System Security Properties

Last updated: September 23, 2026

Leading2Lean keeps your system both accessible and secure. Password and login settings can be customized to your site's specific security and accessibility requirements — just reach out to the L2L support team with your request.

All authentication is built on industry-standard libraries. Passwords are salted and hashed — never stored in plaintext. Login sessions are encrypted via SSL/TLS 1.2, and all data is protected both in transit and at rest.

System Properties

System properties affect all sites on a particular server.

  • Use l2l.com as the default dispatch DNS domain in all user communications: For customers using l2l.com in their SAML/SSO instead of leading2lean.com. Enables l2l.com in scheduled report emails and QR code links. (Without this setting, links will prompt a re-login if your SAML directs to l2l.com.)

  • Disable Login after X Failed Attempts: A number specifying how many failed login attempts are allowed before an account is locked.

  • Disable Login for X Minutes after Failed Attempts Limit: A number (in minutes) specifying how long an account stays locked once it hits the failed-attempts limit above.

  • Users Can't Use Any of Their Last X Recent Passwords: A number specifying how many previous passwords are blocked from reuse.

  • Don't Allow Common Passwords to Be Used: 0 or 1 (1 = enabled). When enabled, blocks commonly-used passwords (e.g., "123456", "password").

  • Passwords Must Meet at Least X of the Supported Complexity Classes: A number from 1–4, specifying how many of the four complexity requirements (uppercase, lowercase, numeric, non-alphanumeric) a password must satisfy.

  • Case-Insensitive Logins for Usernames: 0 or 1 (1 = enabled). When enabled, username matching ignores letter case.

  • Disable Password Reset Functionality: 0 or 1 (1 = disabled). When enabled (set to 1), this removes the "Reset My Password" link from the login page. (Note: when this setting is off/0, the reset link is available so users can reset their password via their username and email.)

  • Enable SSOConfig Mode Functionality: 0 or 1 (1 = enabled). Grants IT Manager Administrators and Administrator-Administrators access to the SSO configuration screen from Setup.

  • Enable SAMLConfig Mode Functionality: 0 or 1 (1 = enabled). Grants IT Manager Administrators and Administrator-Administrators access to the SAML configuration screen from Setup.

Changing Property Values

To modify any of these settings for your site or server, submit a ticket to L2L Support specifying which properties you'd like changed, to which values, and for which sites (if applicable).

Once L2L enacts the changes, they take effect immediately:

  • Users already logged in at the time of the update will be prompted to update their password the next time they reach a point requiring a digital-signature-equivalent action (e.g., clicking "Dispatch Me"), if their current password doesn't meet the new requirements.

  • Users not logged in at the time of the change will be prompted to update their password on their next login, if it's out of compliance.


One note: your source text says setting Disable Password Reset Functionality to 1 means "disabled," but then describes what happens when it's "enabled" — those two read like they contradict each other. I flagged it above (in the disabled bullet) rather than resolve it silently — worth double-checking the actual behavior before this goes out.