October 2026
- Sign-in, verification and authenticator codes are entered one digit per box; pasting the whole code fills every box.
- Sign-in protection without a CAPTCHA. Repeated failed sign-ins, codes or password resets lock further attempts for 30 minutes, and the lock clears by itself; no account is locked permanently. Networks you have signed in from in the last 30 days are not locked by other people's attempts.
- After 100 wrong second-factor codes in a row, codes stop working for 30 minutes at a time. A recovery code still signs you in, and the Super Admin can reset the account.
- Locks, early unlocks and recovery-code sign-ins appear in the audit log of each organisation the account belongs to, and in no other.
- Opening FDIE from your identity provider's app portal shows a Continue page first, so another website cannot start a sign-in for you.
- Changing the identity provider needs the Super Admin's password and, where one is set up, an authenticator code.
- SCIM 2.0 provisioning under Settings, Single sign-on: your identity provider can add, update, deactivate and remove people on your verified domain.
- With Google Workspace single sign-on, FDIE accepts only accounts that your organisation's Workspace manages, and no provider may report the email address as unverified.
- Organisation names cannot contain web links or email addresses.
- Compliance evidence: ZIP files are not accepted, and PDFs that carry scripts, launch actions or attached files are refused; print such a PDF to a new PDF and upload that. The file picker shows the accepted types and the 50 MB limit.
- Data export stays available when no plan is active.