Strengthen your organization's security by configuring the level of protection you want to enforce. From Security Configuration, you can set up Multi-Factor Authentication (MFA), password policies, session timeouts, and allowed email domains.
How to enable Multi-Factor Authentication for your organization.
How to configure password policies, including duration and minimum length.
How to set maximum session and inactivity timeouts.
How to restrict organization membership to allowed email domains.
Multi-Factor Authentication (MFA) adds an extra layer of protection to user logins. When enabled, all users in your organization must set up MFA the next time they log in.
To enable MFA for your organization, log in to your Contentstack account and perform the following steps:

Note: Once enabled, MFA setup becomes mandatory for all users on their next login.
Additional Resources: Refer to our document on setting up multi-factor authentication for more information.
Password policies help you control how passwords are created and maintained in your organization. You can choose to configure any combination of the available settings, depending on the level of security you want to enforce.
To enable and customize password policies for organization users, log in to your Contentstack account and perform the following steps:
Note: Set Password Duration to 0 for no password expiry.

Note:
If you belong to multiple organizations:
Session timeout in Contentstack's Security Configuration settings allows organization owners and admins to automatically log users out after a defined period of inactivity or a maximum session duration. This enhances account security by minimizing risks related to unattended active sessions.
Enabling session and idle timeouts helps ensure:
You can also whitelist email addresses to exempt specific users from timeout enforcement, which is ideal for service accounts or trusted users.
To configure session timeout, log in to your Contentstack account and perform the following steps:

The Allowed Email Domains feature lets you restrict user access to specific email domains within your organization. This enhances security by ensuring that only users with approved email domains can be added to your organization.
Note: Enabling this setting does not affect existing users.
To enable and add email domains, log in to your Contentstack account and perform the following steps:

Note: You can add up to 30 email domains.
Note: When this setting is enabled, users with unapproved email domains cannot be invited or added to your organization. An error message appears if you attempt to add them.
By implementing these security features, you can significantly enhance your organization’s security.