Emburse Professional administrators can manage organization-level security settings for user authentication. You can configure failed login notifications, require multi-factor authentication (MFA), and reset the Receipt External Access Code. You can also review the minimum password requirements that apply to all Emburse Professional users.
Open Security Settings
-
On the Emburse Professional home page, select Settings.
-
Under User Accounts and Billing, select Security Settings.
Security Settings
On the Security Settings page, you can review or configure the following settings:
-
Minimum Password Rating: All Emburse passwords must meet a minimum level of complexity. You cannot configure these requirements. New passwords must:
- Contain at least eight characters.
- Contain at least one lowercase letter.
- Contain at least one uppercase letter.
- Contain at least one number.
- Contain at least one special character: !@#$%^&*()_+=,.<>?;:/
- Failed Login Notifications: Enter the email addresses of users who should receive a notification when a failed login attempt occurs.
-
Require Multi-Factor Authentication for all Users: Select this option to require MFA for all users. If you do not require MFA at the organization level, users can manage MFA from their account MFA settings.
- MFA replaces security questions as an identity verification method in Emburse Professional. Emburse Professional can require MFA when a user logs in from an unrecognized device, IP address, or web browser. When MFA is required, Emburse Professional sends the user a one-time security code by email or text message. The user enters the code in Emburse Professional to verify their identity. For more information, see Multi-Factor Authentication.
- Receipt External Access Code: Receipt External Access Codes automatically expire one year after creation. You can manually reset your organization’s access code when necessary. Resetting the code invalidates all previous access codes. For more information, see Locate the Receipt External Access Code.