Skip to main content

XTM Academy

Configure security settings

Note

XTM is a secure environment. XTM Cloud uses an SSL certificate to ensure secure communication via HTTPS and we recommend the same for all XTM Suite installations as this not only improves security but ensures compatibility when connecting different instances of XTM for subcontracting.

  1. From the topmost menu in XTM Cloud click on Configuration.

  2. Just below and to the left click on Settings.

  3. From the menu that appears on the left-hand side, click on Security.

  4. From the remaining options, Implement your company's security policy. Consult the guide for each section indicated below:

  5. Click on the Save button when done.

Authentication settings
Allowing API authentication for new users

The function is enabled by default. If this function is switched on, Administrator can decide how users can log to XTM: via User Interface and API, via UI only, or API only.

  1. Go to Configuration > Settings > Security.

  2. Select the Allow API authentication for new users checkbox.

  3. Select Save.

The Authentication section in Edit user > Access rights will be displayed only for users with PM roles.

Enabling the 2-step verification on your XTM instance
  1. Go to Configuration > Settings > Security.

  2. Select the Use 2-step verification checkbox.

  3. Select Save.

  4. Log out from XTM.

All users are required to go through the 2-step verification process to log in to XTM.

Configuring allowed login attempts
  1. If the user makes the number of invalid login attempts specified, then their account will be blocked, and they will not be able to access the system.

  2. unblock the account, the Administrator needs to go to the Users tab and select Unblock account from the menu icon bars-solid.png in the left-hand column of the users listing.

  1. Go to Configuration > Settings > Security.

  2. In the Allowed log on attempts enter the number of times the user can try to log in.

  3. Select Save.

If the user makes the number of invalid login attempts specified, then their account will be blocked, and they will not be able to access the system. The account will then need to be unblocked by the Administrator.

Disabling account after non-use

If the user does not log into their account during the period of days specified, then the account will be blocked. The account will then need to be unblocked by the Administrator as described above.

  1. Go to Configuration > Settings > Security.

  2. In the Disable account after non-use (days) enter the number of days after which the user cannot access the system.

  3. Select Save.

If the user does not log into their account during the period of days specified, then the account will be blocked. The account will then need to be unblocked by the Administrator.

Computer activation level
Configuring computer activation level

This setting specifies who will need to go through the PC activation process on the first login. The process involves generating an automatic email.

  1. Go to Configuration > Settings > Security.

  2. In the Computer activation level select who needs to go through the activation process on the first login:

    • All users

    • All users except customer Project Managers

    • Only Project Managers

    • None

  3. Select Save.

Passwords settings

Feature

Description

Allow users to change their password

Allows users to change the password which the Administrator or PM assigned to them when creating user accounts.

Password duration (days)

Specifies the number of days that user passwords will be valid. After this period the user will have to change their password.

Check against previous passwords

Specifies the number of previous passwords that cannot be used as the current password.

Minimum password length (characters)

Specifies the number of characters required in the password.

Use brute force dictionary

Defines the words that cannot be used as or in a password. By default, the following words and components are excluded:

  • User’s first or last name

  • Administrator

  • Reviewer

  • User

  • Admin

  • Test

  • Super

  • qwe

  • 1111

  • 111

  • Password

  • Translator

  • XTM

  • Guest

  • Sys

  • Pass

Force password change on the first login

Check to enforce this measure.

Password strength

Password characters are split into 4 groups:
  • upper-case letters

  • lower-case letters

  • numbers

  • non-alphanumeric symbols

There are 3 levels of password strength

  • Simple Must use characters from at least 1 group

  • Medium Must use characters from at least 2 of the groups

  • Strong Must use characters from at least 3 of the groups

Privacy settings

Use this section to define who can update segment comments and hide the names or details of other users of the system.

The list describes the places where user information is displayed in XTM Workbench. These are:

  • Segment comments

  • Additional information about the TM match

  • Additional information about terms

  • Who is locking a segment

  • Segment filters

For each area there are three options:

  1. Everyone can see the user information

  2. Only Project Managers can see the information

  3. No one can see the information.

Configuring displaying user locking segment
  1. Go to Configuration > Settings > Security > Privacy.

  2. In the Allow segment comments to be updated by

    • All users

    • Creator only

    • Only in current step

  3. Select Save.

Configuring displaying user locking segment
  1. Go to Configuration > Settings > Security > Privacy.

  2. In the Display user details in comments for select who needs to go through the activation process on the first login:

    • All users

    • PMs only

    • No one

  3. Select Save.

Configuring displaying user details in comments
  1. Go to Configuration > Settings > Security > Privacy.

  2. In the Display user details in comments for select who needs to go through the activation process on the first login:

    • All users

    • PMs only

    • No one

  3. Select Save.

Configuring displaying user details in segment filters
  1. Go to Configuration > Settings > Security > Privacy.

  2. In the Display user details in segment filters for select who needs to go through the activation process on the first login:

    • All users

    • PMs only

    • No one

  3. Select Save.

Configuring information displayed about users in terms
  1. Go to Configuration > Settings > Security > Privacy.

  2. In the Display user details in terms for select who needs to go through the activation process on the first login:

    • All users

    • PMs only

    • No one

  3. Select Save.

Configuring information displayed about users in TM matches
  1. Go to Configuration > Settings > Security > Privacy.

  2. In the Display user details in TM matches for select who needs to go through the activation process on the first login:

    • All users

    • PMs only

    • No one

  3. Select Save.

Configuring information displayed about users

This option allows Administrators to decide what information should be visible to other users

  1. Go to Configuration > Settings > Security > Privacy.

  2. In the Information to display about users select who needs to go through the activation process on the first login:

    • Username

    • User ID

    • First and last name

    • Initials

  3. Select Save.