Dive offers Security Settings for owners with fine-grained controls including access restriction, login authentication, data / sharing restrictions, permitted user roles per feature, device cache settings, audit logs, and more — all configurable to match your operational policies. This article provides an overview.
Who can configure
Only users with Owner privileges can change Security Settings.
How to open the settings screen
- Log in to Dive with Owner privileges
- Open "Owner Functions" from the side menu
- Select the "Security" tab at the top
Settings overview
Access restriction
- Configure IP address restriction — Allow access only from specific sites or through VPN (IPv4 / IPv6, single addresses, ranges, and CIDR notation supported)
Login authentication
- Configure Password policy — Password expiry date and forced password change on first login
- Make two-factor authentication (MFA) mandatory for the entire team — Require TOTP for all team members (Enterprise plan only)
- Configure Single Sign-On (SSO) — Integration with Microsoft Entra ID (OIDC) / SAML 2.0, option to prohibit non-SSO login (Enterprise plan only)
- Prohibit the use of email-free accounts — Prohibit new ID-login type accounts
Data / sharing restrictions
- External Sharing Restriction Settings (enable / disable external sharing) — Allow or disallow time-limited external share URL functionality at the team level
Permitted user roles per feature
- Permitted user roles per feature — Role thresholds for SOP export / Folder Excel export / External Sharing / Media download / Attachment download / Skill map export / Usage report export (Enterprise plan only)
Device-side controls
- Device cache settings (do not retain view data on devices) — Disable offline playback and preload, always require network connection (Enterprise plan only)
Logs
- Export Audit log to CSV — Download operation logs for the entire team as CSV
Related (personal settings / external connection requirements)
- Two-factor authentication (personal setup)
- About allowlist in Security (external connection domains)
Tips
- When configuring IP address restriction before production use, your own IP address is automatically added if not already included. If you set the restriction from a network outside your usual range, you may lock yourself out even as an owner, so please be careful.
- Before enabling MFA required, ensure you (the owner) have already registered MFA (if you enable it before registering, you will lock yourself out)
- Before enabling SSO forced (prohibit non-SSO login), test SSO login with a test user
- The default role thresholds for each feature are Dive's recommendation. Adjust them to match your organization's security policies