Enforcing Security Policies Across Your Organization
Individual security habits vary — policies don't. Settings → Security Policies (admins only) applies your security rules to every member automatically.
The Policies
1. Require 2FA — every member must enroll at their next login; no opt-outs. The single highest-value switch on this page.
2. Password expiry — rotate passwords on your schedule, with a built-in grace period so nobody is locked out mid-task.
3. Session controls — automatically sign out idle sessions, so an unlocked laptop in a café isn't an open door.
Rolling Out Without Pain
• Announce first. "2FA becomes mandatory Monday — install an authenticator app" saves your help desk twenty confused messages.
• Enable 2FA first, expiry later — one change at a time.
• Admins are subject to the policies too, as it should be.