-
Manage dual authentication for staff and teachers
To combat malicious acts, and in accordance with the recommendations of ANSSI (the French National Cybersecurity Agency), it is recommended that you do not simplify the minimum password requirements and that you activate dual authentication (entering a PIN code when logging in from a new device) for all exposed accounts.
- Go to the menu Parameters >General options > Protecting accounts.
- The configuration may vary depending on the user type: select the corresponding user type on the left.
- If users log in directly to PRONOTE (and not via the digital workspace [ENT]), they must follow the PRONOTE password policies listed on the right. By default, three rules apply to all users, and it is strongly recommended that you adhere to these rules at a minimum:
- passwords must be at least 12 characters long,
- at least three complexity criteria are required,
- the password expiration policy is mandatory, with a default expiration period of 12 months.
- For students, guardians, and internship counselors, it is possible to authorize the reset of the PRONOTE password via e-mail. This is only possible if e-mail addresses have been entered in PRONOTE.
A link to reset your password will then appear on the user's login page. - Whether users log in directly to PRONOTE or via the digital workspace (ENT), entering a PIN code when logging in from a new device is required by default for users in the Administrative/Management, Teachers, and Staff categories, and it is strongly recommended that this setting be maintained at a minimum.
- It is possible to authorize the reset of the PIN code via e-mail. This is only possible if e-mail addresses have been entered in PRONOTE.
A link to reset the PIN code will then appear on the page where the user enters their PIN code. - For less sensitive accounts, you can ensure basic security and give users a choice. To do this, select Give a choice for a solution, then tick Enter a PIN code and Notification of connections (which, at a minimum, alerts you if a login from a new device is detected).
- For security reasons, there is also an automatic disconnection after a certain period of inactivity for users in the Administrative/Management, Teacher and Staff groups:
- for Administrative/Management users, the button takes you to the user administration.
The inactivity time before disconnection is set on a per-group basis. - For teachers and staff, the button takes you to the authorization profiles.
The inactivity timeout before disconnection is set per profile.
- for Administrative/Management users, the button takes you to the user administration.
For more information...
- How can security be strengthened in a malicious environment?
- What should be done if a PIN code is required every time a user logs in (and not just when logging in from a new device)?
- How can users be forced to change their PRONOTE password?
- How can users be forced to log out?
- What should be done if a user has forgotten their PRONOTE password or PIN code?
Was this content useful to you ?
Can't find an answer to your question ?
Contact our support