MiroxMirox
  • Platform

    • Philosophy
    • Platform Overview
    • Platform Resources
  • Mirox-Cloud

    • Cloud Overview
    • Connected Microservices
  • Mirox-Agent

    • Agent Overview
    • Deployment Options
    • Data Scraper
    • Digital Twin
  • Technical Details

    • Metric Collection
  • Information

    • Supported Plants
  • Plant Types

    • Solar Plants
    • Wind Plants
    • Battery Storage
    • Alarm System
  • Monitoring & Visualization

    • Real-time Monitoring
    • Digital Twin
    • Component States
    • Inverter Status Codes
    • Inverter Events
    • Loss Detection
    • Power Limits & Curtailment
    • Efficiency Detection
    • KPI Dashboard
  • Data Management

    • Events
    • Alarm Levels
    • Tickets
    • Forecasts
    • Reports
    • Metrics
  • Alert Manager

    • Overview
    • Alert Rules
    • Alerts & Notifications
    • Examples
  • Integration & Sharing

    • Cooperations
    • API Tokens
    • VPN
    • VPN Address Conflicts
    • Proxy
  • AI

    • AI Assistant & Wizards
    • Agentic Access (MCP)
  • Billing

    • Market & Tariffs
    • How Revenue Is Calculated
    • Accounting & Billing
  • Collaboration

    • Invitations
  • Security

    • Authentication
    • Account Lockout
    • Organization Security Policy
    • Permission System
    • Network Segmentation
    • Cooperation Restrictions
    • Access Audit Logging
    • Activity & Audit Trail
  • Nodes

    • mrxnode
  • Application

    • Door Control
    • Generic Relay
  • Edge Cluster

    • Orchestration
  • Getting Started

    • Onboarding
    • Setup
  • Personal

    • Using the VPN
    • Using the Proxy
    • Two-Factor Authentication
    • Sessions
    • API Tokens
    • Notifications
    • Connect Microsoft Teams
  • Per Park

    • Contacts
    • Network Devices
    • Data Loggers
    • Generic Modbus Reader
    • Components
    • Direct VPN (per Agent)
    • Data Volume
    • History Import
  • Organization

    • Member Permissions
    • Security Policy
    • Cooperations
    • File Storage
    • VPN Services
    • Working with Reports
  • Data Export

    • Metric Export
    • Metric Export API
    • Migrating to the Metric Export
    • Legacy Export API
    • External Report Generation
    • Grafana
    • Grafana Dashboards
    • API Overview
    • MiroxQL Formulas (API)
  • Support

    • Request an Integration
  • mrxnode

    • Overview
    • How-To Guide
    • Container Deployment
    • Command Cheatsheet
    • Troubleshooting
  • Reporting

    • External Report Generator
    • Metric Export for Excel
  • Remote Access
  • Account Security
  • AI in Mirox
  • History Import
  • Reports
  • Data Export
  • English
  • Deutsch
  • Español
  • Français
  • Português
  • Italiano
  • English
  • Platform

    • Philosophy
    • Platform Overview
    • Platform Resources
  • Mirox-Cloud

    • Cloud Overview
    • Connected Microservices
  • Mirox-Agent

    • Agent Overview
    • Deployment Options
    • Data Scraper
    • Digital Twin
  • Technical Details

    • Metric Collection
  • Information

    • Supported Plants
  • Plant Types

    • Solar Plants
    • Wind Plants
    • Battery Storage
    • Alarm System
  • Monitoring & Visualization

    • Real-time Monitoring
    • Digital Twin
    • Component States
    • Inverter Status Codes
    • Inverter Events
    • Loss Detection
    • Power Limits & Curtailment
    • Efficiency Detection
    • KPI Dashboard
  • Data Management

    • Events
    • Alarm Levels
    • Tickets
    • Forecasts
    • Reports
    • Metrics
  • Alert Manager

    • Overview
    • Alert Rules
    • Alerts & Notifications
    • Examples
  • Integration & Sharing

    • Cooperations
    • API Tokens
    • VPN
    • VPN Address Conflicts
    • Proxy
  • AI

    • AI Assistant & Wizards
    • Agentic Access (MCP)
  • Billing

    • Market & Tariffs
    • How Revenue Is Calculated
    • Accounting & Billing
  • Collaboration

    • Invitations
  • Security

    • Authentication
    • Account Lockout
    • Organization Security Policy
    • Permission System
    • Network Segmentation
    • Cooperation Restrictions
    • Access Audit Logging
    • Activity & Audit Trail
  • Nodes

    • mrxnode
  • Application

    • Door Control
    • Generic Relay
  • Edge Cluster

    • Orchestration
  • Getting Started

    • Onboarding
    • Setup
  • Personal

    • Using the VPN
    • Using the Proxy
    • Two-Factor Authentication
    • Sessions
    • API Tokens
    • Notifications
    • Connect Microsoft Teams
  • Per Park

    • Contacts
    • Network Devices
    • Data Loggers
    • Generic Modbus Reader
    • Components
    • Direct VPN (per Agent)
    • Data Volume
    • History Import
  • Organization

    • Member Permissions
    • Security Policy
    • Cooperations
    • File Storage
    • VPN Services
    • Working with Reports
  • Data Export

    • Metric Export
    • Metric Export API
    • Migrating to the Metric Export
    • Legacy Export API
    • External Report Generation
    • Grafana
    • Grafana Dashboards
    • API Overview
    • MiroxQL Formulas (API)
  • Support

    • Request an Integration
  • mrxnode

    • Overview
    • How-To Guide
    • Container Deployment
    • Command Cheatsheet
    • Troubleshooting
  • Reporting

    • External Report Generator
    • Metric Export for Excel
  • Remote Access
  • Account Security
  • AI in Mirox
  • History Import
  • Reports
  • Data Export
  • English
  • Deutsch
  • Español
  • Français
  • Português
  • Italiano
  • English
  • Monitoring & Visualization

    • Real-Time Monitoring
    • Digital Twin
    • Component States
    • Inverter Status Codes
    • Inverter Events
    • Loss Detection
    • Power Limits and Curtailment
    • Efficiency Detection (PRRC)
    • Local Network Inspector
    • Access Monitoring
    • KPI Dashboard
    • Graph Visualization
  • Data Management

    • Events
    • Alarm Levels and Notifiable Events
    • Tickets
    • Forecasts
    • Reports
    • Metrics
  • Alert Manager

    • Alert Manager
    • Alert Rules
    • Alerts & Notifications
    • Examples
  • Integration & Sharing

    • Cooperations
    • API Tokens
    • VPN
    • VPN: Address Conflicts
    • Proxy (Web Access to Plant Devices)
  • AI

    • AI Assistant & Wizards
    • Agentic Access (MCP)
  • Billing

    • Market & Tariffs
    • How Revenue Is Calculated
    • Accounting & Billing
  • Collaboration

    • Invitations
  • Security

    • Authentication
    • Account Temporarily Locked
    • Organization Security Policy
    • Permission System
    • Network Segmentation
    • Cooperation Permission Restrictions
    • Access Audit Logging
    • Activity & Audit Trail

Organization Security Policy

Every organization can set its own sign-in rules: how long its members stay signed in, how often members with two-factor authentication (2FA) sign in again, and whether a second factor is required to see the organization's plants. There is one set of rules per organization, and its Admins and Moderators set it on the organization's Security tab. Where an organization sets nothing, the Mirox platform defaults apply.

This page explains the rules. For the steps, see the guide Setting Your Organization's Security Policy.

The Security Tab

The Security tab of the organization page has three cards:

CardWhat you set there
Two-factor authenticationWhether a second factor is required to see your organization's plants, and from which date.
Web appSession lifetime: how long a sign-in in the browser lasts. 2FA re-check interval: after what time accounts with 2FA sign in again.
Mobile appThe same two fields for the mobile app.

Each value can be left on Platform default. Then Mirox uses the default from the table below.

Who May Edit the Policy

  • Admin and Moderator of the organization see the Security tab and change the rules.
  • The other organization roles — Asset Manager (Technical), Asset Manager (Commercial), Member and External — do not see the tab.
  • Switching the 2FA requirement off, or moving its start to a later date, additionally needs 2FA on your own account.

Every change is recorded in the organization's activity, see Traceability.

Platform Defaults

These values apply to an organization that has set nothing, and to users who belong to no organization:

SettingWeb appMobile app
Sign-in duration (Session lifetime)1 year (the longest possible)1 year (the longest possible)
2FA re-check interval (accounts with 2FA only)NoneNone
Require 2FA for plant accessOffOff

With these defaults a sign-in ends only when its year is up, and accounts with 2FA are not asked to sign in again before that. An organization that wants stricter rules saves shorter values on its Security tab; they apply to its members from that moment on, see When You Change the Rules.

The 2FA requirement is one setting for the whole organization. It is not set per app. No sign-in lasts longer than one year.

Whose Rule Applies to Whom

The two kinds of rules follow different organizations:

RuleDecided by
Sign-in duration and 2FA re-check intervalThe organization you belong to
2FA requirement for plant accessThe organization that owns the plant

So your own organization decides how long you stay signed in. The owner of a plant decides whether you need a second factor to see that plant. Rules about sign-in duration are never passed on to the users of a cooperation partner.

Sign-In Duration

The sign-in duration is the time after which a member signs in again. On the cards this is the Session lifetime field. You set it separately for the web app and for the mobile app.

  • It applies to every member of your organization, from the moment they join it.
  • It counts per sign-in. Each browser and each phone has its own time.
  • When the time is up, the member is signed out and signs in again: with the password, plus the code or the passkey if the account has 2FA.

2FA Re-Check

The re-check interval applies to accounts with a second factor: an authenticator app (TOTP) or a passkey. Such an account is signed out a set time after it last proved its second factor on that sign-in, and signs in again with password and code or passkey.

  • You set it separately for the web app and for the mobile app. By default there is no re-check, see Platform Defaults: the value only takes effect once your organization sets an interval, for example 7 days.
  • A member is never asked for a code in the middle of their work. The code is asked at sign-in, as always.
  • A re-check interval that is longer than the sign-in duration has no effect, because the sign-in ends first.
  • Accounts without 2FA are not affected by this value.

A second factor only protects an account if it is presented regularly. The re-check makes sure that a browser left signed in cannot be used for weeks without the code.

Requiring 2FA

2FA is optional by default: each user decides for their own account. With Require 2FA for plant access your organization makes a second factor a condition for seeing its plants. A second factor is an authenticator app (TOTP) or a passkey; either counts, and a member needs only one of them.

You announce it first. You choose a start date. The default is 7 days ahead, and it must be at least 24 hours ahead, so everyone has time to set 2FA up. Until that date nothing changes. The Security tab shows how many of your members still have no second factor.

From the start date, a user without a second factor no longer sees your organization's plants:

  • not in lists and dashboards,
  • not on the plant pages,
  • not through the plant's device proxy,
  • not in exports and not in Grafana. Grafana follows within about an hour, both when the rule starts and after the user enables 2FA.

What does not happen:

  • Nobody is signed out. The user stays signed in.
  • Profile, settings and the organization pages keep working, so the user can set 2FA up.
  • A hint in the header tells the user to enable 2FA.
  • As soon as the user enables 2FA, the plants are back.
  • Plants of other organizations are not affected.

Cooperation partners. The rule belongs to the organization that owns the plant. It therefore also applies to the users of your cooperation partners on your plants, and to your users on the plants of a partner that requires 2FA. The cooperation list shows whether a partner requires 2FA. See Cooperation Restrictions.

Switching it off. To switch the requirement off or to move its start to a later date, you need 2FA on your own account.

Mirox support

Mirox platform administrators (Mirox support) are not subject to an organization's 2FA requirement.

Mobile App

The mobile app has its own card, because a phone is used differently from a browser.

  • The defaults are the same as in the web app, see Platform Defaults: one year, and no 2FA re-check.
  • One year is the longest sign-in duration. You can choose a shorter one.
  • The 2FA re-check interval applies to accounts with 2FA (authenticator app or passkey), as in the web app.
  • When the time is up, the app shows the sign-in screen and the user signs in again.
  • Alarm notifications keep arriving on the phone, also while the app is waiting for a new sign-in.

When You Change the Rules

You can change the rules at any time. Sign-ins that are already running follow the new rules. This includes your own.

ChangeWhat happens to running sign-ins
Stricter (shorter sign-in duration or shorter re-check interval)Sign-ins that are now too old end a short time after the change, between about 10 and 70 minutes. Open browser tabs show a warning first.
Looser (longer values)Sign-ins simply last longer. Nobody has to sign in again.

Before you save a stricter value, the tab shows how many sign-ins and how many people it will end, including your own. After the save it tells you when the first and the last of them end.

Tell your team before you tighten the rules

A stricter rule can sign out many colleagues within the same hour. Text in a form that was not saved is lost when a sign-in ends. Announce the change, or make it outside working hours.

What Members See

When a sign-in ends: in the browser, a countdown appears in the header during the last 24 hours. Shortly before the end Mirox warns the user. Then the sign-in page appears with a sentence that says why, and after signing in the user returns to the page they were on. The details are in What You See When a Sign-In Ends.

With a sign-in duration or a re-check interval of less than 24 hours, members see that countdown all the time.

When plants are hidden by a 2FA requirement: the user stays signed in and sees a hint in the header that leads to the 2FA setup. See Setting Up Two-Factor Authentication.

What the Policy Does Not Affect

The policy covers signing in to the Mirox web app and the mobile app. It does not touch the following:

  • API tokens — Tokens are made for automation. They are never asked for a second factor and they are not ended by the rules for sign-in duration. They keep working. One rule: a user without a second factor cannot create a new API token while their own organization requires 2FA.
  • VPN connections — The VPN is based on a certificate. It depends neither on a sign-in nor on 2FA. Keep the certificate safe.
  • Alarm notifications — They are always delivered on the channels a user set up: email, push, Telegram and webhook. This also holds for plants that are hidden from a user by the 2FA requirement.
  • The container registry — Mirox platform administrators sign in to the container registry on a separate access path with its own protection. It is unchanged.

Two things follow the signed-in user rather than standing apart:

  • The AI assistant in the app acts for the user who is signed in. It sees what that user may see, so not the plants hidden by a 2FA requirement, and it stops when the user's sign-in ends. External tools that connect with an API token follow the API-token rule above.
  • The device proxy always requires 2FA on the account and a live sign-in, whatever the organization's policy says. See Proxy.

Traceability

Every change to the policy appears in the organization's activity as Security policy updated, with who changed it, when, and the old and new values. See Activity & Audit Trail.

Related Features

  • Setting Your Organization's Security Policy — the steps on the Security tab
  • Authentication — sign-in, 2FA, how long a sign-in lasts and what you see when it ends
  • Setting Up Two-Factor Authentication — the guide to send to members who still have no second factor
  • Cooperation Restrictions — how your 2FA requirement applies to partner users
  • Permission System — the roles that decide who may reach a plant at all
  • Account Security FAQ — short answers on sign-outs, missing plants and lost authenticators
Prev
Account Temporarily Locked
Next
Permission System
© 2026 Mirox Verwaltungs GmbH. All rights reserved. | Privacy Policy