> For the complete documentation index, see [llms.txt](https://athome-1.gitbook.io/athome-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://athome-1.gitbook.io/athome-docs/setup/security.md).

# Security

This tab contains security settings regarding password policy, two-factor authentication, and active sessions.

***

## Password security policy

* Force passwords to comply with security policy

<figure><img src="https://2965217165-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBk8u0TPogHtiUd7DaQyf%2Fuploads%2Fgit-blob-4184e175f5cbf9996654c10f79290fdf6b9dfa67%2Fpassword_security_policy.png?alt=media" alt=""><figcaption></figcaption></figure>

***

### Security policy configuration

The security policy is only enforced if this is enabled

* Password minimum length
* Password need digit
* Password need lowercase character
* Password need uppercase character
* Password need symbol

***

### Password expiration policy

The following options can be configured as part of the password security policy:

* Password expiration delay (in days)
* Password expiration notice time (in days)
* Delay before account deactivation (in days)
* Validity period of the password initialization token
* Prevent users from reusing previous passwords

***

## Two-factor authentication (2FA)

* 2FA Suffix : This will be added in the issuer name for authenticator app
* Enforce 2FA

<figure><img src="https://2965217165-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBk8u0TPogHtiUd7DaQyf%2Fuploads%2Fgit-blob-8124023af41f914fd73adf3064f7fad722ee54a9%2Fsecurity-2fa.png?alt=media" alt=""><figcaption><p>View 2FA</p></figcaption></figure>

***

## Sessions

This tab lists all active user sessions and allows you to revoke them. Available informations:

* **Type**: type of connexion
* **User**: displays first and last name
* **Details**: browser version, OS type, etc.
* **IP address**
* **Login**: user login time
* **Last activity**: time of last detected activity
* **Status**: connection status
* **Actions**: revoke a session

<figure><img src="https://2965217165-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBk8u0TPogHtiUd7DaQyf%2Fuploads%2Fgit-blob-9ecce9b6d49a33fa4c09d571d31ac321a5594cb8%2Fsecutiry-sessions.png?alt=media" alt=""><figcaption><p>Details of sessions</p></figcaption></figure>

### Revoke a session

Revoking a session closes it. The user will need to log in again after this action.

<figure><img src="https://2965217165-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBk8u0TPogHtiUd7DaQyf%2Fuploads%2Fgit-blob-73d76b1ce7d3f74a110093358325871e52eee6fe%2Fsecutiry-revok-session.png?alt=media" alt=""><figcaption><p>Revok a session</p></figcaption></figure>

### Revoke all sessions

You can also revoke all active sessions

<figure><img src="https://2965217165-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBk8u0TPogHtiUd7DaQyf%2Fuploads%2Fgit-blob-99b288b187235609910fc2dda0f47049078325c4%2Fsecutiry-revok-all-sessions.png?alt=media" alt=""><figcaption><p>Revoke all active sessions</p></figcaption></figure>
