Skip to main content

Controlling who can get into a portal

Password protection, visitor login, link expiry and copyright notices, and a sensible default posture for external shares.

Written by Zakaria Waletski

A portal is content leaving your boundary, so the access settings are worth understanding properly rather than accepting whatever the dialog offered. This is also the part a security reviewer will ask about.

Password protection

Set at creation, this requires a password before anyone sees the content. Use it whenever the material is not something you would be relaxed about a stranger opening.

Requiring people to identify themselves

Visitors can be asked to log in with a name and email address before the portal opens. This is not authentication in the sense your identity provider means it, and you should not treat it as proof of who someone is. What it does give you is attribution in the activity log, so you can see who opened what.

Expiry, which is the important one

A portal link stays live until it expires or until someone removes it. Setting an expiration date and time when you create the share means access ends on its own, without anyone having to remember.

Make this a habit rather than a decision. The alternative is a growing collection of live links nobody is tracking, and that collection is exactly what gets found during an audit or when someone leaves.

To set it: open Manage Portal from the ioPortal tab, find the link expiration setting, enable it, choose the date and time, and save. Access stops at that point.

Copyright notice

You can display a copyright line on the portal. It does not restrict anything technically, but it sets expectations for whoever receives the content, and for licensed or rights managed material it is worth the ten seconds.

Open Manage Portal, go to the copyright section, enable it, enter your text, and save.

A sensible default posture

  • Expiry set on every portal, always

  • Password protection on anything not already public

  • Login required where you need to know who looked

  • Guest upload off unless you specifically want content coming back in

  • Copyright text on anything licensed or client owned

Configure a portal this way once and set it as your default, and every future share starts from the right place.

Related

Creating a portal covers default portal settings. Monitoring and closing a portal covers seeing who actually opened it.

Did this answer your question?