It is possible to set and enforce specific security policies at the Enterprise level in zkipster.
Changes to Multi-Factor Authentication (MFA) from October 1, 2026
A note on MFA: Since October 1, 2026, every zkipster User is required to verify their identity with a code sent to their email by default when logging in from their browser. This applies automatically on every plan, with nothing to set up.
The Custom Security Policies described in this article are an additional layer of security available only on Enterprise: centrally managing and enforcing your organization's MFA settings, such as requiring SMS as an extra factor or resetting a User's MFA. See Managed Multi-Factor Authentication for a full overview of these global changes.
What are the advantages of setting Custom Security Policies?
There are many advantages to controlling your own custom policies:
1. Improve Security: Align user access management with the requirements of your organisation and retain full control over changes.
2. Achieves Compliance: Allows your organization to achieve the necessary compliance requirements to mitigate audit findings and avoid potential fines.
3. Stronger passwords: Your internal IT team can set the password policy that is satisfactory to your organization.
4. No repeated passwords: Your organization can restrict password fatigue and limit the amount of time passwords are reused.
5. Company managed Multi-factor authentication: Multi-factor authentication, or MFA, refers to the use of more than one identity factor to authenticate a
User. For example, in addition to entering a username and password, a User needs to enter a code sent to the email address on their profile or, if they have added a phone number, an SMS code. MFA is much more secure than relying on a password alone.
How to set up Custom Security Policies in zkipster?
In the Account Settings, in the Security tab, you can set up password policies, password attempt limits, and managed multi-factor authentication (MFA).
Password Policies
Password restrictions in zkipster can be specified as follows:
Minimum Length - None, 4 to 12 characters
Password Complexity - None, Low - alpha only, Medium - alpha & numerics, High - alpha, numeric and special characters
Password Expiration - Never, 1 to 12 months
Password Retention - Disabled, 1 to 12 passwords
You can also set up a block on multiple failed login attempts to minimize the risk of malicious hacking of passwords.
Failed Login Attempts in zkipster can be specified as follows:
Never, 3, 4, 5, 10, 15, 20
On the Security tab, you'll also find where to set up managed multi-factor authentication (MFA).
If you'd like to upgrade to Enterprise, or have a question on Custom Security Policies, reach out to sales@zkipster.com.


