Skip to main content
Last reviewed: March 5, 2026 Owner: Security + Engineering Review cadence: Quarterly Status: Implemented This standard defines how Tero enforces user authentication controls, including password policy ownership, MFA, and session protections.

What this standard answers

  • Who owns password policy controls in hosted and self-hosted deployments
  • How authentication is enforced for users and admins
  • What controls are applied when password-based authentication is used

Implementation status (March 5, 2026)

Tero supports SSO and OIDC-capable authentication and enforces authentication and session controls in application access paths.

Authentication and password baseline

Supported login and SSO protocols

Automated provisioning and deprovisioning

Session timeout and reauthentication settings

Session binding and network attribute controls

Enforcement model

  • Tero requires authentication before access to protected application paths.
  • Tero evaluates authorization in tenant and workspace context.
  • Tero removes or adjusts access when role and lifecycle state changes.

Hosted vs self-hosted scope

Exceptions and governance

Any authentication or password-control exception requires documented risk acceptance, approval, compensating controls, and a time-bound remediation plan. Questions: