Connect manages the default authentication policy (password and 2FA) for employees within verified domains. This policy does not apply to users outside those domains (for example @gmail.com/@outlook.com addresses or external parties). They sign in with their email address and password according to this policy.
Do we support two-step verification?
Two-step verification (2FA) runs entirely through Visma Connect and is tied to the user’s Connect profile, which means it applies to every Visma application they sign in to, not just Spend Cloud. Spend Cloud itself contains no 2FA settings. Whether 2FA is available depends on how you sign in:
- Signing in with a username and password in Spend Cloud (without Connect): two-step verification is not available. If you want to use 2FA, you need to move to Connect.
- Signing in through Connect with an email address and password: two-step verification is available. As an administrator you make it mandatory at authenticationsettings.connect.visma.com with the option “Require 2-Step Verification during sign-in”. Every user within a verified domain is then taken through the setup wizard the next time they sign in, even if they never registered for it themselves. If 2FA is not mandatory, users can enable it themselves in their Account Settings in Connect.
- Signing in through Connect with Single Sign-On (SSO): Connect cannot enforce 2FA here. In that case you arrange two-step verification in your own identity provider (for example Microsoft Entra ID). Connect only sees whether two-step verification was used during sign-in.
Separately from this, Connect may ask for additional verification for certain sensitive actions, even when 2FA is not mandatory.
Default password settings
- Minimum length: 15 characters.
- Complexity: no mandatory combination of upper case, lower case, digits or special characters. A passphrase is allowed too, as long as it is at least 15 characters long.
- Password history: you cannot reuse your 5 most recent passwords.
- Account lockout: Connect locks the account for 30 minutes after 8 failed sign-in attempts (the failed attempt counter resets after 10 minutes).
- Expiry: passwords do not expire automatically.
- Additional check: Connect automatically checks every new or changed password against the “Have I Been Pwned” database and rejects passwords that appear in known data breaches, even if they meet all of the requirements above.
Default 2FA settings
- Two-factor authentication (2FA) can be made mandatory for all users that fall under your domain. For users outside your domain 2FA is optional. Users need an authenticator app for this (for example Microsoft or Google Authenticator) and enter a 6-digit code when signing in.
- “Remember this device”: by default the option to skip 2FA for 30 days on a trusted device is enabled.
Changing the settings
Please note: these are organisation-wide settings. Discuss changes with your IT department and/or Visma Connect administrator.