--- title: "Security Settings" slug: "sicherheitseinstellungen" updated: 2025-12-23T08:14:15Z published: 2025-12-23T08:14:15Z canonical: "help.frisbii.com/sicherheitseinstellungen" --- > ## Documentation Index > Fetch the complete documentation index at: https://help.frisbii.com/llms.txt > Use this file to discover all available pages before exploring further. # Security Settings ## Preliminary Remarks The **security settings** in the user administration are used for the security of the Merchant Backend accounts and are set for **all users** of the Merchant Backend. The following security settings can be made: - Two-factor authentication - Automatic deactivation of inactive users - Reset password - Password rules --- ## Security Settings ### Two-factor authentication If the checkmark is set, every Merchant Backend user is forced to set up two-factor authentication. ### Automatically disable inactive users If the check mark is set, inactive users of the Merchant Backend are automatically disabled after the defined period has expired. - **after x days** determines after how many days inactive users should be disabled. A value between 1 and 365 can be entered here. - **Session timeout of users** defines the time in hours after which an inactive user is automatically logged out of the Merchant Backend. If no entry is made here, a time of 12 hours is automatically set. > [!TIP] > **Note**: Only accounts with the "User" role are automatically disabled. User accounts with the "Administrator" role are not automatically disabled. ### Reset password - **Email recipient***: The e-mail addresses of those responsible can be entered here if a Merchant Backend user wishes to reset their password. - **Reset password***: The drop-down menu can be used to determine whether the password can be reset by **users** or only by the **administrator** . If only the **administrator** can reset the password, the administrator receives an e-mail that a user wants to reset the password. The administrator logs into the Merchant Backend and can reset the password for the user at [User Administration> Users](/frisbii-media/docs/benutzer-anlegen). If the **users** can reset their password themselves, they will receive an e-mail containing the token for resetting the password. > [!TIP] > **Note**: Users can only receive an e-mail if an e-mail address has been stored in their user account. If the user has not entered an e-mail address, the administrator receives an e-mail informing them that a user wishes to reset their password. ### Password rules - **Minimum length of password** (mandatory field): Setting for the minimum length of the password. - Checkboxes: determine which components the password must contain. - **Capital letters** - **Lower case** - **Digits** - **Special characters** ![](https://cdn.document360.io/b84e1b5d-2ba6-4465-8c62-fb45a2f31314/Images/Documentation/image-P7LZ19NK.png)