Locking User Accounts After a Security Breach¶
In the event of a security breach, System Administrators can take immediate action to prevent further unauthorised access by locking affected user accounts.
Note
The following can only be performed by a System Administrator.
Step 1 – Access the User Administration Area¶
-
Navigate to
Administration → Usersfrom the Menu Button -
Use the filters or search options to identify the users whose access needs to be revoked.
-
Select one or more user records by ticking the checkboxes next to each username.

Selecting Multiple Users
Clicking the checkbox at the top of the user list will only select the records currently visible on the page.
If your filter criteria match more records than are displayed, use the menu option shown in the preceding image to choose Select All Results. This will select all matching records across all pages.
- Click the
Mass Updatebutton.

- In the Mass Update modal:
- Select the Is Active field.

- Set the Is Active field to False.

- Click
Updateto confirm the mass update.
Note
Any user account set to Inactive will be immediately prevented from logging in. If a user is already logged in when this change occurs, they will be automatically logged out.
Step 2 – Reset User Passwords¶
Once user accounts have been deactivated, System Administrators should reset user passwords to maintain system security and prevent unauthorised access.
There are several different ways to reset the Users password depending on your need:
- Option A - Send Password Change Link
- Option B – Send Password Reset Email
- Option C – Generate a Temporary Password
Additional Recommendations¶
- Communicate Internally: Notify relevant stakeholders about the breach and actions taken.
- Audit Logs: Review login and activity logs to identify any suspicious access.
- 2FA Enforcement: Confirm that all reactivated accounts are configured with two-factor authentication.
- Review Permissions: Evaluate Role and Permission settings to ensure no excessive access exists.
Taking swift action to lock accounts and reset credentials is critical to preserving the security of your system.
See also¶
- Access Info Template
- Password Change Link Template
- Multi-Factor Authentication
- Change Password
- Mythradon Marketing
- Mythradon Sales
- Mythradon Service
- Mythradon System Administration
- Mythradon Tools