Rock U - People - Account Protection Profiles
Transcribed Video Content
A staff pastor's login is a much bigger target than a first time guest's login. And that's because there's more access and data tied to important people in your organization. And Rock knows that automatically assigning an account protection profile of low, medium, high, or extreme and automatically adding some more security to Rock. To look at our account protection profile settings, we'll head to admin tools, then settings, and start looking for security settings. We'll click there and it's pretty simple to understand what these different levels are.
So a low level out of the box is gonna be one with no risk items, medium has a login account, And a High profile would be one either that has an active scheduled financial transaction, a saved payment account, or in a security role marked with high elevated security. And that's because if someone were to take over this account, they could use someone's card for example and they could do more damage. And then an extreme role, which is only for those accounts that have a security role marked with Extreme Elevated Security. And we handle things differently depending on the settings you have set up. So one thing is when we're adding new profiles, sometimes something we do to make sure that there's less duplicate profiles is to do duplicate checking and see when it looks you have similar things a similar address or phone number, and then it will automatically merge those profiles essentially.
But for security purposes, you're going to want to check some of these profiles to be disabled for duplicate checking. And out of the box we'll have medium, high, and extreme checked. That's pretty important because there's a high risk of account takeover when you have these unchecked and people can end up getting access to a role that they should not have access to. There's some more things we can do disable predictable IDs and that means the git file, git image, and git avatar endpoints will use IT keys and GUID values instead of a really simple number so that certain things will be more secure. And there's a lot more that you can do in the security settings, but let's focus on the account protection profiles.
So something really important is having your security roles set up so that there's people that are allowed to do merges of a certain protection profile, such as Hi, and we have Data Integrity workers allowed to do that, then here we have an even more elevated role that's allowed to do account protection profile merges of extreme. So very few people will be able to make this decision, which can be really dangerous. Then you can also disable usage of personal tokens for the following protection profiles. And what this means is if you have an email, for example, with a link with a person token so that someone can click a link in their email and immediately be logged into their account. We can automatically turn it off for specific profiles so that no one can easily be logged into an account they shouldn't have access to.
Then if you want to set up two factor authentication you can do so for different protection profiles here. Then there's also authentication settings but those are covered in our documentation. Now we'll hit save here and you saw there's high and extreme profile levels. Let's look at how to set a security role with a specific elevated security. So we'll go to admin tools, settings, and we'll look for security roles.
Then immediately here in this column you can see some of our roles have security levels marked as extreme or high. And this will just depend on, what you determine the risk to be associated with someone taking over one of these accounts. And it's really easy to change the security level. You'll click on the role, edit it, and you'll go down. Then you can pick enable a security role, then pick a security level here either of none or high or extreme.
So we'll leave this on extreme and let's go use an example of a way that Rock limits people in the way they approach merging. So we will look up Alicia Marbles profile here and say we go to merge Alicia and Bill Marble, which we don't want to do obviously, but this is just for the sake of example, you'll see we immediately get a critical security alert and it says one of these records has a login and different emails associated with this merge. This could be an attempt to hijack the account and one or more of these records is a member of a security role with elevated privileges, which is true because Alicia Marble has an extreme level of security. And something else to note is right now I'm logged in as Alicia, so I have the authority to do this merge. But if I wasn't in a profile with an extreme or high elevated security level or account protection profile, then it would tell me here that I can't make that change.
I have to be in a role of administrator or data integrity worker, for example. Your most important accounts now get extra protection without any daily effort. Rock watches so that you can focus on ministry.