Skip to content
Help Center
Products
Back to Admin Guide

Account Security Settings: How to Manage Password and Multi-Factor Authentication

Summary

A step-by-step guide to configuring the Security Settings tab in KnowledgeCity LMS, including password policy, account lockout rules, and multi-factor authentication enforcement.

Introduction

The Security Settings tab is the second of five configuration sections within Account Settings. This is where you establish the protective framework for user accounts in your KnowledgeCity LMS. Proper configuration here ensures strong password policies, automated account disabling for inactive or locked users, and an additional layer of security through multi-factor authentication. These controls directly reduce security risks and help maintain compliance with organizational data protection standards.

Steps to Follow

Accessing the Security Settings Tab

This guide covers the core configuration options available under Security Settings. Once you have familiarized yourself with the Account Settings section (as covered in: Understanding and Navigating Your Account Settings in KnowledgeCity LMS), you can now proceed with configuring your security preferences.

Follow the steps below to access the Security Settings tab:

  1. Log in to your KnowledgeCity LMS as a Super Admin.

  2. Locate the Settings dropdown menu on the top panel of the LMS interface and select Account Settings.

  3. Click on the Security Settings tab to access the configuration options covered in this guide.

The Security Settings page is organized into three key sections: Password Policy for complexity and expiration rules, Account Lockout Rules for login attempts and inactivity automation, and Multi-Factor Authentication for enforcing MFA across your learning portal.

Account-settings-Security-20260304-185012.png
An example illustration of accessing Security Settings inside Account Settings of the LMS.

Configuring Password Policy

Password settings control complexity, expiration, and reuse rules for all user accounts.

Under the Password section, configure the following:

  • Password must include: Select which character types to require from the following options:

    • At least one lowercase character

    • At least one uppercase character

    • At least one special character

    • At least one number

  • Password confirmation: Toggle Show password confirmation field ON to require users to enter their password twice when creating or changing passwords, reducing typographical errors.

  • Password minimum length: Set the minimum number of characters required for passwords using the number field. The default value is 6 characters.

  • Password duration: Click the dropdown menu to define how long a password remains valid before users are prompted to update it. Options include:

    • Not set (default)

    • 1 month

    • 3 months

    • 6 months

    • 1 year

  • Check for previously used passwords: Enter the number of previous passwords the system should remember and check against. When users change their password, they will not be allowed to reuse any of the specified number of previous passwords.

Account-settings-Password policy-20260304-185211.png
An example illustration of the Password section showing complexity, duration, and reuse options.

Configuring Account Lockout Rules

These settings automatically disable accounts based on failed login attempts or prolonged inactivity.

  • Login attempts: Under the Login attempts section, use the number field to set the maximum number of consecutive failed logins allowed before the account is disabled.

    • Enter 0 for unlimited attempts (not recommended)

    • Enter a specific number (e.g., 3) to enforce limits

  • Disable inactive account after (days): Under the Disable inactive account after (days) section, use the number field to specify the number of days of inactivity that triggers automatic account disable.

    • Enter 0 to disable this feature

    • Enter a specific number (e.g., 90) to disable accounts after 90 days of no sign-in activity

Account-settings-Lockout rule-20260304-185419.png
An example illustration of Login attempts and Inactive account disable configuration options.

Configuring Multi-Factor Authentication

Multi-factor authentication (MFA) adds a critical layer of security by requiring users to verify their identity through a second method beyond just their password.

Under the Multi-factor authentication section, click the Turn on multi-factor authentication toggle.

A popup window will appear with the following options:

  • Select MFA methods: Choose one or both verification methods:

    • Email: Users receive a one-time code via email during login

    • Authenticator app: Users generate a time-based code from apps like Google Authenticator or Microsoft Authenticator

Click Save changes to enable MFA or Cancel to close the popup without enabling.
After saving, an Edit button becomes available to modify your MFA configurations anytime.

Account-settings-MFA-20260304-185617.png
An example illustration of the Multi-factor authentication configuration popup window.

Save Your Changes

After configuring your desired security settings, scroll to the bottom of the page and click Save to apply all changes. Changes will not take effect until the Save button is clicked.

Conclusion

You have successfully configured the Security Settings for your KnowledgeCity LMS. Password policy, account lockout rules, and multi-factor authentication are now set according to your organization's security requirements. These protective measures ensure user accounts remain secure and compliant with your data protection standards.

Ask Casey about this article