XTM Cloud v 13.1

Authentication settings
Allowing API authentication for new users

The function is enabled by default. If this function is switched on, Administrator can decide how users can log to XTM: via User Interface and API, via UI only, or API only.

  1. Go to Configuration > Settings > Security.

  2. Select the Allow API authentication for new users checkbox.

  3. Select Save.

The Authentication section in Edit user > Access rights will appear only for users with PM roles.

Enabling the 2-step verification on your XTM instance
  1. Go to Configuration > Settings > Security.

  2. Select the Use 2-step verification checkbox.

  3. Select Save.

  4. Log out from XTM.

All users are required to go through the 2-step verification process to log in to XTM.

Configuring allowed login attempts
  1. If the user makes the number of invalid login attempts specified, then their account will be blocked, and they will not be able to access the system.

  2. unblock the account, the Administrator needs to go to the Users tab and select Unblock account from the menu icon bars-solid.png in the left-hand column of the users listing.

  1. Go to Configuration > Settings > Security.

  2. In the Allowed log on attempts enter the number of times the user can try to log in.

  3. Select Save.

If the user makes the number of invalid login attempts specified, then their account will be blocked, and they will not be able to access the system. The account will then need to be unblocked by the Administrator.

Disabling account after non-use

If the user does not log into their account during the period of days specified, then the account will be blocked. The account will then need to be unblocked by the Administrator as described above.

  1. Go to Configuration > Settings > Security.

  2. In the Disable account after non-use (days) enter the number of days after which the user cannot access the system.

  3. Select Save.

If the user does not log into their account during the period of days specified, then the account will be blocked. The account will then need to be unblocked by the Administrator.