Security Settings
For LMS, Business & Enterprise Accounts only. To upgrade your account go to: https://www.coursebox.ai/pricing
The Security page is where Super Administrators set the password policy and sign-in methods for their platform. From here you can decide how strong user passwords need to be — or remove passwords altogether and have everyone sign in with a magic link.
Accessing Security Settings
From the top navigation bar, click the dropdown menu (▼) next to your profile icon.
Select Settings.
In the left-hand menu, click Security.
Disable passwords (magic link only)
The Disable passwords toggle switches your platform to passwordless sign-in.
Setting | What it does |
|---|---|
Disable passwords | When turned On, users sign in with a magic link only. Password login, password reset and password change are all turned off. |
With this setting On, a user enters their email address on the login screen and receives a one-time sign-in link by email — there is no password field, no “Forgot password” flow, and no way for users to change a password from their profile.
Tip: Passwordless sign-in removes weak and reused passwords entirely and cuts down on password-reset support requests. Before switching it on, make sure your email settings are configured correctly and that learners can reliably receive email from your platform — if magic link emails don't arrive, users cannot log in at all.
Note: When Disable passwords is On, the password policy options below no longer apply, because no new passwords are being created.
Minimum password length
Minimum password length sets how many characters a new password must contain. The default is 12.
Click the pencil (edit) icon next to the number.
Enter your preferred minimum length.
Save the value.
This applies to new passwords — that is, any password created at registration, at a password reset, or when a user changes their password.
Tip: Length is the single biggest factor in password strength. A minimum of 12 characters is a sensible baseline for most organisations; raise it if your compliance policy requires it.
Character requirements
Character requirements let you choose which character types every new password must include. Each requirement is an independent On/Off toggle, and all four are On by default.
Requirement | What the password must include |
|---|---|
Require an uppercase letter | At least one capital letter (A–Z). |
Require a lowercase letter | At least one lowercase letter (a–z). |
Require a number | At least one digit (0–9). |
Require a special character | At least one of the following characters: |
Turning a requirement Off makes that character type optional rather than forbidden — users can still include it if they wish.
Tip: If learners report that a password “keeps getting rejected”, check this page first. The password they are choosing is most likely missing one of the required character types, or falling short of the minimum length.
Choosing the right policy
If you want to… | Do this |
|---|---|
Remove passwords and password-reset requests entirely | Turn Disable passwords On (magic link sign-in only). |
Meet a corporate or compliance password standard | Leave Disable passwords Off, raise the minimum password length, and keep all four character requirements On. |
Make sign-up as frictionless as possible for public learners | Keep the 12-character minimum but turn off one or two character requirements. |