Skip to main content

Login security: password rules, verification codes and 2FA settings

Frontu login and account security

Frontu login is now more secure. This article explains what changed for password resets, passwords, email verification codes, two-factor authentication (2FA), passkeys and account changes.

Password reset and invitation links

  • A password reset link is valid for 1 hour.

  • An invitation link ("Send a link to create password") is valid for 7 days.

  • Each link works only once.

  • If you request a new link, only the newest one works. Older links stop working.

  • You can request up to 3 reset links per hour.

  • If the password is changed in another way (in the profile or by an Administrator), any pending link stops working.

If a link has expired, you see "This link has expired…". Request a new link from the login page.

Have in mind that for security reasons, the reset page shows the same message whether or not the email exists in Frontu.

Password rules

A new password must:

  • have at least 8 characters;

  • not be a known leaked password (for example, Password123).

Uppercase letters, lowercase letters and numbers are no longer required. A long, unique phrase is a good choice.

Email verification code

When 2FA is on, Frontu sends a 4-digit code to your email after you enter your password.

  • The code is valid for 10 minutes.

  • Each code works only once.

  • Up to 5 codes per hour can be sent. After that, use the last code you received.

Require 2FA separately for web and app

Administrators can now require 2FA for office users and app users separately.

  1. Go to Settings → Additional info → Security.

  2. Choose the options you need:

    • Require two-factor authentication on the web – office users must enter a code when they log in with a password.

    • Require two-factor authentication in the app – app users (technicians) must enter a code when they log in.

  3. Click Save.

The two options work independently. Turning on one does not turn on the other.

Have in mind that your previous "Enforce two-factor authentication" value was kept, so nothing changes until you edit these settings.

These settings do not apply to customer portal users or to logins with Google or Microsoft single sign-on (SSO).

Have in mind that the required setting does not change each user's own 2FA choice. If you turn it off, each user goes back to the 2FA setting on their own profile.

Single sign-on (SSO) counts as the second step

When you log in with Sign in with Google or Sign in with Microsoft, Frontu does not ask for an email code or passkey. Your Google or Microsoft login already provides the extra security.

If the same user logs in with email and password, Frontu 2FA still applies.

Passkeys

A passkey lets you confirm your login with your device, for example with your fingerprint, face or device PIN, instead of an email code.

You can add, rename and remove your passkeys on your profile.

If you logged in more than 10 minutes ago, Frontu asks for your password before you manage passkeys. You get an email when a passkey is removed.

When an Administrator removes a passkey

An Administrator can remove a user's passkey, for example when the user loses or replaces their device.

  • If the user was in the middle of logging in with that passkey, the login stops with the message "Your passkey was removed. Please sign in again".

  • The user starts a new login. Frontu no longer asks for the removed passkey.

TIP! After a passkey is removed, the user can add a new one on their profile.

Remember me

  • Remember me on the login page is now unticked by default.

  • Users who can only use the mobile app cannot log in on the web, even with Remember me ticked. They see a message to log in via the app.

  • If a user's role changes, their saved login no longer lets them in without the normal checks.

Confirm your password for important changes

If you logged in more than 10 minutes ago, Frontu asks for your password before you:

  • change your email;

  • turn off 2FA;

  • manage passkeys, devices or API tokens.

For email and 2FA changes, enter your password in the Current password field on your profile and click Save. For passkeys, devices and API tokens, a confirmation page opens.

Frontu emails you after each of these changes: email change, password change, 2FA turned off, passkey removed and new API token. When you change your email, both the old and the new address get a message. If you did not make the change, change your password and contact your Administrator.

Too many failed logins

After several wrong passwords, Frontu shows "Too many failed login attempts…" and blocks login for a short time. Wait and try again, or reset your password.

Did this answer your question?