Login policy
Choose approved login methods, including formatted MFA and passwordless options.
Request a demo →
Configure how users authenticate, where they can connect, how sessions behave, how identity records synchronize and how Rainbow Secure responds to suspicious activity.
Security access policies provide consistent rules for authentication, network and country access, credential standards, session handling, identity synchronization and automated response.
Administrators can tune policies to the organization’s environment rather than applying one rigid setting to every use case.
Choose approved login methods, including formatted MFA and passwordless options.
Apply blacklist, whitelist, IP-range and allowed-country controls.
Set length, rotation and formatting requirements.
Set OTP length, validity period and formatting enforcement.
Control failed-attempt thresholds and lockout duration.
Standardize how usernames are generated across the organization.
Limit idle session time before access ends.
Configure alerts, blocking actions and AI-assisted detection.
Define trusted and restricted network ranges, apply effective dates, and restrict access to approved countries.
Use independent upstream and downstream schedules based on how quickly each environment needs updates.
Upstream and downstream frequencies are configurable independently.
REAL THREAT RESPONSE POLICY
Alert security contacts, block bot attempts, respond to unusual locations and choose actions for risky IP, country or schedule conditions.
Map authentication, location, session, synchronization and response requirements into practical controls.