Security Settings
Manage your account security including password, multi-factor authentication, and linked accounts.
Manage your account security including password, multi-factor authentication, and linked accounts.
Accessing Security Settings
Security settings are part of your profile settings:
- Go to Profile in the sidebar
- Navigate to the security-related sections
- The URL is
/home/settings
Password Management
Changing Your Password
If password authentication is enabled:
- Find the Password section
- Enter your current password
- Enter your new password
- Confirm the new password
- Click Update Password
Note: Password change is only available if your organization has password authentication enabled.
Password Best Practices
- Use unique passwords - Don't reuse passwords from other sites
- Use a password manager - Tools like 1Password, LastPass, or Bitwarden
- Never share your password - Support will never ask for it
Multi-Factor Authentication (MFA)
MFA adds an extra layer of security by requiring a second verification step when signing in.
Viewing MFA Factors
The Multi-Factor Authentication section displays:
- A table of enrolled factors
- Factor name (friendly name)
- Factor type (e.g., TOTP)
- Factor status (verified or unverified)
No Factors Enrolled
If you have no MFA factors enrolled, you'll see an information card encouraging you to set up multi-factor authentication.
Setting Up MFA (TOTP Authenticator)
- Find the Multi-Factor Authentication section
- Click Setup Authenticator App
- A dialog will open with a QR code
- Scan the QR code with your authenticator app:
- Google Authenticator
- Authy
- Microsoft Authenticator
- 1Password
- Enter the 6-digit code from the app to verify
- The factor appears in your enrolled factors table
Unenrolling an MFA Factor
To remove an MFA factor:
- Find the factor in your enrolled factors table
- Click the X button to remove it
- A confirmation dialog appears
- Confirm the unenrollment
Warning: Removing your MFA factor makes your account less secure.
Using MFA to Sign In
Once MFA is enabled:
- Enter your email and password
- When prompted, open your authenticator app
- Enter the 6-digit code
- Click Verify
See Setting Up MFA for detailed instructions.
Linked Accounts
If identity linking is enabled, you can connect multiple sign-in methods to your account.
Viewing Linked Accounts
The Linked Accounts section shows:
- Your current authentication methods
- Email/Password connection status
- OAuth provider connections (Google, etc.)
Linking a New Account
- Click Link next to an available provider
- Complete the OAuth flow (sign in with the provider)
- The account is now linked
Unlinking an Account
- Find the account in your linked list
- Click Unlink to remove the connection
- Confirm the action
Note: You must have at least one sign-in method. You cannot unlink your only authentication method.
Benefits of Linked Accounts
- Sign-in flexibility - Use any linked method to sign in
- Account recovery - Multiple ways to access your account
- Convenience - Use OAuth instead of password
Email Authentication
Update Email
To change your email address:
- Find the Update Email section
- Enter your new email address
- Click Update Email
- A verification email is sent
- Click the link in the email to confirm
Link Email (if not primary method)
If you signed up with OAuth and want to add email login:
- Find the Linked Accounts section
- Click Link Email (if available)
- Enter the email and password you want to use
- Verify through the confirmation email
Forgot Password
If you've forgotten your password:
- Go to the sign-in page
- Click Forgot Password
- Enter your email address
- Check your email for the reset link
- Create a new password
See Password Reset for details.
Security Recommendations
Checklist
- Use a strong, unique password
- Enable multi-factor authentication
- Review linked accounts periodically
- Be cautious of phishing attempts
What to Do If Compromised
If you suspect your account is compromised:
- Change your password immediately
- Review linked accounts - Remove any you don't recognize
- Enable MFA if not already
- Contact support if needed
Feature Availability
Security features depend on your organization's configuration:
| Feature | Configuration |
|---|---|
| Password change | Password auth enabled |
| MFA enrollment | Always available |
| Identity linking | Identity linking enabled |
| Email linking | Email auth enabled |
Related Topics
- Setting Up MFA - Detailed MFA guide
- Password Reset - Recover access
- Signing In - Authentication methods
- Profile Settings - Account information