This guide covers logging into the system, setting up two-factor authentication (MFA) and configuring security settings. Data security is a core requirement of ISO 17025 (§8.4).
If your password has expired, you will be prompted to change it before continuing.
MFA (Multi-Factor Authentication) adds a second layer of security. It uses an authenticator app (Google Authenticator, Authy, Microsoft Authenticator).
For accredited laboratories, enabling MFA for all users is recommended.
Go to Settings → Security (Lab Directors only).
| Setting | Description |
|---|---|
| Minimum password length | Minimum number of characters |
| Password expiry (days) | Days until password expires (0 = no expiry) |
| Session timeout (minutes) | Auto-logout after inactivity (0 = disabled) |
| Max failed login attempts | Failed logins before account lockout |
| Lockout duration (minutes) | How long the account stays locked |
| Setting | Description |
|---|---|
| Mandatory MFA | All users must enable an authenticator app |
| MFA reminder | Shows a reminder at login if MFA is not enabled |
| E-signature on approval | Requires password re-entry when approving an analysis |
| Setting | Description |
|---|---|
| Audit log retention (days) | How long audit records are kept (0 = forever) |
What if I lose access to my authenticator app?
A Lab Director can reset a user's MFA from the Users page. After reset, the user must set up MFA again.
How do I unlock a locked account?
The account unlocks automatically after the lockout duration. A Lab Director can also unlock it manually.
Why am I asked for my password when approving an analysis?
If "E-signature on approval" is enabled, password re-entry is required as an electronic signature — an ISO 17025 requirement.