Atlassian uses cookies to improve your browsing experience, perform analytics and research, and conduct advertising. Accept all cookies to indicate that you agree to our use of cookies on your device. Atlassian cookies and tracking notice, (opens new window)
/
Authentication Preferences
Authentication Preferences
May 22, 2025
What is Authentication Preferences?
Authentication Preferences is a page where you can set up authentication options for challenge questions, e-PIN and/or two-factor authentication. Additionally, the page lets you specify the number of days within which the User or New Hire must complete their self-registration before the link expires.
Who can access Authentication Preferences?
Users with the System Administrator role can access Authentication Preferences.
How do you access the Authentication Preferences page?
Click the menu icon on the left and select the "Authentication Preferences" link on the navigation menu.
Menu
What do the fields on the Authentication Preferences page mean?
The following fields in Authentication Preferences can be changed based on the requirement.
Authentication Preferences Page
Click here to understand what each field means
Field
Action
If checked on, users and new hires are asked to answer their challenge questions each time they login into the system. For more details on verifying the challenge questions, please click here.
If checked off, challenge questions are presented only during the initial login. In subsequent logins, the challenge questions will not be presented.
By default, the system is delivered with "SMS & Email" option selected in the Delivery Method drop down. The System Administrator can alter this authentication setup based on how they want the user login verification to be done in their organization. For more details, please click here.
The Two-Factor Delivery Method is a key factor in determining whether Email and Telephone options are displayed during the initial verification process at self-registration and in subsequent logins. Users are prompted to verify using the delivery methods configured in this setup when they self-register, and they can select one of these options as the delivery method for receiving the verification code each time they log in.
If no option is selected in the Two-Factor Delivery Method, an error message will appear on the page when attempting to save the authentication preferences:
Note:
The phone number provided on the user's or new hire's invitation will be used for authentication verification during self registration or subsequent system logins only if it is a USA number (associated with the country code "001") that supports text messaging (which means a Cell number). If the telephone number doesn't belong to USA (i.e., the country code is not "001"), only the email option will be displayed for authentication verification, regardless of the configured delivery method.
If "SMS" is set as the only delivery method in the Authentication Preferences, the System Administrator or HR Specialist must provide a cell number that supports text messaging when creating user or new hire invitations.
Enable User Account Lock
If checked on, options are displayed to lock accounts on terminated or completed invitations.
By specifying the number of days in both or either of the fields, the System Administrator can set a lock on the user accounts associated with it after the mentioned days. Locking the account prevents users from accessing the system.
If checked off, no locking will be enforced on the user accounts.
Allow same user account for multiple invitations
If checked on, the feature to link the User ID to multiple primary invitations is enabled. As default, this value is checked on. To view the details of adding multiple invitations to a same user account for New Hires and Admin Users, please click on the respective links.
If checked off, the feature to link the User ID to multiple primary invitations is disabled.
*Note: If required, adjust impacted email templates to align with the status of this property. Refer to How to configure the linking code for a sample.
Self Registration link expires after
If specified, the self registration link in the email invitation will expire after the days entered. The users and new hires have to use the link before it expires.
If no value is entered, the self registration link will not expire.