Additional security options for key users and group administrators
In this article, you will learn how to strengthen your organization’s access and security in 12Build as an administrator. We will discuss the advanced tools available to key users and group administrators for controlling user flows, managing login methods, and ensuring optimal data protection.
What will you find in this article?
-
Tools for Key Users: Managing session history, user lists, and password resets.
-
Options for Group Administrators: Advanced login security such as SSO and two-factor authentication.
-
Security settings: Adjusting password lengths and session durations for the entire organization.
Summary
Key users and group administrators possess additional authority to prevent unauthorized access to customer data. This includes monitoring login behavior via login reports, requiring Single Sign-On (SSO), and enforcing stricter password and authentication requirements for all users.
Prerequisites and Target Audience
This article is specifically intended for key users and group administrators within 12Build. These roles have access to advanced security settings that exceed the platform’s standard best practices.
Key users
As a key user, you have direct oversight of who has access to your organization’s environment.
-
Log overview: Download the session history to see who has logged in and via which method (password or SSO).
-
Remove old users: Use the monthly overview of active users to immediately delete accounts of former employees.
-
Add inactive users: Create accounts for new employees in advance without allowing them to log in immediately. Activate these accounts on their first day of work.
-
Password management: Send emails for setting passwords or perform an immediate reset. Upon a reset, the user is immediately logged out.
Group Administrators
Group administrators manage security standards at the organizational level.
-
Single Sign-On (SSO): Enable login via Azure or Google accounts. You can also make SSO mandatory, which means logging in with a standard password is no longer possible.
-
Password Length: Increase the minimum password length for the entire organization (default is 8 characters).
-
Require Two-Factor Authentication (2FA): Enable 2FA for all users. They must activate this upon their next login.
-
Stay logged in temporarily: The default session duration of 1 week after inactivity can be shortened as desired to reduce the risk associated with unattended devices.
-
Change notifications: Whenever security settings are modified, all registered group administrators automatically receive an email notification.
Frequently Asked Questions (FAQ)
Question: What happens if I make SSO mandatory? Answer: From that point on, users can only log in with their Azure or Google account. Their old 12Build password will no longer be valid for accessing this account.
Question: How often should I check the user overview? Answer: Key users receive a monthly overview via email. We recommend checking this overview immediately upon receipt for employees who have since left the company.
Troubleshooting
-
Symptom: A user cannot log in after a password reset by the key user.
-
Cause: The user is immediately logged out and must first create a new password via the link in the email.
-
Solution: Ask the user to check their inbox (and spam folder) for the reset email and follow the steps.
-
-
Symptom: SSO is not working for a specific employee.
-
Cause: The username in 12Build does not exactly match the email address of the Azure or Google account.
-
Solution: Update the username in 12Build so that it matches the business email address exactly.
-