---
title: "Enhance ProcessMaker Platform Security"
slug: "enhance-processmaker-platform-security"
updated: 2026-06-03T17:58:00Z
published: 2026-06-03T17:58:00Z
canonical: "documentation.decisions.com/enhance-processmaker-platform-security"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://documentation.decisions.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Enhance ProcessMaker Platform Security

Follow security best practices to better secure your ProcessMaker Platform instance.

## Overview

Follow these best practices to enhance security in your ProcessMaker Platform instance:​

- [Require all users to periodically reset passwords](/v1/docs/enhance-processmaker-platform-security#require-all-users-to-periodically-reset-passwords).
- [Require all users to log on via SSO to ProcessMaker Platform](/v1/docs/enhance-processmaker-platform-security#require-all-users-to-log-on-via-sso-to-processmaker-platform).
- [Verify all user accounts that run scripts](/v1/docs/enhance-processmaker-platform-security#verify-all-user-accounts-that-run-scripts).
- [Identify invalid and blacklisted IP addresses](/v1/docs/enhance-processmaker-platform-security#identify-invalid-and-blacklisted-ip-addresses).

## Require All Users to Periodically Reset Passwords

Require all users to periodically reset their passwords.

[Enable the **User must change password at next login** toggle key in each user account to require tat user to change the password prior to next logging on to ProcessMaker Platform](/v1/docs/edit-a-user-account).

## Require All Users to Log On via SSO to ProcessMaker Platform

Require all users to log on to your ProcessMaker Platform instance via Single Sign-On (SSO), OAuth, OKTA and/or two-factor authentication.

Follow these guidelines:

1. [Configure SAML SSO](/v1/docs/sso-saml-settings) or another ProcessMaker Platform-supported SSO authentication protocol.
2. Instruct all users to authenticate via SSO to log on to your ProcessMaker Platform instance.

## Verify All User Accounts that Run Scripts

Verify that all user accounts that run scripts are valid and appropriate.

[Review the **Run script as** setting for all Scripts to determine which user's API client token to use with the ProcessMaker Platform REST API](/v1/docs/configure-a-script).

## Identify Invalid and Blacklisted IP Addresses

Follow these guidelines to identify invalid and blacklisted IP addresses that access your ProcessMaker Platform instance:

1. Ask your Customer Success Manager to provide a list of all IP addresses that access your ProcessMaker Platform instance.
2. Identify the following from the list of IP addresses:

  - Identify which IP addresses on this list are invalid.
  - Identify which IP addresses are blacklisted.
3. Provide your Customer Success Manager an incident report.
