Setting Your Organization's Security Policy
The security policy is your organization's own set of sign-in rules. On one tab you decide how long your members stay signed in, how often two-factor authentication (2FA) is asked again, and whether 2FA is required to see your plants. This guide walks you through each setting.
For what the rules mean and whom they apply to, see the Organization Security Policy feature page. This page is the how-to.
Before You Start
- The Security tab is open to Admins and Moderators only. If you do not see the tab, you do not hold the right organization role.
- Enable two-factor authentication on your own account first. A 2FA requirement applies to you as well, and you need 2FA yourself to switch the requirement off again or to postpone it.
- You do not have to set anything. Every value you leave on Platform default follows the Mirox defaults: a sign-in lasts one year, and accounts with 2FA are not asked to sign in again before that. Stricter rules apply to your members from the moment you save them.
Open the Security Tab
- Open your Organization page and select the Security tab (in the app: Profile menu ▸ your organization ▸ Security).
- You see three cards: Two-factor authentication, Web app and Mobile app. Each card is saved on its own.
Open in Mirox
Open the Security tab — the link resolves to your default organization.
Set How Long Members Stay Signed In
The sign-in duration is the time after which a member has to sign in again. On the cards the field is called Session lifetime. You set it separately for the browser and for the mobile app.
- In the Web app card, choose the Session lifetime from the list. The default is one year; a shorter value, for example 30 days, tightens the rule.
- In the Mobile app card, choose the Session lifetime for the app. One year is the longest possible value.
- Click Save Changes on each card you changed.
Keep the Mobile App Signed In for Long
Alarm notifications also arrive on a phone whose sign-in has ended and is waiting for a new sign-in. But a member who has to sign in first reacts later. A long sign-in duration for the mobile app keeps the way from the alarm to the plant short.
Set How Often 2FA Is Asked Again
The 2FA re-check interval only concerns members who have 2FA on their account (an authenticator app or a passkey). By default there is no re-check. Once you set an interval, a set time after they last proved their second factor, they are signed out and sign in again with password and code or passkey. See what the re-check does.
- In the Web app card, choose the 2FA re-check interval.
- In the Mobile app card, choose the 2FA re-check interval for the app.
- Click Save Changes on each card you changed.
A re-check interval that is longer than the sign-in duration has no effect, because the sign-in ends first. The tab tells you when that is the case.
Values Under 24 Hours
Members see a countdown in the header during the last 24 hours of a sign-in. With a sign-in duration or a re-check interval of less than 24 hours, they see that countdown all the time.
What Happens to People Who Are Signed In
A change applies to sign-ins that are already running, including your own. A stricter rule ends the sign-ins that are now too old between 10 and 70 minutes after you save, with a warning in open browser tabs. Before you save such a value, the tab shows how many sign-ins and how many people it will end, including your own; after the save it tells you when the first and the last of them end. A looser rule needs nothing from anyone. See When You Change the Rules.
Text that a member typed into a form and did not save is lost when the sign-in ends. For a stricter rule, pick a quiet time of day.
Require 2FA for Plant Access
With this rule, your organization's plants are only shown to users who have 2FA (an authenticator app or a passkey) on their account. Nobody is signed out by it.
- In the Two-factor authentication card, switch on Require 2FA for plant access.
- Read the dialog. It tells you how many of your members have no second factor yet.
- Choose when the rule starts. The suggestion is 7 days from now. The earliest possible start is 24 hours from now, so that people have time to set up 2FA.
- Confirm with Require 2FA.
Until the start date the card shows the rule as announced, with the date and the number of members who still have no second factor. From the start date it is in force.
Tell Your Members and Partners
Use the time before the start date. Tell your members and your cooperation partners the date and send them the guide Setting Up Two-Factor Authentication.
What Members and Partners See
From the start date, a user without a second factor:
- no longer sees your organization's plants: not in lists and dashboards, not on plant pages, not through the device proxy, in exports or in Grafana (Grafana follows within about an hour, both when the rule starts and after 2FA is enabled);
- stays signed in, and can still use the profile, the settings and the organization pages;
- sees a hint in the header that tells them to enable 2FA;
- gets the plants back as soon as 2FA is enabled on the account.
The rule belongs to the organization that owns the plant. It therefore also applies to the users of your cooperation partners on your plants, and your partners see in their cooperation list that your organization requires 2FA.
Not affected: alarm notifications are always delivered, also for hidden plants. API tokens that exist keep working, and VPN profiles keep working. One limit: a member without a second factor cannot create a new API token while your organization requires 2FA. The full list is in What the policy does not affect.
Check Who Still Has No Second Factor
- On the Security tab, the Two-factor authentication card shows how many members still have no second factor. The card shows the number as soon as the rule is announced.
- Remind your team and send the guide Setting Up Two-Factor Authentication. Each member enables 2FA on their own profile. You cannot do it for them.
- Check the number again before the start date. It goes down as members enable 2FA.
Change the Date or Switch the Requirement Off
- Start earlier: while the rule is announced, use Change date. The new start must again be at least 24 hours ahead.
- Start later, or switch it off: this makes the rule weaker, so Mirox asks for more. You need 2FA on your own account. Without it, the tab shows a link to your profile where you set 2FA up first.
When you switch the requirement off, the hidden plants are shown again to everyone who has a role on them.
Review Changes
Every change to the security policy is recorded in your organization's activity log. Open the Activity tab on the Organization page to review it.
Troubleshooting
| Situation | What to do |
|---|---|
| A member says plants are missing | The member has no 2FA and your organization, or the partner that owns the plants, requires it. The member enables 2FA on the profile and the plants are back. |
| A partner's users no longer see your plants | Your requirement applies to them as well. Send them the two-factor guide. |
| A member lost the authenticator app | The member signs in with a passkey, if one is set up, or with the backup code, which switches the authenticator app off, and then sets 2FA up again. Without a backup code or passkey, the member contacts Mirox support. See If You Lose Your Authenticator App. |
| Many members were signed out at once | A rule was made stricter. Running sign-ins that were too old ended. Signing in again is all that is needed. |
| You cannot switch the requirement off | Enable 2FA on your own account first. |
Related Guides
- Organization Security Policy — what each rule means, whom it applies to, and what it does not affect
- Setting Up Two-Factor Authentication — the guide to send to members and partners
- Managing Your Sessions — what a member sees when a sign-in ends
- Managing Member Permissions — organization roles and plant permissions of your members
- Creating Cooperations — how a 2FA requirement shows up between partner organizations
- Account Security FAQ — short answers for your members