> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.vkard.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How to enhance the security of Dashboard logins ?

Protecting your data starts with a strong password and reinforced security measures. Here's how to configure an effective password policy and activate two-factor authentication (2FA) to better secure your organization’s accounts.

---

## ✅ Step 1: Access Security Settings

1. Log in to your [Dashboard](https://dashboard.vkard.io) (as an administrator)
2. In the left-hand menu, click on **Organization Settings**, then go to the **Security** tab.

![](https://storage.crisp.chat/users/helpdesk/website/-/8/9/f/0/89f0496dcd22d000/parametre-orga_h90965.png =300x416)

---

## 🔧 Step 2: Set a Minimum Password Length

To strengthen password protection:

1. In the **Minimum password length** field, set a value (for example, **8 characters**).
2. Click **Save** to apply the changes.

![](https://storage.crisp.chat/users/helpdesk/website/-/8/9/f/0/89f0496dcd22d000/image_1uqz5z8.png =800x424)

---

## ✉️ Step 3: Enable Two-Factor Authentication (2FA)

**Two-factor authentication** (2FA) is a highly effective way to enhance account security.  
It adds a second verification step when logging in, making unauthorized access much harder — even if a password is compromised.

When a user logs in from a **new device**:

* A **one-time security code** is automatically sent to their email address.
* The user must enter this code to complete the login.

![](https://storage.crisp.chat/users/helpdesk/website/-/8/9/f/0/89f0496dcd22d000/double-auth_1ujx3q.png =600x347)

||| 🔁 Even if a device was previously authorized, the system will prompt for a new code every 60 days to ensure ongoing security.

---

### Good to Know

* 2FA is **mandatory** for all members once enabled at the organization level.
* Users **cannot disable 2FA themselves**, greatly reducing the risk of unauthorized access.
* It’s a **recommended measure** for all teams handling sensitive data or requiring enhanced security.
