Security best practices
11 min
keeping your fusion signage account secure doesn’t need to be complicated a few simple habits can help protect your content, screens and company information while ensuring the right people have the right level of access give everyone their own login each person using fusion signage should have their own user account avoid sharing login details between team members individual accounts make it easier to apply the right permissions to each person remove access when someone leaves see who made a change keep passwords and authentication methods private fusion signage supports unlimited user accounts, so there’s no need to share choose the right user level fusion signage has two main user levels standard best for users who create and manage content management includes standard access, plus the ability to manage users and update account or company information we recommend reserving management access for people who genuinely need to administer the account permission groups https //support fusionsignage com au/using fusion signage/permissions can provide more control over the screens, media folders, playlists and schedules that standard users can access enable mfa multifactor authentication adds an extra security step when signing in and helps protect your account if your password is compromised fusion signage supports authenticator apps such as google authenticator, microsoft authenticator and duo mfa is optional, but we highly recommend enabling it for every user learn more about mfa https //support fusionsignage com au/using fusion signage/multifactor authentication mfa consider using a passkey passkeys allow you to sign in securely without a password depending on your device, you can use face id, touch id, windows hello, a device pin or a hardware security key passkeys provide strong protection against password theft and phishing to register one, go to settings → security → login methods and select register a new passkey once passkeys are enabled, you’ll use a passkey instead of your username and password we recommend registering a backup passkey or using a securely synchronised one in case your device is lost or replaced learn more about passkeys use a strong, unique password if you use password based login, choose a password that is unique to fusion signage long and difficult to guess stored securely in a trusted password manager never shared through email, chat or support tickets if you think your password has been exposed, change it immediately under settings → security → login methods use sso and scim for larger teams single sign on allows users to access fusion signage through your organisation’s identity provider this can make it easier to enforce company security policies and manage access centrally scim helps automate user management, including creating, updating and removing users when someone joins, changes roles or leaves your organisation together, sso and scim can reduce manual administration and help prevent former team members from retaining access sso, saml and scim are available with a pro licence contact fusion signage if you would like to discuss enabling these features remove access when it’s no longer needed when someone leaves your organisation or no longer needs fusion signage, remove their access promptly remember to review their fusion signage user account permission group and location access registered passkeys personal access tokens sso or identity provider access integrations or automations they managed it’s also a good idea to review your user list every few months and remove old or unnecessary accounts keep personal access tokens secure personal access tokens, or pats, are used for api connections and integrations such as zapier they should be treated like passwords create separate tokens for different integrations give each token a clear name store tokens securely never include tokens in emails, screenshots or public code revoke tokens that are no longer required replace tokens before they expire pats are user specific, so users should not share tokens learn more about personal access tokens review audit logs audit logs show who made a change, when it happened and which item was affected they can help you investigate unexpected changes, accidental deletions or publishing issues audit logs are available with a pro licence under settings → audit learn more about audit logs secure your screens and media players don’t forget about the physical devices running your signage where possible keep operating systems, firmware and applications updated change default device passwords use kiosk or signage mode prevent unauthorised access to settings secure external media players and accessible usb ports use menu secure access on supported interactive devices connect devices to a trusted, managed network fusion signage requires outbound access over port 443 using https if you use a firewall, we recommend allowing fusionsignage com au check with your it team before making any network changes be careful with external content before connecting websites, dashboards, data sources or third party integrations make sure the source is trusted avoid including usernames or passwords in urls check who can update the original content don’t display confidential information on public screens remove integrations you no longer use remember that changes made in a connected platform may also affect what appears on your screens a quick security checklist give every user their own login avoid shared accounts enable mfa or passkeys use strong, unique passwords limit management access review users and permissions regularly remove access promptly when someone leaves protect personal access tokens keep devices and software updated use trusted networks and content sources consider sso, scim and audit logs for larger teams a quick security review every few months can go a long way toward keeping your account, content and screens protected looking for something else? we can’t wait to hear about it reach out to our sunshiney support and we'll be in touch in a flash