1. Access Controls Overview
Password Policy and Two Factor Authentication settings can be found under Settings → Access Controls (under Identity & Access).
The Access Controls area contains three sections:
SAML Settings: configure Single Sign-On via your Identity Provider
Password Policies: define password strength requirements for all users
Two Factor Authentication: require users to verify their identity with an authenticator app
2. Configure Password Policy
Set password requirements that apply to all users in your organization.
Navigate to
Settings→Access Controls(under Identity & Access)Scroll to the
Password Policies & Two Factor AuthenticationsectionConfigure the requirements using the checkboxes and number fields
Click
Save Password Policyto apply
💡 Tip
Use the checkbox next to each requirement to enable or disable it. Only checked settings are enforced when a user sets or changes their password.
Setting | Description |
Expires after days | Number of days before a password expires and must be reset. Leave unchecked to disable expiry. |
Minimum length | Minimum number of characters required. |
Upper case characters | Minimum number of uppercase letters required. |
Lower case characters | Minimum number of lowercase letters required. |
Numbers | Minimum number of numeric characters required. |
Special characters | Minimum number of special characters required. |
3. Enable Two Factor Authentication
When 2FA is required, users must verify their identity with an authenticator app in addition to their password on every login.
Navigate to
Settings→Access Controls(under Identity & Access)Scroll to the
Two Factor AuthenticationsectionCheck the
Two Factor Authentication required for logincheckbox
⚠️ Important
Once enabled, all users will be prompted to set up 2FA on their next login. Communicate this change to your users in advance so they are prepared.
4. User 2FA Setup Flow
Users are prompted to set up 2FA in two scenarios:
After their first login with a temporary link
On their first login after 2FA is enabled for the organization
The user flow works as follows:
Install an authenticator app: revel8 supports Google Authenticator, Microsoft Authenticator, and FreeOTP
Login to the revel8 platform via the temporary or set password
Scan the QR code: open the authenticator app and scan the QR code shown on the setup screen. Alternatively, click Can't scan? Enter key manually to type the setup key directly
Enter the verification code: enter the 6-digit one-time code from the authenticator app into the One time code field
Name the device: enter a label in the Device name field (e.g.
My Phone)Optionally check Sign out from other devices to end all other active sessions
Click Verify & Activate to complete the setup
💡 Note
After completing the setup, users must enter a fresh 6-digit code from their authenticator app on every subsequent login.
✅ Final Checklist
Password Policy requirements configured and saved
Two Factor Authentication enabled for the organization
Users informed of the upcoming 2FA prompt
Test login completed to confirm the 2FA setup screen appears correctly



