/
Secure a Dermi Atlas Professional team member account with two-factor authentication (2FA) and a strong password. Password requirements, 2FA setup, recovery, and session management.
Every account on a Dermi Atlas Professional deployment is a team member account, created by claiming an invitation from the Dermi Portal. The username, password, two-factor authentication, and trusted devices belong to the individual member and are set on the deployment, where the password never leaves the practice network. This article covers the password requirements, two-factor authentication, account recovery, and session management.
Dermi Atlas Professional enforces the following password complexity requirements:
! @ # $ % ^ & * ( ) - _ = + { } ; : , < . > ?. Other symbols are not accepted.The requirements are validated when an invitation is claimed and during password resets.
2FA can be enabled to add an extra layer of security to the member account.
Illustrative demo with synthetic data. Learn more
Once 2FA is enabled, the sign-in page hands off to an Enter Authentication Code step after the username and password are accepted. The current code from the authenticator app is entered there and confirmed with Verify.
Illustrative demo with synthetic data. Learn more
If the authenticator device is unavailable, Need help? on that step reveals a Use recovery code action, which switches the page to Enter Recovery Code. Ten recovery codes are issued when 2FA is enabled, and each one works a single time; a code is consumed once it has been used to sign in.
Illustrative demo with synthetic data. Learn more
Two-factor authentication can also be disabled later from Options => Account using the Request Disable verification link. The link opens the Confirm 2FA Removal page, which takes a current authenticator code and the Disable 2FA action.
Illustrative demo with synthetic data. Learn more
Verification links and recovery email for a deployment are delivered only to the verified email addresses of its team members. An address is verified when the invitation sent to it is claimed. An account adopted from a deployment that predates team membership may hold an address that was never verified by email; in that case the license owner selects Verify Address under Change Member in the Dermi Portal, a code is emailed to the address, and the member enters it under Changes from the Dermi Portal on their Atlas account page. Email address changes follow the same route through the owner, as described in Claiming a Team Invitation.
While an address is unverified, links for two-factor authentication, password changes, and account recovery are opened from Dermi Atlas Manager through the Verifications icon (shield) instead of from the inbox.
If the password or the username is forgotten, Forgot your login? on the sign-in page opens the Recover Account page. Entering the account email address and selecting Recover Account generates a recovery link. The link is emailed to the address on file together with the username; when no email is sent, the confirmation reports that the link has been created and it can be opened from Dermi Atlas Manager through the Verifications icon (shield). Recovery requires a verified email address, and the link expires after one hour.
Illustrative demo with synthetic data. Learn more
The link opens the Change Your Password page, whose New Password field enforces the complexity requirements listed above. Selecting Update Password applies the new password, ends every active session, and clears all trusted devices, so signing in again with the new password is required.
Illustrative demo with synthetic data. Learn more
The Security & Authentication section includes a Sign Out of All Devices card. Selecting Sign Out immediately ends every active session across all devices and locations, including the current device, and clears all trusted devices. Signing in again is required afterward. Use this if unauthorized access is suspected or a shared workstation was left signed in.
A session depends on team membership as well as on the username and password. Sign-in is refused, and an open session ends, when the account has been disabled in Dermi Atlas Manager or when the member has been removed or restricted in the Dermi Portal. The sign-in page then names the reason (Disabled, Restricted, Revoked, or Unlisted) and who to contact; each state, with the message it shows and who resolves it, is covered under Sign-In Refused for an Account That Previously Worked in Troubleshooting Account and Authentication Issues.
Your feedback helps us improve our documentation
Contact our support team for personalized help
All demonstrations, screenshots, and media on this page use synthetic data only. No real patient information is shown.
The following are synthetic and do not correspond to real patients:
Media is provided solely to illustrate platform functionality and workflows.