Skip to main content

Account Settings

Menu Path: Settings > Account

Table of Contents

  • Account Deactivation Period Setting
  • Password Policy Settings
  • Display Password Reset Button
  • Bulk Change of All User Passwords (On-Premise Only)
  • Session Automatic Logout Settings
  • Recent Access Information
  • Account Authentication Policy Settings
  • Automatic Cleanup and Deactivation of Conditional Policy Members
  • Unused Account Automatic Deactivation Policy

User Account Automatic Deactivation Settings

If a user does not log in for the set period, the account will be automatically deactivated. Deactivated accounts areUser ManagementYou can reactivate it from the menu.


Password Policy Settings

Users added through external account integration such as Microsoft and SAML are not subject to password rules.

itemDescription
Password Policy SettingsSet the required characters and minimum length for password creation and change.
Setting Password Change FrequencySet the cycle for changing the password.
Password Reuse RestrictionRestrict the reuse of the last N passwords.
Password Change Extension SettingsSet the number of times and the extension period that can be extended without changing the password.
URL to move when changing passwordSet the URL to redirect to after the password change is complete.
Setting User Initial PasswordThis is the initial password automatically issued to the user during manual registration (individual registration, CSV batch registration). The user must change this password to a new one after the first login.

Reference (Password Reuse Restriction Example): If set to 2, the 2 most recently used passwords cannot be reused.


Password Reset

Displayed in the password input step of the login screenPassword ResetSet the visibility of the button. If turned off, users will not be able to reset their password directly from the login screen.

itemDescription
Display Password Reset ButtonSet whether to display the 'Reset Password' button on the login screen. (Show / Hide, default: Show)
  • This setting is for the SHIELD ID login page configuration andLink with the same valueIt will be reflected the same way whether you change it in the management center or the SHIELD ID console.
  • Only the super administratorcan be changed, and other administrators can only view it.

Note: Organizations that use external IdP login or helpdesk reset policies can disable this option to block users from resetting themselves on the login screen.


Batch Change of All User Passwords

This feature is for On-Premise only. In a cloud (SaaS) environment,**[Password Bulk Change]**The button is not displayed.

Registered in the tenantReset all users' Security365 internal passwords at onceis a function. In the password policy settings section of theUser initial passwordunder the item**[Password Bulk Change]**You enter through the button. The requester's own account is always excluded. For accounts synchronized with external systems such as SCI Server, Microsoft, etc.Security365 internal password onlyIt is initialized, and the password of the external system is not changed.

Comparison with the existing password reset feature

divisionEmail InitializationTemporary Password GenerationFull Batch Initialization
LocationUser List > Action ButtonUser List > Action ButtonSettings > Password Policy Settings
TargetSelected Multiple UsersSingle UserEntire Tenant
Initialization MethodSend reset link via emailTemporary password generation and deliverySet all with the specified password
Processing MethodmotiveMotivationasynchronous
Application EnvironmentCloud / On-PremisesCloud / On-PremisesOn-Premise Only

Input Item

When you click the [Bulk Password Change] button, a popup will be displayed.

itemRequireddefault valueDescription
Change Password-Password rule settings will display the conditions.
Password Confirmation-You must enter the new password the same as the current password.
Excluding Administrator (ADMIN)CheckedExcludes users with ADMIN roles from the target when checked.
Password change required on next loginCheckedForcing the user to change to a new password after their first login when checked.

Processing Action

When the [Reset] button is clicked, the request is immediately received and the popup closes. The actual password change is processed **in the background (asynchronously)**, and for large tenants, it may take several minutes to complete. If an error occurs, the popup remains open and an error message is displayed.

Exclusion Target

TargetconditionAction
Your AccountalwaysExclusion
ADMIN RoleExcluding Admin (ADMIN) when checkingExclusion (Default: Checked)

Session Automatic Logout Settings

Set to automatically log out after a certain period of inactivity or if simultaneous access occurs. Individual settings are available for each service and are applied to the management center / SHIELD Drive / SHIELD Gate.

Unused Automatic Logout

If no mouse or keyboard input is detected for the set period of time, you will be automatically logged out of the service.

timeNote
10 minutesdefault value
30 minutes-
1 hour ~ 12 hours1 hour unit

Default Logout TimeSelecting a time from the dropdown will apply it uniformly to all services. You can individually change the logout time for each service row using the dropdown. The toggle for each service row allows you to individually set whether to enable automatic logout. Only the services you are currently subscribed to (Management Center, SHIELD Drive, SHIELD Gate) will be displayed.

Simultaneous Login Automatic Logout

If a new connection occurs from a different IP with the same account, the existing connection session will be automatically terminated. The toggle for each service row allows individual settings for enabling or disabling automatic logout for simultaneous connections. Only the services currently subscribed to (Management Center, SHIELD Drive, SHIELD Gate) will be displayed.


Recent Access Information

You can set it up to display the last access date and IP of the user when logging into the management center.


Account Authentication Policy Settings

Set a policy to temporarily lock accounts when user authentication fails. When the configured number of failures is reached, the account is automatically locked and will be automatically released after a specified time.

itemOption
Authentication failure count5 times / 10 times / 15 times
Account Lockout Duration5 minutes / 10 minutes / 30 minutes / 60 minutes

A locked account is restricted from logging in until the set time, even if the correct password is entered.

Note: This applies only to manual login users who do not use SSO (Single Sign-On).


Automatic Cleanup and Deactivation of Conditional Policy Members

When a user moves to another group, the conditional policies that include that user as a member are automatically synchronized. Depending on the group movement, policy members may change or the policy may be automatically disabled, andIndividual settings by serviceThis is possible.

Disqualification Criteria

in the existing grouponly in case of withdrawalIt will be automatically disabled.

Before Change GroupAfter Change GroupDeparture StatusPolicy Action
ABdepartureDeactivation Target
AA, BNot a departure (only addition occurs)maintenance
A, BADeparture (Departure from B)Deactivation Target
A(none)Exit (All Group Exit)Deactivation Target

Applicable Services

Set the automatic synchronization usage for each service toggle individually.

Servicedefault value
Security365Not in use
SHIELD GateNot in use
SHIELD DriveNot in use
SHIELD DRMNot in use
SHIELD MailNot in use
SDFNot in use

Note: The list of services displayed varies depending on the services currently subscribed to.

Scope of Application

This policy applies equally to group changes for all paths below.

  • Manual Modification in the Management Center
  • SCI Server Synchronization
  • CSV Synchronization (Bulk Registration)
  • Microsoft 365 Synchronization
  • SAML SP Integration

Caution

  • The conditional policy of a service with the toggle disabled is not affected when moving groups.
  • Even if you change the toggle of a specific service back to disabled, the previously automatically disabled conditional policies will not be restored. If necessaryCondition Items > Conditional Policy MembersYou must activate it directly.
  • If changes exceed 500 people at once, the automatic synchronization process will be carried out in parts, so it may take time to reflect.

Unused Account Automatic Deactivation Policy

This is a policy that automatically deactivates user accounts that have not been accessed for a certain period. Automatic deactivation is performed daily based on the set period. Admin accounts are excluded from the target.

itemDescription
Automatic Deactivation of Inactive AccountsUse / Not Use Selection (Default: Not Use)
Deactivation Criteria PeriodDays elapsed since last access (default: 90 days, enter an integer of 1 or more)

UnusedThe duration input field will be disabled when selected.SaveThe settings will be applied when clicked.