Skip to main content

XTM Cloud 13.4

Authentication settings
Allowing API authentication for new users

The function is enabled by default. If this function is switched on, Administrator can decide how users can log to XTM: via User Interface and API, via UI only, or API only.

  1. Select Configuration > Settings > Security.

  2. Select the Allow API authentication for new users checkbox.

  3. Select Save.

The Authentication section in Edit user > Access rights will only be displayed for users to whom the Administrator role has been assigned.

Enabling the 2-step verification on your XTM Cloud instance
  1. Select Configuration > Settings > Security.

  2. Select the Use 2-step verification checkbox.

  3. Select Save.

  4. Log out from XTM Cloud.

All users are required to go through the 2-step verification process to log in to XTM Cloud.

Configuring allowed login attempts
  1. If the user makes the number of invalid login attempts specified, then their account will be blocked, and they will not be able to access the system.

  2. unblock the account, the Administrator needs to go to the Users tab and select Unblock account from the menu icon bars-solid.png in the left-hand column of the users listing.

  1. Select Configuration > Settings > Security.

  2. In the Allowed log on attempts enter the number of times the user can try to log in.

  3. Select Save.

If the user makes the number of invalid login attempts specified, then their account will be blocked, and they will not be able to access the system. The account will then need to be unblocked by the Administrator.

Disabling account after non-use

If the user does not log into their account during the period of days specified, then the account will be blocked. The account will then need to be unblocked by the Administrator as described above.

  1. Select Configuration > Settings > Security.

  2. In the Disable account after non-use (days) enter the number of days after which the user cannot access the system.

  3. Select Save.

If the user does not log into their account during the period of days specified, then the account will be blocked. The account will then need to be unblocked by the Administrator.