Account and security
What protects an account once somebody is already inside it: a second proof at sign-in, separate passwords for the devices that cannot give one, a way back in when the password is lost, and a list of everywhere the account is currently signed in. How a session begins and ends is covered under Signing in.
Change your password
Summary A dialog, reachable from the Security settings and from the account menu, where the user types the current password once and the new one twice. A strength indicator and a hint stating how long the password has to be and which characters it needs can be shown beside the fields. Saving ends the session, and the button says so before it is used.
Why it matters A password becomes a liability the moment it turns up in a breach list, is typed into a convincing imitation of the login page, or is known to somebody who should no longer have it. If changing it means opening a ticket, the change waits for the helpdesk, and the old password keeps working in the meantime. Keeping it in the settings makes the response immediate, and applies the deployment's own length and character rules at the moment they actually matter.
Description
- Asks for the current password once and for the new one twice
- A strength indicator and a hint about the required length and characters can be shown
- Minimum and maximum length, the required special characters and a regular expression the new password must satisfy are set by the deployment
- Changing the password signs the user out; the button reads Change password and sign out
- A guest account that has no password yet gets an Add login password variant instead
Availability Since 7.10.6 or earlier. Requires edit_password. The length limits, the required characters, the strength indicator and an optional password generator are configured under io.ox/core//password.
Protect sign-in with a second step
Summary After the password is accepted, sign-in asks for one more proof: a code sent by text message, a code from an authenticator app, or a security key. Where more than one method has been registered, the user chooses which to use. The methods themselves are added, renamed and removed in the Security settings.
Why it matters A password is a single secret, and it can be phished, reused across sites, or read out of somebody else's breach. Once it leaks, nothing stands between an attacker and a mailbox that holds the password resets for every other account the person owns. A second step makes the stolen password worthless on its own, because whoever has it would also have to hold the phone or the key. For an organization it is the one control that still works after a user has made a bad judgment call on a convincing fake login page.
Description
- Sign-in asks for the second step after the password, and offers a choice between the registered methods
- Supported methods are a code by text message, an authenticator app code (TOTP), a FIDO/U2F security key and Yubikey one-time passwords
- A printable backup code can be registered as a recovery option for the case the device is lost
- I lost my device on the sign-in prompt falls back to that recovery option
- Methods are added, renamed and removed in the Security settings
- Sensitive actions can ask for the second step again during a session that is already signed in
Availability Since 7.10.6 or earlier. Requires multifactor together with multifactor_service, and is not offered to anonymous guests. A multifactor service must be configured in the Middleware. Whether more than one method may be registered is a setting.
Application passwords for other mail and sync clients
Summary Separate passwords, each created for one named application, that the user hands to a mail client or a phone instead of the account password. The Security settings list the ones that exist. A new password is shown once, at the moment it is created, and removing it later cuts off that one client.
Why it matters The mail app built into a phone, and most desktop mail clients, sign in with a password and have nowhere to type a code from an authenticator app. Without application passwords the choice is between switching the second factor off and not using those clients at all, and the second factor is usually what loses. An application password keeps it in place for the browser while each device gets a credential of its own, so a phone left in a taxi costs one password that is revoked in the settings — not the account password and every client that shares it.
Description
- The Security settings list the application passwords that currently exist
- Create one for a named application, choosing the application and a descriptive name for it
- The new password is shown once, straight after it is created
- Removing a single password cuts off the client that uses it and leaves the others alone
Availability Since 7.10.6 or earlier. Requires app_passwords.
Reset a forgotten password yourself
Summary A Forgot password link on the sign-in page asks for the email address and sends a reset link to it. Following that link opens a page that checks the token and asks for the new password twice. An Account recovery section in the Security settings holds the recovery email address and mobile number the account is recovered with.
Why it matters A forgotten password is the most common reason anybody contacts support, and it arrives at the worst moment: on a Sunday, from the road, from somebody who cannot read the mail explaining what to do next. Handled by hand it costs the operator a ticket and an identity check every time, and costs the user hours of being locked out of everything the account reaches. Letting the account prove itself through an address and a number registered in advance takes the human out of the middle of it.
Description
- A Forgot password link on the sign-in page asks for the email address and sends a reset link
- The link opens a page that validates the token and asks for the new password twice
- The new password is checked against the same requirements as one changed from the settings
- An Account recovery section in the Security settings stores a recovery email address and a mobile number
- The same two fields can be presented as a page of the first start wizard
- A deployment that runs its own reset page configures a link to it, and the built-in flow steps aside
Availability Since 8.46. Requires account_recovery and is not available to guest users. Feature toggle accountRecovery, off by default. Whether the email address, the phone number or both are asked for is configurable, and the Middleware must provide the account recovery service.
Require recovery details before continuing
Summary Turns the recovery email address and mobile number from something a user may fill in into something they must. The fields are marked as required wherever they appear, and the page of the first start wizard that asks for them cannot be left behind until they carry a value.
Why it matters Self-service password reset only helps the accounts that registered a way of being reached, and left optional, those are exactly the accounts that end up calling support. Asking once, at first sign-in, catches every user at the only moment they are guaranteed to be paying attention, so the way back in exists before anybody needs it. Which of the two fields are compulsory stays with the deployment, for the markets and the user groups where a mobile number cannot be asked for.
Description
- The recovery fields in the settings and in the first start wizard are marked as required
- The wizard page cannot be completed while a required field is empty
- Which of the fields are asked for stays under the deployment's control
Availability Since 8.50. Requires account_recovery, is not available to guest users, and needs the accountRecovery toggle to be on as well. Feature toggle accountRecoveryMandatory, off by default. Not available on smartphones.
Require a first and last name before using the account
Summary Holds the first start wizard open at sign-in until the user has supplied the personal data the deployment insists on, beginning with a first and last name. It works whether or not the regular first start wizard is in use, and it can be told to clear provisioned placeholder names once so that they have to be replaced.
Why it matters A directory that was migrated or provisioned in bulk often arrives with placeholder names, or with no surname at all, and that placeholder is then what appears on every message the account sends, on every meeting invitation and in the company address book. Asking people to correct it in a newsletter reaches almost nobody. Holding the wizard open at sign-in reaches everybody exactly once, and fixes the data at its source rather than through a provisioning run against names the operator does not know.
Description
- First and last name are marked as required, and the wizard cannot be left without them
- Enforced at every sign-in until the data has been stored
- Works even where the regular first start wizard is switched off
- Can clear provisioned placeholder names once, so the user is made to replace them
Availability Since 8.46. Not available to guest users, and not on smartphones. Feature toggle mandatoryPersonalData, off by default. It also needs personal data to be editable at all, which is itself a setting.
See where you are signed in and sign out other devices
Summary A list in the Security settings of every session the account currently holds, each with the name of the client it belongs to, where it is, and when it was last active. The session the user is sitting in is marked and sorted to the top. A sign-out button beside any of the others ends that one.
Why it matters A session outlives the moment it was created: the browser left signed in on a hotel computer, the laptop taken out of a car, the tablet handed on to somebody in the family. Changing the password does not by itself tell the user whether anybody else is still reading their mail. A list of live sessions answers that question directly — a device or a location the user does not recognize is the evidence — and the button next to it ends that session without ending the one being used to look.
Description
- Each session is listed with the client name, its location and when it was last active
- The current session is marked and sorted to the top
- Sign out ends a single other session, after a confirmation
Availability Since 8.16. No capability is required, but the Middleware must offer the session management endpoint.