Password and 2FA policy in Connect

Password and 2FA policy in Connect

Connect determines how employees sign in: which password rules apply and whether a second step is required. For users with an email address within a verified domain of your organization, you can adjust that policy yourself in the Connect Authentication Settings.

Users with an email address outside a verified domain (for example @gmail.com or @outlook.com, or the address of an external party) fall under Visma's default policy. As an administrator, you cannot change that policy. They sign in with email address and password and cannot sign in via your own SSO.

Default password settings

  • Minimum length: 15 characters.
  • Complexity: no mandatory combination of uppercase letters, lowercase letters, numbers or special characters. A passphrase is also allowed, as long as it has at least 15 characters.
  • Password history: you cannot reuse your 5 most recent passwords.
  • Account lockout: after 8 failed sign-in attempts, Connect locks the account for 30 minutes. The failed attempts counter resets after 10 minutes.
  • Expiry: passwords do not expire automatically.
  • Known data breaches: Connect checks every new or changed password against the “Have I Been Pwned” dataset and rejects passwords that appear in known data breaches, even if they meet all the requirements above.
Info
Note the date: the 15-character requirement applies to passwords created or changed from 1 July 2026. Older passwords keep working according to the policy that applied when they were set, until the user changes the password.

Idea
What do employees notice during the migration to Connect? They keep their own password. If it does not meet this policy, Connect asks for a new password the next time they sign in. As an administrator, you don't need to arrange anything for this.

Official Connect documentation: docs.connect.visma.com/docs/password-policy.

Two-step verification (2FA)

Two-step verification (also known as multi-factor authentication or MFA) runs entirely through Connect and is linked to the user's Connect profile. It therefore applies to all Visma applications the user signs in to, not just Elari. There are no 2FA settings in Elari itself.

What is possible depends on the way of signing in:
  • Signing in to Elari without Connect (the old sign-in page): no two-step verification available. If you want to use 2FA, switching to Connect is required.
  • Signing in via Connect with email address and password: 2FA is available. As an administrator, you make it mandatory via authenticationsettings.connect.visma.com with the option “Require 2-Step Verification during sign-in”. Every user within a verified domain then gets the setup wizard the next time they sign in, even if they had not signed up for it before. Is 2FA not mandatory? Then users can enable it themselves in their Account Settings in Connect.
  • Signing in via Connect with Single Sign-On (SSO): Connect cannot enforce 2FA here. Whether a second step is required is determined by your own identity provider (for example Microsoft Entra ID or Okta). With supported providers, Connect can see afterwards whether two-step verification was used, but Connect cannot enforce or guarantee it. So if you make 2FA mandatory in Connect, it only applies to users who sign in with email address and password.
Separately, Connect may ask for additional verification for certain sensitive actions, even when 2FA is not mandatory.

Which second step can users use?

  • Visma Authenticator app: the user approves a notification on their phone. This is the method Visma recommends.
  • Another authenticator app: for example Microsoft or Google Authenticator, with a 6-digit code that changes every 30 seconds.
  • Passkey or security key: for example Windows Hello, Touch ID or a USB key such as a YubiKey.
  • Code via text message (SMS): possible, but less secure than an authenticator app.
  • One-time emergency code: a backup code for when the user no longer has access to their second step. Store it securely, for example in a password manager.
More information for users: docs.connect.visma.com/docs/understanding-2fa-in-visma.

Other 2FA settings

  • Do you switch off the requirement later? Then 2FA remains active for users who had already set it up. They can switch it off themselves in their Account Settings.
  • “Remember this device”: by default, a user may skip 2FA for 30 days on a trusted device.

Adjusting settings

Want to adjust this policy for your organization? Go to authenticationsettings.connect.visma.com and open the Policies tab. Besides password and 2FA, you can also set there, for example, which sign-in methods are allowed, from which IP addresses or countries users may sign in and how many active sessions are allowed. See Authentication Settings in Connect: setting policies and managing users.

Warning
Please note: these are organization-wide settings that apply to all Visma applications of your organization, not just Elari. Discuss changes with your IT department and/or Visma Connect administrator.