Security Settings
Information on the security settings section
"Umbraco": {
"CMS": {
"Security": {
"KeepUserLoggedIn": false,
"HideDisabledUsersInBackOffice": false,
"AllowPasswordReset": true,
"AuthCookieName": "UMB_UCONTEXT",
"AuthCookieDomain": "",
"UsernameIsEmail": true,
"MemberRequireUniqueEmail": true,
"AllowedUserNameCharacters": "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-._@+\\",
"BackOfficeHost": "http://your-domain.com",
"UserPassword": {
"RequiredLength": 10,
"RequireNonLetterOrDigit": false,
"RequireDigit": false,
"RequireLowercase": false,
"RequireUppercase": false,
"HashAlgorithmType": "PBKDF2.ASPNETCORE.V3",
"MaxFailedAccessAttemptsBeforeLockout": 5
},
"MemberPassword": {
"RequiredLength": 10,
"RequireNonLetterOrDigit": false,
"RequireDigit": false,
"RequireLowercase": false,
"RequireUppercase": false,
"HashAlgorithmType": "PBKDF2.ASPNETCORE.V3",
"MaxFailedAccessAttemptsBeforeLockout": 5
},
"UserDefaultLockoutTimeInMinutes": 43200,
"MemberDefaultLockoutTimeInMinutes": 43200,
"AllowConcurrentLogins": false,
"UserDefaultFailedLoginDurationInMilliseconds": 1000,
"UserMinimumFailedLoginDurationInMilliseconds": 250,
"PasswordResetEmailExpiry": "01:00:00",
"UserInviteEmailExpiry": "3.00:00:00",
"BackOfficeTokenCookie": {
"SameSite": "Strict"
}
}
}
}Root level settings
Keep user logged in
Hide disabled users in backoffice
Allow password reset
Auth cookie name
Auth cookie domain
Username is email
Member require unique email
Allowed user name characters
BackOffice Host
User default lockout time
Member default lockout time
Allow concurrent logins
User login duration
Password reset email expiry
User invite email expiry
User password settings
Required length
Require non letter or digit
Require digit
Require lowercase
Require uppercase
Max failed access attempts before lockout
Hash algorithm type
Member password settings
Backoffice token cookie settings
Same site
Last updated
Was this helpful?