External IdP Integration (SCIM) options are not subject to this setting.
Note: If you enable this setting, we recommend having multiple TrustLogin administrators. If there is only one administrator, that administrator could be suspended due to inactivity and become unable to log in.
Note: If you use G Suite integration, members who are automatically suspended due to reasons such as an extended leave of absence will no longer be able to receive email. If a member is expected to take an extended leave, we recommend not enabling this setting for them.
To reactivate the status of an automatically suspended user, search for the user from "Admin Page > Settings > Members" and edit the user information.
-
Account Lock
You can set the number of incorrect password attempts before an account is locked, and the time until it is automatically unlocked.
Account Lock Count: 4 (default)
You can specify a half-width integer between 1 and 10, which sets the number of consecutive incorrect password attempts before the account is locked.
Account Lock Duration: 0 (default)
You can specify a half-width integer between 0 and 60; 0 means the account will not be automatically unlocked.
For 1 to 60, after X minutes, the user can log in and the lock will be released once they log in with the correct password.
When an account is locked, the following message is displayed at the top of the screen. -
Customize Login Flow
When logging in to TrustLogin, if there is only one account selection candidate,
the account selection screen can be skipped.
If the target account uses Desktop SSO,
simply clicking the "Open Login Screen" button in the extension completes the login.
Note: By logging in from "Log in with a different account" in the menu at the top right of My Page,
you can add another user to the account selection list. After that, the screen will no longer be skipped.Note: If this is used together with Client Authentication and Device Restrictions, enabling this setting will automatically proceed
Note: If login fails due to IP address restrictions while this feature is enabled, the following occurs:
to the certificate selection screen. However, if you then switch to a different account, the browser will retain the previous certificate selection,
so you will not be able to reselect a certificate. If you plan to switch between multiple accounts
with Client Authentication and Device Restrictions enabled, please disable this setting.
The login form appears empty, as if no account has been selected,
and an error message is displayed.
However, this message actually applies to users whose account selection was skipped.
-
Note: If the setting to prioritize Desktop SSO is enabled,
even if a user logs out, account selection and Desktop SSO authentication will
be performed automatically, and the user will be redirected back to My Page after logging in.