Password sign-in with multi-factor authentication
Teams without single sign-on can now use password sign-in protected by authenticator-app MFA, account lockout, and breached-password checks.
Organizations that don’t use single sign-on can now sign in to Timberline with a password, protected by the same controls you’d expect from an SSO provider.
- Multi-factor authentication with any standard authenticator app. It is recommended by default, and administrators can require it.
- Accounts lock after repeated failed attempts.
- Passwords known to have appeared in public breaches are refused. The check never sends your full password anywhere.
- New users set their password through a one-time setup link, and administrators can reset a user’s MFA from the Access panel.
- “Forgot password” responds the same way for every address, so it can’t be used to discover who has an account.
SSO remains available and recommended for organizations that have it.
Request a demo