Authentication

Last updated: 2026-04-11 • ← Security program

Backbuild supports enterprise authentication through single sign-on, multi-factor authentication, and configurable session and lockout policies. All authentication events are recorded in a tamper-evident audit log with user attribution.

Single sign-on

Multi-factor authentication

Session management

Account lockout

Ten consecutive failed SSO authentication attempts trigger a 30-minute account lockout for the affected user. This threshold is aligned with PCI DSS v4.0 requirement 8.3.4. Administrators can review lockout events and, where appropriate, unlock accounts through a documented process that is itself audit logged.

Authentication audit logging

Contact

SSO configuration help or authentication questions: