Password and 2FA policy in Connect

Password and 2FA policy in Connect

Connect manages the default authentication policy (password and 2FA) for employees within verified domains. This policy does not apply to users outside those domains (for example @gmail.com/@outlook.com addresses or external parties). They sign in with their email address and password according to this policy.

Do we support two-step verification?

Two-step verification (2FA) runs entirely through Visma Connect and is tied to the user’s Connect profile, which means it applies to every Visma application they sign in to, not just Spend Cloud. Spend Cloud itself contains no 2FA settings. Whether 2FA is available depends on how you sign in:
  • Signing in with a username and password in Spend Cloud (without Connect): two-step verification is not available. If you want to use 2FA, you need to move to Connect.
  • Signing in through Connect with an email address and password: two-step verification is available. As an administrator you make it mandatory at authenticationsettings.connect.visma.com with the option “Require 2-Step Verification during sign-in”. Every user within a verified domain is then taken through the setup wizard the next time they sign in, even if they never registered for it themselves. If 2FA is not mandatory, users can enable it themselves in their Account Settings in Connect.
  • Signing in through Connect with Single Sign-On (SSO): Connect cannot enforce 2FA here. In that case you arrange two-step verification in your own identity provider (for example Microsoft Entra ID). Connect only sees whether two-step verification was used during sign-in.
Separately from this, Connect may ask for additional verification for certain sensitive actions, even when 2FA is not mandatory.

Default password settings

  • Minimum length: 15 characters.
  • Complexity: no mandatory combination of upper case, lower case, digits or special characters. A passphrase is allowed too, as long as it is at least 15 characters long.
  • Password history: you cannot reuse your 5 most recent passwords.
  • Account lockout: Connect locks the account for 30 minutes after 8 failed sign-in attempts (the failed attempt counter resets after 10 minutes).
  • Expiry: passwords do not expire automatically.
  • Additional check: Connect automatically checks every new or changed password against the “Have I Been Pwned” database and rejects passwords that appear in known data breaches, even if they meet all of the requirements above.

Default 2FA settings

  • Two-factor authentication (2FA) can be made mandatory for all users that fall under your domain. For users outside your domain 2FA is optional. Users need an authenticator app for this (for example Microsoft or Google Authenticator) and enter a 6-digit code when signing in.
  • “Remember this device”: by default the option to skip 2FA for 30 days on a trusted device is enabled.

Changing the settings

Do you want to change this policy for your organisation? Go to authenticationsettings.connect.visma.com and open the Policy tab. This applies to all users with an email address within a verified domain. For the official Connect documentation you can consult this page: https://docs.connect.visma.com/docs/password-policy

Please note: these are organisation-wide settings. Discuss changes with your IT department and/or Visma Connect administrator.
    • Related Articles

    • Log in and set password with Connect

      Alert Please note: Connect is currently being rolled out in phases and is currently only available to a pilot group. As soon as Visma Connect becomes applicable to your Spend Cloud environment, you will receive an email with further information. ...
    • Login and resetting your password

      Depending on your organization, you can log in to Spend Cloud by entering your login credentials or through Single Sign-On. Single Sign-On means that if you are already logged into your organization's environment, you can navigate directly to Spend ...
    • Log in with Connect

      What is Connect? Connect is Visma’s central Identity Provider for managing employee logins. It acts as a secure digital gateway. With Connect, you use one set of login credentials (your email address and password, or Single Sign-On via another ...
    • What do I have to take in account when the end of the year is in sight?

      As the end of the year approaches, there are several important matters we want to bring to your attention before the year-end transition. Please review the following tips and the Year-End Tips Theme Webinar. End of the Year Tips Automatic Email ...
    • Why choose Single-Sign on?

      What is SSO? With Single Sign-On, abbreviated as SSO, users log in to the Spend Cloud in a very simple and secure way, without needing a username and password. The SSO connections between different applications ensure that authentication happens ...