Skip to content
  • There are no suggestions because the search field is empty.

Managing Security Settings to prevent Lock-outs

EnrollNow security settings are designed to align with HIPAA-compliance standards by default. Site Admins can adjust these settings to better meet their organization’s security requirements and internal policies.

Accessing Security Settings

To view or update your site’s password and account security settings:

  1. Click the Site Admin tab.
  2. Select the Security tab on the left.

Session & Inactivity Settings

Within the Passwords section, Site Admins can configure password requirements for users on their site.

  • Lock accounts after N failed login attempts: Automatically lock user accounts after a defined number of attempts.
  • Prevent Concurrent sessions on the same account: Restrict users from being logged in to the same account from multiple sessions at the same time.
  • Automatically logout after N minutes of inactivity: Set the number of minutes of inactivity before users are automatically logged out.

Password Settings

  • Password expire after: Set how often users are required to change their passwords.
  • Prevent reuse of last N passwords: Determine whether users are allowed to reuse a certain number of previous passwords.
  • Minimum password length:  Minimum number of characters required for a password.
  • Minimum password strength level: Choose Weak, Moderate or Strong. 
  • Require at least one digit: toggle on or off
  • Require at least one symbol: toggle on or off
  • Require mixed case: toggle on or off 

These settings can help support your organization’s access control and security policies.

Important Note About Password Reset Links

Password reset links expire 24 hours after a new password reset email is sent.

Each time a Site Admin sends a password reset email, EnrollNow generates a new reset link. Any previously sent password reset links become invalid and can no longer be used.

If a user reports that their reset link is no longer working, confirm whether a newer password reset email was sent and ask the user to use the most recent link.

For EnrollNow Customers Using SSO

For customers with Single Sign-On (SSO) configured, most password security settings are managed by your institution’s identity provider or IT team.

Within EnrollNow, Site Admins can still manage select account security settings, including:

  • Prevent concurrent sessions on the same account: Restrict users from being logged in to the same account from multiple sessions at the same time.
  • Automatically log out after N minutes of inactivity: Set the number of minutes of inactivity before users are automatically logged out.
  • Lock accounts after inactivity: Set a timeframe for inactive accounts to be locked. This timeframe can be configured in days, weeks, months, or years.