Who should read this: Workspace administrators and account owners responsible for
organizational security policy.Prerequisites: Admin or Account Owner role. An active PlaneConnection workspace.
Two-Factor Authentication (2FA)
Two-factor authentication adds a second verification step after password entry. PlaneConnection supports TOTP-based 2FA (authenticator apps like Google Authenticator, Authy, or 1Password) and SMS-based verification codes.Enable 2FA for your account
Individual users can enable 2FA from their profile settings. As an admin, you can enforce 2FA for all users.Enforce 2FA for all users
To require all workspace members to use two-factor authentication:When 2FA enforcement is enabled with a grace period, users can still sign in without 2FA during
the grace window but see a persistent banner reminding them to set it up. After the grace period
expires, users must complete 2FA setup before accessing any workspace features.
Passkeys
Passkeys provide passwordless authentication using biometrics (fingerprint, face recognition) or hardware security keys. They are phishing-resistant and more secure than passwords.Register a passkey
Users can register multiple passkeys for different devices. Each passkey is tied to a specific device and browser combination.Remove a passkey
Navigate to Profile & Security > Passkeys and click the Remove button next to the passkey you want to delete. You must have at least one other authentication method (password or another passkey) to remove a passkey.Session Policies
Session policies control how long users stay signed in and under what conditions sessions expire.Configure session duration
Force sign-out all users
In an emergency (compromised credentials, terminated employee), you can force-expire all active sessions:- Navigate to Settings > Security > Sessions.
- Click Revoke All Sessions.
- Confirm the action.
Password Requirements
PlaneConnection enforces baseline password requirements through its authentication infrastructure. As an admin, you can configure additional policies.Default password rules
All passwords must meet these minimum requirements:- At least 8 characters.
- Cannot be a commonly breached password (checked against known breach databases).
- Cannot be the same as the user’s email address.
Configure additional password policies
Navigate to Settings > Security > Password Policy to enable additional requirements:Authentication Methods Overview
PlaneConnection supports multiple authentication methods. The following table summarizes availability and configuration:Security Audit Log
All authentication events are recorded in the workspace audit log:- Sign-in attempts (successful and failed)
- 2FA enrollment and verification
- Passkey registration and removal
- Session creation and revocation
- SSO configuration changes
- Role and permission changes
Related
Configure SSO
Set up SAML-based single sign-on with your identity provider.
Manage Users and Roles
User provisioning, role assignment, and member management.
User Roles Reference
All 24 platform roles and their access scope.
Permissions Matrix
Detailed feature-by-role permissions breakdown.