The Security section allows you to control access to your DocSpace and monitor the activity of all users. It includes three subsections: DocSpace Access, Login History, and Audit Trail.
Controlling DocSpace access
The DocSpace Access subsection of the Security settings allows you to provide users with secure and convenient ways to access the DocSpace.
Password strength settings
This section allows you to determine password complexity (the effectiveness of a password in resisting guessing and brute-force attacks). To do that,
Two-factor authentication
This section allows you to enable two-step verification with authenticator apps that ensures more secure DocSpace access.
To enable two-factor authentication with an authenticator app,
- check the By authenticator app radio button under the Two-factor authentication section,
- click the Save button at the bottom of the section to apply the changes you made.
When two-factor authentication with an authenticator app is enabled, a user can access the DocSpace data after entering their regular email and password or signing in via a social media account and typing in a six-digit verification code or a backup code generated by the authenticator app.
To access your DocSpace for the first time after enabling two-factor authentication:
- Enter your regular credentials to access your DocSpace. The QR code and your secret key are displayed on your DocSpace login confirmation page.
- Install an authenticator app on your mobile device. You can use Google Authenticator for Android and iOS or Authenticator for Windows Phone.
- Open the authenticator app on your mobile device and configure it in one of the following ways:
- Scan the QR code displayed in the browser, or
- Manually enter your secret key displayed in the browser,
- On your DocSpace login confirmation page, enter a 6-digit code generated by your application.
- Click the Connect app button.
To learn more on how to use two-factor authentication in your DocSpace, you can read the following article.
Trusted mail domain settings
This section allows you to specify the mail servers used for user self-registration in your DocSpace. By default, this option is disabled. To enable it,
- check the Custom domains radio button,
- enter the trusted mail server in the field which appears below,
- click the Save button at the bottom of the section to apply the changes you made.
To add more mail servers, use the Add trusted domain link. To delete a server added by mistake, click the corresponding
icon to the right of the field.
After that, any user who has an account at a specified mail server will be able to register on their own by clicking the Click here to join link on the Sign In page and entering the email address. An invitation email with a link to the DocSpace will be sent to the specified email address. To sign in, the user will need to follow the link provided in the email, enter a password and confirm it.
To disable this option again, just check the Disabled radio button.
IP security settings
This section allows you to prevent unwanted visitors from accessing your DocSpace by allowing access to the DocSpace from trusted networks only. If a user attempts to log in to your DocSpace from any IP address except those you specify, this login attempt will be blocked. To restrict access to your DocSpace based on the IP addresses,
- check the Enable radio button;
- click the Add allowed IP address link;
- in the entry field that appears, specify a single IP address in the IPv4 format (#.#.#.#, where # is a numeric value from 0 to 255) or set an IP addresses range by entering the starting and ending IP addresses of the range in the #.#.#.#-#.#.#.# format;
You can find the information on your DocSpace visitors IP addresses in the Login History subsection of the Security settings by clicking the Download and open report button.
- in the same way, add as many trusted IP addresses as you need;
- click the Save button at the bottom of the section.
If necessary, you can delete the added IP addresses by clicking the corresponding
icon to the right of the IP address. To disable this option again, just check the Disable radio button and click the Save button.
Administrator message settings
This section allows you to display the contact form on the Sign In page so that people can send a message to the DocSpace administrator in case they have troubles while accessing DocSpace.
To enable it, just check the corresponding radio button and click the Save button at the bottom of the section to apply the changes you made.
Session Lifetime
This section allows you to set a time limit (in munutes) during which the DocSpace users will need to enter their DocSpace credentials again in order to access the DocSpace.
To set a session lifetime, check the Enable radio button, enter the necessary time value measured in minutes in the Lifetime field that appears and click the Save button at the bottom of the section to apply the changes you made. After that, all the users will be logged out from the DocSpace.
When this setting is enabled, the Remember me checkbox will be hidden on the login page.