> For the complete documentation index, see [llms.txt](https://docs.devolutions.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.devolutions.net/cloud/web-interface/administration/configuration-and-security/system-settings.md).

# System settings

Manage global Devolutions Cloud system settings, including temporary passwords, vault visibility, RDM companion tools, session recording, and forbidden password rules.

The ***System settings*** section of the ***Administration*** panel is used to manage the global settings of all users and user groups in Devolutions Cloud.

### General

In the ***General*** section of the ***System settings***, manage settings related to temporary passwords, networking, support tickets, and opened sessions.

<table><thead><tr><th width="201.79998779296875">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Send temporary password by email</strong></td><td><p>Select how the temporary password is sent to users when creating their Devolutions Account from an invite in Devolutions Cloud:</p><ul><li><em><strong>Ask</strong></em>: When creating a new Devolutions Account, a prompt will appear asking to send a temporary password by email.</li><li><em><strong>Send</strong></em>: When creating a new Devolutions Account, users will receive their temporary passwords by email.</li><li><em><strong>Not send</strong></em>: When creating a new Devolutions Account, users will not receive their temporary password by email. At that time, a prompt will appear with their temporary password. This critical information can then be communicated to the users if need be.</li></ul></td></tr><tr><td><strong>Allow sending messages</strong></td><td>Allow users to send messages with or without attachments, or to restrict them from sending messages.</td></tr><tr><td><strong>Block Tor traffic</strong></td><td>Blocks Internet traffic coming from the Tor network.</td></tr><tr><td><strong>Allow users to submit a support ticket</strong></td><td>Enables the option for users to submit a ticket to the customer support team.</td></tr><tr><td><strong>Automatic "Mark as closed" after X days</strong></td><td>Marks opened sessions as closed after a set number of days.</td></tr></tbody></table>

### System message

Administrators can share general messages to communicate essential information and procedures to users. Users have the option to dismiss these messages or retain them as reminders that will be displayed each time they sign in.

System messages settings can also be managed for specific users in ***Administration*** – ***Users*** – ***Edit*** – ***Allow send messages***.

### Vault

In the vault section of the ***System settings***, manage settings related to user vault and visibility.

<table><thead><tr><th width="281">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Allow</strong> <strong>user vault</strong></td><td>Allow User vault for users.</td></tr><tr><td><strong>Public - Allow access request</strong></td><td>Set vault visibility to public. Every user can see public vaults, but only those who have requested access can use them.</td></tr><tr><td><strong>Private - Invitation only</strong></td><td>Set vault visibility to private. Only users with an invitation can see and use them.</td></tr><tr><td><strong>Force default status</strong></td><td>Enforce a default visibility status for new vaults.</td></tr><tr><td><strong>Force Checkout mode on entries</strong></td><td><ul><li>Checkout mode: Control how the <em><strong>checkout mode</strong></em> is enforced when users access entries in the vault.</li><li>Checkout prompt: Define whether users are prompted before checking out an entry.</li></ul></td></tr></tbody></table>

{% hint style="info" %}
Note that vault visibility can also be changed for each vault individually. See [Vault access in Devolutions Cloud](/cloud/web-interface/vault-access-in-devolutions-cloud.md#individual-vault-visibility) for more info.
{% endhint %}

#### RDM & Workspace clients

The **RDM & Workspace clients** settings allow administrators to configure various aspects of how Remote Desktop Manager and its companion tools interact with Devolutions Cloud workspaces.

<table><thead><tr><th width="222.60003662109375">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Cache/Offline</strong></td><td>Set the length of time offline data is stored before it expires.</td></tr><tr><td><strong>Force application password on RDM</strong></td><td>Require a password for accessing Remote Desktop Manager.</td></tr><tr><td><strong>Allow syncing all vaults</strong> <strong>(background)</strong></td><td>Remote Desktop Manager will periodically synchronize all accessible vaults without requiring manual action.</td></tr><tr><td><strong>Portable license</strong></td><td>Allow Remote Desktop Manager users to use their Remote Desktop Manager licenses across workspaces.</td></tr><tr><td><strong>Enforce biometric lock or master password</strong></td><td>Require the use of biometrics or master password when connecting to the workspace.</td></tr><tr><td><strong>Resolve variables in linked host</strong></td><td>Variables are resolved in the linked host field of entries, allowing dynamic values to be used instead of static text.</td></tr><tr><td><strong>Version management</strong></td><td>Set minimal and maximal Remote Desktop Manager version requirements per platform (Windows, macOS, Linux), with optional custom messages.</td></tr><tr><td><strong>Force auto lock after a delay of</strong></td><td>When activated, the Devolutions Cloud workspace in Devolutions Password Manager will lock itself after a specified delay (e.g., 30 seconds) of inactivity.</td></tr><tr><td><strong>Force background lock</strong></td><td>Activating this feature provides an additional layer of security by preventing unauthorized access to the Devolutions Cloud workspace in Devolutions Password Manager if a user switches to another task or window.</td></tr><tr><td><strong>Force clear clipboard after copy with a delay of</strong></td><td>Enforce clear clipboard lets administrators require Remote Desktop Manager and Workspace clients to automatically clear clipboard data after a set delay.</td></tr></tbody></table>

### Session recording

Allow administrators to view and download all recordings for supported sessions with Devolutions Gateway.

{% hint style="info" %}
The [Devolutions Cloud Services](https://docs.devolutions.net/pam/pam-with-devolutions-cloud/install-the-devolutions-cloud-services-to-enable-pam-and-encryption-integration) is required to enable session recording.
{% endhint %}

<table><thead><tr><th width="338.5999755859375">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Enable</strong> <strong>Devolutions Gateway</strong> <strong>recording</strong></td><td>Enable Devolutions Gateway recording in entries.</td></tr><tr><td><strong>Enable Devolutions Gateway recording automatic cleanup</strong></td><td>Automatically deletes session recordings older than a specified duration (in days, weeks, months, or years).</td></tr></tbody></table>

### Users

Allow users to work in offline mode by default. Disabling this option increases security by requiring users to stay connected to the Devolutions Cloud.

<table><thead><tr><th width="282.60003662109375">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Allow offline by default for users</strong></td><td>Determines whether users are allowed to use offline mode by default.</td></tr></tbody></table>

### Advanced

In the ***Advanced*** section of the ***System settings***, manage settings related to Devolutions Password Manager browser extension autofill and external sharing.

<table><thead><tr><th width="353.800048828125">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Allow</strong> <strong>Devolutions Password Manager browser extension</strong> <strong>autofill</strong></td><td>Allow Devolutions Password Manager browser extension to autofill credentials.</td></tr><tr><td><strong>Allow users to send messages and passwords securely via</strong> <strong>Devolutions Send</strong></td><td>Users can send encrypted messages and passwords using <a href="https://docs.devolutions.net/send/overview/devolutions-send">Devolutions Send</a>.</td></tr><tr><td><strong>Require passphrase for</strong> <strong>Devolutions Send</strong></td><td>A passphrase is required before users can send a message using Devolutions Send.</td></tr></tbody></table>

### Password management

The ***Password management*** section of the ***System settings*** lets administrators enable and configure forbidden password validation for the Devolutions Cloud workspace.

<table><thead><tr><th width="222">OPTION</th><th>DESCRIPTION</th></tr></thead><tbody><tr><td><strong>Forbidden password check</strong></td><td>A verification of the password against all configured forbidden password rules is done if enabled. If disabled, no forbidden password validation is applied. Validation is enforced in the web client, as well as in Remote Desktop Manager and Devolutions Password Manager when connected to this workspace.</td></tr></tbody></table>

### Forbidden password

***Forbidden passwords*** let administrators build a list of rules that block specific passwords from being used in the Devolutions Cloud workspace. Each rule has its own name and verification mode, and rules can be added, edited, or removed independently.

{% hint style="info" %}
Use the ***Have I Been Pwned*** integration to check whether a password already appears in known lists of passwords leaked in data breaches, then add it to the forbidden password list if needed.
{% endhint %}

<table data-header-hidden><thead><tr><th width="160"></th><th></th></tr></thead><tbody><tr><td><strong>Setting</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Name</strong></td><td>Give the rule a name to identify it in the list.</td></tr><tr><td><strong>Case sensitive</strong></td><td>Make the rule's verification mode case sensitive.</td></tr><tr><td><strong>Verification mode</strong></td><td>Select the verification mode for the rule between:<br>Contains: the password will be forbidden if it contains the rule's forbidden password.<br>Exact match: the password will be forbidden if it matches the rule's forbidden password.</td></tr><tr><td><strong>Import</strong></td><td>Import a list of passwords from your computer, one password per line. Imports are limited to 1 MB and 1,000 passwords per rule. Passwords that don't match the accepted format are skipped and reported in a warning listing the non-conforming entries, which can be copied to the clipboard; the warning also links to the <a href="https://docs.devolutions.net/rdm/ribbon-menu-bar/reports/entry-security-analyzer">Entry security analyzer</a> report, pre-filtered to the affected entries.</td></tr><tr><td><strong>Export</strong></td><td>Export the forbidden password list as a JSON file.</td></tr></tbody></table>

#### See also

* [Devolutions Academy – Exploring configuration & security](https://academy.devolutions.net/student/page/2761744-exploring-configuration-security?curriculum_activity_id=4271806\&path_id=2543918\&sid=fb72ff46-963b-486d-85f5-6eae67886ddf\&sid_i=0)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.devolutions.net/cloud/web-interface/administration/configuration-and-security/system-settings.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
