How sign-in security works
Two screens decide how people get in — the password policy and security profiles. Which rules bind an Offision password, and which bind everyone including Microsoft 365 and Google sign-ins.
Two screens under Security decide how people get into Offision. Global password policy sets the rules for Offision passwords and what happens when someone gets one wrong. User security profiles set where a person may sign in from, whether they need a second factor, and from which IP addresses.

Global password policy — the rules for Offision passwords.
The part that surprises people
Signing in with Microsoft 365 or Google skips the password policy entirely. No lockout after failed attempts, no expiry, no reuse check, no two-factor prompt. The same is true of an LDAP or Active Directory sign-in.
That is not an oversight. There is no Offision password in those sign-ins to hold to a rule — the identity provider checked the credentials before Offision ever saw the person, and it is the one enforcing lockout and multi-factor. Setting Maximum failed login attempts to 3 does nothing for a company that signs in entirely through Microsoft 365, and the place to set that rule is Microsoft’s console, not this one.
So the password policy is worth setting when some or all of your people sign in with an Offision password. Where everyone uses single sign-on, it is inert.
What binds everyone
Three things apply to every person, however they signed in.
IP restriction on a security profile is the strongest of the three. It is checked on the server, on every request, so a person outside the range is refused even if they signed in perfectly a minute earlier and even if they are using the API directly.
The platform toggles — desktop browser, mobile browser, the mobile app, the Outlook and Teams add-in — are checked when the app opens. Someone on a blocked platform is told why and signed out.
Auto logout ends a session after that many minutes without touching the keyboard or screen. It runs in the app, so it applies wherever the person came from.

A security profile: where these people may sign in from, two-factor, and IP restriction.
Security profiles are assigned per person, and one profile is the default that new people get. They need the Security setting licence; the password policy does not.
What it does not control
None of this ends a session that is already running. Changing the password policy, adding an IP restriction, or turning a platform off governs the next sign-in and the next request — a person already signed in stays signed in until their device is signed out. That is Login devices, and it is a separate job.
Who may see or do what is permissions, not security. A profile decides where someone signs in from, never what they can reach once inside.
The Windows app follows the Desktop browser toggle from 4.5.9. Before that it was not covered by any of them, so a profile that blocked desktop browsers still let the Windows app in.
Open Global password policy
