Administrating Realms : About realm security
  
About realm security
Ensuring that your system is as secure as possible is important. User authentication policies, function-based roles, session expiration, API access, and support access are all a part of realm security. Realm administrators have these security-related settings available to them:
Password policy—Set parameters for valid passwords. See About the password policy and TOTP.
Session expiration time—Terminate inactive user session after the specified duration of inactivity. See About session expiration.
Riverbed Support access—Provide Riverbed Support access to your setup for a specified duration after which access is automatically terminated. See About Riverbed Support access.
Rest API—Enable access to the Rest API. See About REST API access.
Two-factor authentication—Require users to authenticate using their login credentials and one additional form of authentication. See About two-factor authentication.
Also, realm administrators can view log in activity through audit logs. See Auditing login activity.