Security Settings

Protect your RAD Repairs account and data with two-factor authentication, session controls, an active-sessions view, and an IP whitelist for logins.

Security Settings Panel
Security Settings - Light Mode

The Security Settings panel provides centralized control over authentication and access policies

Overview of Security Features

RAD Repairs provides multiple layers of security to protect your business data and customer information. The Security Settings section in Admin Settings lets administrators configure:

In addition, RAD Repairs includes two-factor authentication (2FA) per user, a first-login password change flow for new accounts, and built-in rate limiting on login attempts to slow brute-force attacks.

Security Best Practice: We recommend enabling two-factor authentication for all administrator accounts. It significantly reduces the risk of unauthorized access.

Two-Factor Authentication (2FA)

Two-factor authentication adds an additional security layer by requiring users to provide a second form of verification beyond their password. RAD Repairs supports authenticator app-based 2FA using TOTP (Time-based One-Time Passwords). Once enabled, the user is asked for a 6-digit code from their authenticator app every time they log in.

Enabling 2FA for a User

2FA is set up per user from User Management:

1

Open the User

Go to Admin Settings > User Management and click Edit on the user. The Two-Factor Authentication section shows whether 2FA is currently enabled.

2

Start Setup

Click Set Up 2FA to begin. A QR code is generated for this user.

3

Scan QR Code

Open the authenticator app (Google Authenticator, Authy, Microsoft Authenticator, etc.) on the user's phone and scan the displayed QR code.

4

Verify Setup

Enter the 6-digit code from the authenticator app and click Enable 2FA to confirm the setup is working correctly.

Lost authenticator? If a user loses access to their authenticator app, an administrator can disable 2FA for that user from the same Edit User section so they can log in and set it up again.

First-Login Password Change

New user accounts are created with a temporary password and are required to change it on first login. The first-login flow walks the user through:

  1. Password - Choose a new password. It must be at least 8 characters and contain a lowercase letter, an uppercase letter, and a number.
  2. 2FA Setup - When required, scan the QR code with an authenticator app and verify a 6-digit code.
  3. Complete - The user is signed in with their new credentials.

Session Management

Control user session behavior to balance security with user convenience. Both settings save automatically when changed.

Session Duration

How long users stay logged in without activity before requiring re-authentication. Choose from 30 minutes up to 1 month; the default is 8 hours.

Max Concurrent Sessions

The maximum number of devices a user can be logged in on simultaneously. Choose 1, 2, 3, 5 (the default), 10, or Unlimited.

Active Sessions

The Active Sessions list shows all currently active user sessions across devices. From here administrators can:

IP Whitelist for Login

Restrict login access to specific IP addresses or ranges. This is particularly useful for businesses with static IP addresses that want office-only access. RMM agent connections are not affected by the whitelist.

Setting Up the Whitelist

1

Check Your Current IP

The section shows Your Current IP at the top. Add it to the whitelist first - the Add My IP button does this in one click.

2

Add Allowed IPs

Enter individual IP addresses (e.g., 192.168.1.1) or ranges in CIDR notation (e.g., 10.0.0.0/24), each with an optional description like "Office", "Home", or "VPN", and click Add IP.

3

Enable the Whitelist

Turn on Enable IP Whitelist. If your current IP is not in the list, a warning appears - resolve it before enabling to avoid locking yourself out.

Caution: Be careful when configuring IP restrictions. Incorrect settings could lock yourself or your team out of the application. Always add your own IP before enabling the whitelist.

Frequently Asked Questions

What happens if I lose access to my authenticator app?

Contact your administrator - they can disable 2FA on your account from User Management so you can log in, and then set 2FA up again with your new device.

Can I use SMS-based 2FA instead of an authenticator app?

RAD Repairs currently supports authenticator app-based 2FA only. SMS-based 2FA is not available due to security vulnerabilities associated with SMS (SIM swapping attacks, SMS interception).

What happens when a user hits the concurrent session limit?

Logging in on an additional device beyond the limit displaces the oldest session, so the user never has more active sessions than the configured maximum. Set the limit to Unlimited (0) to disable this behavior.

Does the IP whitelist block my RMM agents?

No. The whitelist only applies to user logins. RMM agent connections from customer machines continue to work regardless of the whitelist.

What should I do if I suspect a security breach?

Immediately: 1) Terminate all active sessions from Security Settings, 2) Change your password, 3) Enable 2FA if it is not already on, 4) Contact RAD Repairs support if needed. For serious incidents, consider contacting your IT security team.

Need Help with Security Configuration?

If you have questions about security settings or need assistance configuring your account protection, our support team is here to help.

Contact Support