An IAM organization administrator configures the following settings for the organization:
Allowed email domains
Password complexity and password expiration times
Options for two-factor authentication
Expiration times for Web UI session tokens, user enrollment links, and API keys
The following list describes the configurable fields in the Organization Settings page:
Organization Details and Description
Description—A description of this IAM organization.
User Email Addresses
Allowed email domains—(Optional) A comma-separated list of email domains allowed for user accounts.
Default: No domains are specified (all email domains are allowed).
Authentication Policy
Minimum policies—(Optional) The minimum number of user identity factors required, including the mandatory knowledge factor (the user password). Increment this value for each possession factor in your policy.
Range: 1–4
Default: 1 (Single-factor authentication only)
Options for Two-Factor Authentication
(Optional) Override the default value of any of the two-factor authentication (2FA) settings.
2FA is disabled by default. All 2FA options are Not Enabled and Minimum Policies is 1. If any 2FA options are Mandatory, users must provide those knowledge factors to authenticate. If two or more 2FA options are Enabled, users can provide any one of the knowledge factors.
One‑Time Password—The policy for using one-time-use passwords generated by the Google Authenticator app on an Android, Blackberry, or iPhone device:
Mandatory
Enabled
Not enabled (default)
Text Message—The policy for using one-time-use passwords sent by SMS message:
Mandatory
Enabled
Not enabled (default)
Voice Call—The policy for using one-time-use passwords sent by voice call:
Mandatory
Enabled
Not enabled (default)
Password Policy
Password complexity and expiration parameters—(Optional) Customize the policy for single-factor authentication passwords:
Trellix Policy―All options are selected. (Default)
Custom Policy—An administrator selects options individually.
The following options can be selected and edited:
Password expires after 60 days
Cannot use last 24 passwords
Account deactivation due to 90 days of inactivity
Allow 3 invalid attempts before lockout
Locked account is unlocked after 1800 seconds (30 minutes)
After 900 seconds (15 minutes), invalid attempt count is reset
At least 12 characters
At least 1 lowercase character
At least 1 numeral
At least 1 special character
At least 1 uppercase character
Expiration Details
(Optional) Override the default value of any of the following expiration times. Specify expiration times in units of seconds, minutes, hours, days, or years by appending the letter s, m, h, d, or y.
Token expires in
Web UI session timeout.
Default: 12h
Link expires in
User enrollment link timeout.
Default: 48h
API key expires in
API connection timeout.
Default: 90d