Sessions, passwords and MFA
Best practices for access, recovery and second factor.
Last updated: Version: 1.0Any role
- Hashing
- Argon2id for passwords; refresh token rotation.
- MFA
- Optional TOTP second factor per user.
- Recovery
- One-time link, short expiration.
- Alerts
- Email on suspicious sign-ins.
Was this helpful?