Sign-in protection and password rules | Doghouse SaaS Knowledge Base     [Skip to content](#main)  [ ![Doghouse SaaS Knowledge Base](/storage/branding/01M3N8PQ7PSDNQBBKKJM6XGW03.svg) ](https://nginx.deploy-lagoon-production.districtcms-docs.dh1.amazee.io)  [Product documentation](/articles) [Roadmap](/roadmap)   Toggle navigation      

  [Product documentation](/articles) [Roadmap](/roadmap)  

  1. [Home](/) ›
2. [Product documentation](/articles) ›
3. [Users, permissions &amp; security](/articles?category=13) ›
4. Sign-in protection and password rules

 Sign-in protection and password rules
=====================================

Updated 5 days ago · 2 min read

 Search     Search  

Overview
--------

Your site already slows down anyone trying to guess a password. Two more tools are installed for when you want stricter rules.

Protection

On this site

Built-in limit on failed sign-ins

On. After 5 failed attempts on one account in 6 hours, or 50 from one address in an hour, sign-in is blocked for a while.

Login Security

Installed, but every limit is set to 0, so it adds nothing yet.

Password Policy

Installed, with no policies set up, so any password is accepted.

> **⚠️ Important:** All of this is administrator work. If a colleague is locked out, an administrator can unblock the account under **People**.

---

Login Security
--------------

Login Security adds limits you choose, and can email someone when an attack looks likely.

1. Go to **Configuration**, then **People**, then **Login Security**.
2. Under **General settings**, set **Track time**, then how many failed attempts to allow per **User**, **Soft host** and **Host**. A value of 0 means no limit.
3. Under **Notification**, add an address to email when an account is blocked or an attack is detected.
4. Press **Save configuration**.

![The Login Security settings screen with General settings outlined in red, showing Track time at 60 minutes and User, Soft host and Host all at 0 failed attempts.](/storage/PZyyk1EjnkpfTtTKcLiFR5fciA3qX8EEg6uiSDaF.png)

---

Password rules
--------------

Password Policy sets rules a password must meet, such as a minimum length, and can make people change it after a set time. It is empty today.

1. Go to **Configuration**, then **Security**, then **Password Policies**.
2. Press **Add Policy**, choose the rules, and choose which roles it applies to.

![The Password Policies screen, outlined in red, saying there are no password policies yet.](/storage/QK6cAtnYbzqJWgIiBRg3lhQD0bogZd7D6mEpqbDc.png)

> **💡 Note:** The **Password Expiration** switch on each account comes from the same tool. See [**Create a user account**](/articles/create-a-user-account).

  Related articles 
------------------

- [ Roles and what they let you do → ](/articles/roles-and-what-they-let-you-do)
- [ Creating a role and setting what it can do → ](/articles/creating-a-role)
- [ Create a user account → ](/articles/create-a-user-account)
- [ Activity log → ](/articles/activity-log)

 Was this article helpful?
-------------------------

Your feedback helps us prioritise what to rewrite.

      Yes     No  

 [    Back to Users, permissions &amp; security ](/articles?category=13) 

 On this page 

**Need additional help?** 
Submit a support request through the [**support portal** ](https://doghouse.atlassian.net/servicedesk/customer/portals)or email 

 © 2026 [Doghouse SaaS](https://doghouse.agency) [Glossary](/articles/glossary)
