Welcome to Zuora Product Documentation

Explore our rich library of product information

Manage Authentication

Learn how to configure sign-in methods, password policies, and multifactor authentication (MFA) for experience builder users.

In User Accounts, you can configure how users sign in to your portal. You can activate email-based one-time passwords, password-based sign-in, or both. You can also configure security settings such as password policies, multifactor authentication (MFA), session timeout, account lock, and lockout after repeated failed sign-in attempts.

  1. Navigate to Customers > User Accounts > Settings.
  2. Expand the Authentication section and select how users sign in to your portal.
    • To use password-based sign-in with optional MFA, select Password.
    • To use email-based sign-in codes only, without passwords, select Passwordless.
    • To let users choose between password and passwordless sign-in, select Both.
  3. Expand the Password Policies section to set password complexity requirements and expiry rules.
    1. In the Minimum password length field, enter the minimum number of characters.
    2. Select the character requirements that you want to enforce.
      • Require uppercase letters (A-Z)
      • Require lowercase letters (a-z)
      • Require numbers (0-9)
      • Require special characters (!, @, #, $, %, ^, &, *)
    3. In the Password expiry field, enter the number of days before passwords expire, or leave the field blank for no expiry.
  4. Expand the Multi-Factor Authentication section to configure MFA requirements and available methods.
    1. To require users to set up MFA before they can access their account, activate Require MFA for all users.
    2. Select the MFA methods that you want to make available to users.
      • Authenticator App: Time-based one-time passwords from apps such as Google Authenticator or Authy.
      • SMS: One-time codes sent by text message.
      • Email: One-time codes sent by email.