How to Apply Security Rules

Strengthen Your Security: A Guide to Setting Security Rules

Welcome to your command center for account security! The Security Rules page in Smackdab gives you the power to create a robust security framework for your entire team. From enforcing strong passwords and enabling two-factor authentication to restricting logins to specific locations, you can customize your settings to protect your valuable data and maintain total peace of mind.

Ready to fortify your defenses? Let's get started.

How to Get There

First, navigate to the right spot in your Smackdab account:

  1. Go to Settings.

  2. Choose the Security Center.

  3. Click on Security Rules.

Now you're ready to customize your security settings.

Enable Two-Factor Authentication (2FA)

This is one of the most effective ways to secure your account. When enabled, users will need both their password and a code from an authenticator app to log in.

  • To enable 2FA: Simply click the toggle to the "on" position. A "Confirm Update" pop-up will appear. Click "Yes" to proceed.

  • Setup Process: A window will guide you through scanning a QR code with an authenticator app (like Google Authenticator or Authy) and verifying the code.

  • To disable 2FA: Just click the toggle to the "off" position.

Set Strong Password Requirements

Ensure every user has a strong, hard-to-guess password by setting clear standards.

  • Add Complexity: Check the boxes to require passwords to include:

    • Both lowercase and uppercase letters

    • At least one number

    • At least one special character (e.g., !, @, #)

  • Set the Length: By default, Smackdab requires a minimum of 12 characters. You can adjust this requirement to be anywhere between 12 and 30 characters.

Manage Password Lifecycles & Lockouts

Keep your defenses fresh and protect against brute-force attacks with these settings.

  • Password Expiration: Use the dropdown menu to decide how often users must update their passwords (e.g., every 90 days).

  • Password Reuse: Prevent users from recycling old passwords. Select a setting from the dropdown to determine how many new passwords must be used before an old one can be repeated.

  • Login Lockout Policy: To protect against repeated login attempts, Smackdab will automatically lock an account after 3 unsuccessful tries (the account unlocks after 24 hours). You can customize this threshold to be anywhere from 3 to 30 attempts.

Control Access with IP Restrictions

For an extra layer of network security, you can ensure users can only log in from trusted locations, like your office.

  1. Click the "Add" button in the "Allow access only for specific IP addresses" section.

  2. In the "Allow IP" window that appears, enter the specific IP address you want to grant access to.

  3. You can also set a start and end time for when this access is valid.

  4. Click "Save", and the IP address will be added to your allowlist.