TrainMeUK LogoTrainMeUK
Home
How It Works
Product
Reports
Pricing
Resources
Login

Summer sale

Limited time

15% off monthly · +20% annual

15%off monthly+20%off annual
Claim offer
Help
Help Center
Adding DepartmentsUser Roles & PermissionsPassword Policy & MFAManaging Inactive & Returning UsersPersonal & Shared Email DomainsTroubleshooting SSO & SCIM
Adding DepartmentsUser Roles & PermissionsPassword Policy & MFAManaging Inactive & Returning UsersPersonal & Shared Email DomainsTroubleshooting SSO & SCIM
HelpUser ManagementPassword Policy & MFA

Password Policy & MFA

Configure password requirements and multi-factor authentication

Overview

Security settings control:

  • Password complexity requirements
  • Password expiry and history
  • Account lockout policies
  • Multi-factor authentication options

These settings apply organisation-wide.

Accessing Security Settings

1

Open System Settings

  1. Log in as an Admin
  2. Go to Admin → System Settings
  3. Select the Security tab

Password Policy Settings

Admin → System Settings → Security — Password Policy and MFAClick image to enlarge

Password Complexity

Control what passwords must contain:

SettingPurposeRecommended
Minimum LengthShortest allowed password8-12 characters
Require UppercaseMust contain A-ZYes
Require LowercaseMust contain a-zYes
Require NumbersMust contain 0-9Yes
Require Special CharactersMust contain !@#$% etc.Optional

Configuring Password Complexity

  1. Navigate to Security Settings
  2. Find the Password Policy section
  3. Set your requirements: enter minimum length, toggle on/off required character types
  4. Click Save

Password Age

Control how long passwords remain valid:

SettingPurposeExample
Maximum Password AgeDays until password expires90 days
Password Never ExpiresDisable expiryToggle on/off

Password History

Prevent reuse of recent passwords:

SettingPurposeExample
Remember Previous PasswordsHow many old passwords to block5 passwords

Account Lockout Settings

Protect against brute-force attacks:

Account lockout — Failed Login Attempts, Lockout Duration, and Reset Counter AfterClick image to enlarge
SettingPurposeRecommended
Failed Login AttemptsAttempts before lockout5
Lockout DurationMinutes account is locked15-30 minutes
Reset Counter AfterMinutes before counter resets15 minutes

What Happens on Lockout

  • User sees "Account locked" message
  • Must wait for lockout period
  • Or contact admin for manual unlock

Multi-Factor Authentication (MFA)

Add an extra layer of security beyond passwords.

Multi-Factor Authentication — Require MFA for all users, Authenticator App, backup codesClick image to enlarge

MFA options in System Settings

SettingDescription
Require MFA for all usersForce all users to set up MFA
Enable Authenticator AppAllow apps such as Google Authenticator
Backup Codes CountHow many backup codes to generate (5–20)
Email Code Expiry (minutes)How long email codes remain valid (5–60)

Configuring MFA Settings

  1. In Security Settings, open the Multi-Factor Authentication sub-tab
  2. Toggle Require MFA for all users if you want MFA mandatory
  3. Toggle Enable Authenticator App to allow authenticator apps
  4. Under MFA Configuration, set Backup Codes Count and Email Code Expiry (minutes)
  5. Click Save MFA Settings

Tip

There is no SMS MFA option in System Settings. Learners use an authenticator app, with email codes and backup codes for recovery as configured above.

Step-by-Step: Enforcing MFA

1

Enable MFA Features

  1. Go to Admin → System Settings → Security
  2. Open the Multi-Factor Authentication sub-tab
  3. Enable Enable Authenticator App
  4. Set Backup Codes Count and Email Code Expiry (minutes)
  5. Click Save MFA Settings
2

Require MFA for all users

  1. Toggle Require MFA for all users on
  2. Click Save MFA Settings
3

Communicate to Users

Let users know:

  • MFA is now required
  • How to set it up
  • Where to get help

What Users Experience

First Login After MFA Required

  1. User logs in with password
  2. Prompted to set up MFA
  3. Scans QR code with authenticator app
  4. Enters verification code to confirm
  5. Receives backup codes to save
  6. Future logins require code from app

Subsequent Logins

  1. Enter username and password
  2. Enter code from authenticator app
  3. Access granted

Best Practices

Password Policy

AreaRecommendation
Length8-12 minimum
ComplexityRequire upper, lower, and numbers
Expiry90 days (or never with MFA)
HistoryRemember last 5 passwords

MFA

AreaRecommendation
RequirementHighly recommended for admins
MethodAuthenticator app preferred
BackupAlways enable backup codes

Account Lockout

AreaRecommendation
Attempts5 failed attempts
Duration15-30 minutes

Tip

Balance security and usability. Too strict = frustrated users. Too lenient = security risk. Find the right balance for your organisation.

Temporary Passwords

When admins create users with temporary passwords:

  • Temporary passwords may bypass complexity requirements
  • Users must change password on first login
  • The new password must meet complexity requirements

This allows admins to create simple temporary passwords for new users.

Troubleshooting

User locked out

Wait for lockout period, or go to User Management and unlock manually. Check for suspicious activity.

User forgot MFA device

Use backup codes if they saved them. Admin can reset MFA in User Management. User sets up MFA again.

Password rejected as too simple

Check complexity requirements. Ensure all requirements are met. Try a longer, more complex password.

MFA code not working

Check device time is correct (TOTP is time-sensitive). Ensure using correct authenticator. Try a fresh code (they refresh every 30 seconds).

Need to disable MFA temporarily

Consider if really necessary. Admin can disable for specific user in emergency. Re-enable as soon as possible.

Compliance Considerations

Financial Services

Often require: MFA for all users, 90-day password expiry, Strong complexity requirements

Healthcare

Often require: Audit trails of access, Strong authentication, Session timeouts

Education

Requirements vary: Check Ofsted/regulatory requirements, Consider safeguarding access controls

Related Guides

  • Creating Users - User account setup
  • User Roles & Permissions - Access control settings
  • Adding Frameworks - Compliance frameworks
Previous

User Roles & Permissions

Next

Managing Inactive & Returning Users

TrainMeUK LogoTrainMeUK Ltd

Connect Azure once. TrainMeUK handles reminders, Teams nudges, certificates, and audit-proof reports — automatically.

hello@trainmeuk.co.uk
+44 1252 929213
8 George Myers Close, Ash, Guildford, Surrey, GU12 6FW

Quick Links

  • Home
  • How It Works
  • Product
  • Reports
  • Pricing
  • Resources
  • Knowledge Base

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Processing Addendum
  • Subprocessors
  • Acceptable Use Policy
  • FAQ

Popular Resources

Mandatory Training Requirements for UK BusinessesHow Often GDPR Training Should Be Done in the UKHow Fast You Should Produce Training Records for Auditors

© 2026 TrainMeUK Ltd. All rights reserved.

CPD Accredited Provider