Lucid admin panel: Security settings

Written by:  Shanna S
Last updated:  

In the Security page of the admin panel, the account owner, account admins, and Shield admins can customize your Lucid security settings to match the needs of your organization. 

Plan availability: Team and Enterprise.
  • Available on FedRAMP accounts. This page can be used for Secure Configuration Guidance for FedRAMP.
  • Read the Lucid Plans article for more information about what is available on your account or the Upgrade your Lucid account article for instructions to upgrade.

Access the Security page

To get to the Security page, follow these steps:

  1. Select Admin.
  2. Click Security in the left-hand menu.

Enable Domain Control enterprise-tag.png

Domain Control is an Enterprise only feature that allows you to control the security settings for users on your domain and set security standards for your entire organization. With domain control enabled on your Lucid account, users are prevented from creating unauthorized accounts with the controlled domain.

When you enable domain control, users who attempt to sign up for a Lucid account will be notified that an Enterprise account already exists and will be redirected to verify their identity. Once they verify their identity, they’ll be added to your organization’s Lucid account.

The method you select to verify users' identities should match the default user sign in authentication method set for the account.

Select one of the following options for verifying user identity:

  • Confirmation email: The user receives an email with a confirmation link.
  • SAML authentication: The user is redirected to your organization’s SAML instance.
  • Google SSO authentication: The user is redirected to authenticate via Google SSO.
  • Office 365 SSO authentication: The user is redirected to authenticate via their Office 365 credentials.
  • Redirect to custom authentication URL: The user is redirected to a different SSO provider via an authentication URL.

Note: Due to the security demands of domain control, you will need to contact your Account Manager, Customer Success Manager, or contact sales to request setup.

Domain verification enterprise-tag.png

Domains are verified for two purposes—consolidations and domain control.

Domain verification is a process that confirms ownership of specific domains prior to locking down a domain to be controlled by a single account or consolidating users who are on those domains. For security and data privacy reasons, Lucid is obligated to follow a specific procedure to verify that an account who's asking to consolidate or control a specific domain does own that domain. 

Domain verification must occur if both of the following are true:

  • The domain to be consolidated or controlled is different from the account owner's domain (referring to their email address on the account).
  • There are no users on the account with the same domain as the one to be consolidated or controlled.

Domain verification methods

Lucid offers four ways to verify your domain:

  • DNS Record Validation
  • Signed Form Validation
  • Hosting Validation
  • Email Validation

To request a domain verification for your Enterprise account, contact your Account Manager, Customer Success Manager, or contact sales and provide the following details:

  • The domain(s) to be verified. 
  • Email address(es) and name(s) of the web-administrators of those domains (if verifying domain via Hosting or DNS Record Validation).
  • Email address(es) and name(s) of the Lucid admin(s).

Domain invites

domain-invites-setting-in-admin-panel.png

Determine whether users on your Team or Enterprise account on the same domain can email you a request to join your account when they create a Lucid account. If you uncheck this box, you will no longer receive join requests and the next largest account with the same domain will receive the requests.

Determine whether users on your account can leave by accepting an invitation to another account. Allowing users to leave your account without express action from an admin is defaulted to off. Selecting that option will allow your users to accept explicit invites from other accounts.

Note: If a user leaves your account via an invitation, they will by default take their documents with them. However, if their documents are organized within a team folder, the documents will not be transferred with the user.

Allow non-admins to invite new users

With this setting, you can indicate the ability for non-admin users on your Team or Enterprise account to invite new users to join.

Your options include:

  • No restrictions. All users can invite new users.
  • All users can invite other users with the same—or approved—domains.
  • All users can invite new users from domains listed here.
  • Total lockdown. Only the account owner, account admins, and Shield admins can invite new users.

Authentication sign-on methods

Select Authentication from the Security dropdown in the left-hand menu to access user sign-on and password settings.

The sign-on methods currently supported in Lucid are as follows:

Note: Lucid users can set up multi-factor authentication (MFA) via SSO login with Google or Microsoft. Enterprise accounts can set up multi-factor authentication via an Identity Management Provider (IDP).

User sign in

Enable and disable different login methods by checking or unchecking the boxes next to the different methods.

user-sign-in-methods-allowed-on-team-or-enterprise-account.png

When you have more than one method selected, users will be able to select their desired log in method after typing their email address into the Lucid log in page.

Default authentication

Your account’s default authentication method is the login method users will encounter when they click Next or hit the "Enter" key after typing their email address into the Lucid login page. 

The default authentication method selected should match the method selected to verify users identity (please see domain control section).

SAML enterprise-tag.png

If you’re using SAML sign-on, SAML should be set as the default authentication method. If it’s not, users will be able to access Lucidchart, Lucidspark, and Lucidscale via your IDP, but will not be able to use SAML sign-on via the Lucid log in page.

Two-factor authentication (2FA) enterprise-tag.png

Two-factor authentication—often shortened to 2FA or MFA—is a security process that requires users to verify their identity using two different methods. Typically those methods are something they know (like a password) and something they have (like a phone or security token).

In Lucid, Enterprise admin have the option to enforce two-factor authentication under the “User sign-in” section of the admin panel. To require users on your account who log in with email and password to set up two-factor authentication through a third-party authentication app, follow these steps:

  1. Check the box next to "Enforce two-factor authentication".
  2. Select Continue.
  3. Click Save changes in the top-right corner of the page.

Set up two-factor authentication as a user
If this option is enabled, all current users and all new users added to your account in the future will be prompted to set up two-factor authentication upon log in via email and password. To do this, users need to:

  1. Log in to Lucid using your email and password.
  2. On a separate device, download or open a third-party authentication app.
    • You can use any authenticator app such as Google Authenticator, Microsoft Authenticator, LastPass and more.
  3. Follow setup prompts within your authentication app.
  4. Scan the Lucid-provided QR code from the app.
    • Alternatively, click eye-hidden-icon.png the eye icon under the QR code and type the Lucid-provided secret code that is revealed into the authenticator app.
  5. Enter the 6-digit code generated by the authenticator app into the provided text box in Lucid.
  6. Click Verify code.
  7. Copy the recovery code that appears and paste it somewhere safe. This code will be needed if you need to sign in without your authenticator app or if you need to recover your account.
  8. Check the box next to “I saved this code in a safe place”.
  9. Click Complete.

Following this setup, users will be prompted to enter a 6-digit code from the authenticator app each time they log in with email and password.

two-factor-authentication-setup.png

Reset users’ two-factor authentication
At any time, account owners, account admins, and Shield admins can reset one or more users’ two-factor authentication through the Users page of the admin panel. To do this:

  1. Click Users from the navigation menu on the left-hand side of the admin panel.
  2. Select one or more users from the list.
  3. Click screenshot of the three dot icon to click to delete a custom shape library in lucidchart.png the three-dot menu to the far right-hand side of a selected user’s row.
  4. Select Reset User 2FA.
  5. Click Confirm.

The next time the selected users log in, they will be required to go through the two-factor authentication process, even if they have already done so in the past.

Set a password policy

If your organization allows email and password log in, the account owner, account admins, and Shield admins can change the settings in Authentication from the dropdown under Security in the left-menu to increase the security of your users’ passwords.

On Team and Enterprise accounts, this includes setting a minimum number of characters, as well as specifying whether at least one of each of the following items are requested: upper case character, numeric character, symbolic character.

password-restrictions-if-email-and-password-allowed-for-Lucid-sign-in.png

Additional password restrictions available to Enterprise accounts only include setting a limit to failed login attempts allowed before lockout, along with the lockout duration period, requiring users to change their passwords after a certain amount of time, and preventing reuse of previously used passwords.

password-restrictions-available-on-enterprise-account.png

Force logout and password reset

Selecting Force reset will end all active sessions for all users on your account, including administrators. Email and password users will be prompted to reset their password upon their next login. SAML and SSO users will be required to re-authenticate through their identity provider (IdP).

Customize max session time-out enterprise-shield-add-on-tag.png

This feature lets you define a maximum session duration for users on your account. Once a user exceeds the configured session limit—regardless of activity—they will be required to re-authenticate. For SAML users, they'll be redirected to their Identity Provider (IdP) for reauthentication.

For more information on the Enterprise Shield add-on, check out our Enterprise Shield add-on overview article.

When this feature is enabled, the account owner, account admins, and Shield admins can customize the time-out duration between 2 hours and 365 days.

To set a max session time-out limit, follow these steps from the “Max session time-out” section of the Security authentication page in the Lucid admin panel:

  1. Check the box to “Automatically log out users after a fixed session duration”.
  2. From the dropdown menus, customize the time limit.
  3. Click Save changes in the upper-right corner.

If you do not want to enforce a max session time-out limit, uncheck the box next to “Automatically log out users after a fixed session duration”.

Configure idle session time-out limit enterprise-shield-add-on-tag.png

With this feature, the account owner, account admins, and Shield admins can set a time limit for inactivity before users are automatically signed out of the Enterprise account. If a user is idle for the set time limit, they will be required to log in again when they resume activity.

For more information on the Enterprise Shield add-on, check out our Enterprise Shield add-on overview article.

Note: This feature is available to all accounts on the FedRAMP environment, even those that don’t have the Enterprise Shield add-on.

The minimum limit you can set is 15 minutes and the maximum limit is 14 days.

To set a time-out limit, follow these steps from the “Idle session time-out” section of the Security authentication page in the Lucid admin panel:

  1. Check the box to “Automatically log out inactive users”.
  2. From the dropdown menus, indicate the time limit.
  3. Click Save changes in the upper-right corner.

If you do not want to enforce an idle session time-out limit, uncheck the box next to “Automatically log out inactive users”.

idle-session-timeout-section-of-lucid-admin-panel.png

Restrict user log in to allowed IP addresses enterprise-shield-add-on-tag.png

If you, as an account owner, account admin, or Shield admin, want your employees to only be able to log into their Lucid account from specific locations, check this box and list certain IP addresses by typing them into the field below. This feature requires CIDR notation to denote IP ranges, e.g. 192.168.2.0/24. For an overview of this and our other Enterprise Shield add-on features, check out this article.

Note: This feature will not prevent users from logging in with an allowed IP address and then moving to another address that is not listed.

Adjust sharing settings

The account owner, account admins, and Shield admins can adjust the sharing settings by selecting Sharing from the Security dropdown in the left-hand menu. Across the top of the page you will see a tab for Sharing settings, Document ownership transfer, and Editor experience.

Basic sharing

Document and folder sharing
If you want to grant your Team or Enterprise users the ability to share documents, images, and folders with all users on the account at once, check this box.

check-box-to-enable-or-disable-sharing-across-your-lucid-account.png

Note: The document and folder sharing setting must be enabled in order to share corporate templates with the entire account. For additional details, refer to our Create and organize corporate templates article.

Document invitation previews
If you want document invitations that users on your account send out to include a preview of the document, check this box.

check-box-to-enable-or-disable-document-invitation-previews.png

Image sharing
You can select the option to restrict Lucidchart users to share specific images or opt to have all images shared automatically.

image-sharing-options-for-lucid-team-or-enterprise-account.png

Advanced sharing enterprise-tag.png

Shareable link
This setting gives you control over whether users on your account can create shareable links to the Lucidchart documents, Lucidspark boards, and Lucidscale documents on your account. 

  • Public: Grant users the ability to generate a share link that is accessible to any user.
  • Restricted: Grant users the ability to generate a share link that will only be accessible for other users on the account.
  • Off: Disable ability for users to generate shareable links.

Customize shareable link settings at organizational group level enterprise-shield-add-on-tag.png
Using Lucid’s organizational groups, the account owner, account admins, and Shield admins can customize shareable link settings for different users within your organization. To do so, select a group from the left-hand “Organizational groups” navigation menu before adjusting the shareable link settings. For more information on the Enterprise Shield add-on, check out our Enterprise Shield add-on overview article.

advanced-sharing-for-organizational-group-settings-in-admin-panel.png

The shareable link settings will be enforced on all documents and folders owned by individuals in that organizational group.

Note: If you put a document or folder into a folder owned by a user from a different organizational group, the parent folder’s sharing permissions take precedence over the permission of the document or folder inside it.

Set a default expiration for shareable links
To set a default expiration for all newly created shareable links:

  1. Navigate to the Lucid admin panel.
  2. Expand the Security dropdown in the menu to the left and select Sharing.
  3. Scroll to the “Expiring shareable links” section.
  4. Check the box next to “Enable share link expiration” and select a time frame for all links to expire. 
    • To apply the default expiration to documents embedded in external tools (like Confluence), check the box next to “Apply to integration embeds”. With this additional setting applied, documents in external tools will no longer be accessible past the default expiration you set for shareable links. 
  5. Select Save changes in the upper-right corner.

With a default expiration set for shareable links, users can set a shorter time frame for expiration in an individual document or board, but cannot set an expiration for longer than the default you set here.

how-to-set-default-expiration-for-shareable-links-in-lucid .png

Keep in mind:

  • A default expiration applies only to share links created after the setting is enabled.
  • The default expiration setting applies to share links only. This means all collaborators who accessed the document prior to the link expiring will continue to have access to the document. To revoke access from a collaborator, you will need to unshare the document or board with them.

Note: You can also allow embedded documents owned by users on your account to persist in external apps when the embed creator no longer has edit and share access to the document. To see complete steps, scroll down to the "Publishing and embedding" section of this article.

Require passcodes to be complex
To enable or disable the requirement that shareable link passcodes be complex, follow these steps:

  1. Navigate to the Lucid admin panel.
  2. Click Security from the navigation menu on the left.
  3. Select Sharing from the options that dropdown.
  4. Scroll to the “Passcodes on shareable links” section.
  5. Check the box next to “Require passcodes to be complex”.
  6. Determine the complexity settings by requiring:
    • Upper and lowercase letters
    • Numbers
    • Special characters
    • Minimum length

Enabling this does not invalidate existing passcodes.
 

Guest Collaborator access in Lucidspark
Enable or disable the ability to generate Guest Collaborator access links for Lucidspark boards. You can also require a passcode on Guest Collaborator links. To learn more Guest Collaborators in Lucid, check out our article.

check-box-to-enable-or-disable-guest-collaborator-link-creation.png

Enable Join ID
Enable or disable the generation of a six digit Join ID code for your Lucidchart documents, Lucidspark boards, and Lucidscale documents.

check-box-to-enable-or-disable-Join-ID.png

Sharing permissions for Join ID links:

  • Public with Guest Collaborators (Lucidspark only): If your account has shareable links set to Public and has Guest Collaborator access links enabled, using Join ID will grant Guest Collaborator access to recipients. If your account has shareable links set to Public and has Guest Collaborator access links disabled, using Join ID will grant Public - Edit and Share access to recipients.
  • Public: If your account has shareable links set to Public, using Join ID will grant Public - Edit and Share access to recipients.
  • Restricted: If your account has shareable links set to Restricted, using Join ID will grant Restricted to Account - Edit and Share access to recipients.
  • Off: If your account has shareable links set to Off, Join ID will not work and will instead display an error message.

Note: If you disable Join ID, existing IDs remain valid for up to two hours before expiring.

Sharing via email 

When setting the Sharing via Email preferences for your account, you have the following options:

  • Do not restrict sharing of items via email: users will be able to share documents through email to users on any domain.
  • Warn users who share documents to emails outside given domains: a warning message will be sent to a user whenever they attempt to share a document outside the allowed domains.
  • Restrict to following domains when sharing an item via email: users will only be able to share documents with other users on allowed domains. If a user attempts to share outside of those listed they will get a notification saying that they are not allowed to do so.
Screenshot 2026-07-08 at 9.45.32 AM.png

Note: If you have opted to warn or restrict users based on shared-to domains, you will be able to input permitted domains that you would like to allow in the text box at the bottom of the “Domain Restrictions” section. If you don’t do this, everyone on your account will be warned or restricted every time they attempt to share a document. 

Accessing external documents and folders enterprise-shield-add-on-tag.png

accessing-external-documents-and-folders-admin-panel-setting.png
Choose from the following options:

  • Allow access to externally owned documents and folders (default)
  • Block access to externally owned documents and folders
  • Block access to externally owned documents and folders, except for those shared by specified domains or user emails
    • If you are going to block access to external documents and folders, we recommend that you first go into your Discovery feature and move any documents that your account owns out of externally owned folders so you do not lose access to the documents. Restoring your users’ access to externally owned folders can’t be done via the admin panel so please be careful when restricting access.
    • If you select this option, you can add up to 200 specific domains and/or email addresses to the allowlist. This gives users on your account the ability to access documents and folders owned by users or teams from the approved domain or email.

Note: If either block access option is selected, an “Enable support” checkbox will appear. Having this enabled will give Lucid the ability to share documents and folders with users on your account for support purposes. If you opt to uncheck this box, this will prevent sharing of Lucid-owned documents for support purposes.

For adding approved domains to the allowlist, please ensure you have added all relevant domains as some companies may have multiple domains associated with their account (e.g. example.co and exampleUSA.com). When adding a domain to your allowlist, we recommend working with that partner to ensure they have enabled domain control for their own Lucid account. Without domain control activated, users can create unauthorized accounts using the uncontrolled domain(s).

For additional details of the user experience based on the option you select for your account, refer to this community post.

Publishing and embedding

These settings provide the following options:

  • Allow documents owned by users on your account to be published or publicly embedded.
    • Enabling or disabling this setting doesn’t impact the embed API.
  • Allow embedded documents owned by users on your account to persist in external apps if the embed creator no longer has edit and share access to the document.
    Screenshot 2026-07-08 at 9.46.31 AM.png

Customize settings at organizational group levelenterprise-shield-add-on-tag.png
Using Lucid’s organizational groups, the account owner, account admins, and Shield admins can customize publishing and embedding settings for different users within your organization. To do so, select a group from the left-hand “Organizational groups” navigation menu before adjusting the publishing and embedding settings. For more information on the Enterprise Shield add-on, check out our Enterprise Shield add-on overview article.

Transfer document ownership settings

This setting allows you to restrict who document ownership can be transferred to. You can opt to remove all restrictions, set it so that document ownership can only be transferred among those on your Enterprise account, or set it so that document ownership cannot be transferred. To see the steps to transfer document ownership, see this article.

document-ownership-transfer-restriction-options.png

Editor experience

In this section of the admin panel, you can enable or disable the ability for users to Chat in Lucidspark, search and use images and icons, and use the standard Lucidchart template library. This is also where you can upload any brand fonts you want to make available to the users on your account. 

Chat

To enable the ability for users to chat while editing a board, check this box. Chat functionality is available in Lucidspark only.

Screenshot 2026-07-08 at 9.49.43 AM.png

Image and icon search

These settings allow you to control the following functionality:

  • Enable Brave image search to allow users to search for images.
  • Enable Giphy image search to allow users to search for GIFs.
  • Enable Noun Project search to allow users to search for icons.

Screenshot 2026-07-08 at 9.49.57 AM.png

Standard templates

Check this box to enable users to use standard Lucidchart templates. Unchecking this box will restrict users to only custom made templates, created either by you personally or by other users on your Team or Enterprise account.

Screenshot 2026-07-08 at 9.50.11 AM.png

Brand fonts

The account owner and account admins can upload brand fonts that can be used by all users on your account in Lucidchart and Lucidspark. Here’s how: 

  1. Expand the Security dropdown in the left-hand menu of the admin panel. 
  2. Click Sharing from the breakdown of left-hand menu options.
  3. Select the Editor experience tab at the top of the page.
  4. Under “Brand fonts”, click the + sign to upload a font file.
  5. Follow the prompts to upload the file.

Lucid Key Management Service (KMS) enterprise-shield-add-on-tag.png

Lucid's Key Management Service (KMS) allows businesses to control their own encryption keys for an additional layer of security. To learn more about this service, see the KMS whitepaper.

For more information on the Enterprise Shield add-on, check out our Enterprise Shield add-on overview article.

Note: As an account owner, account admin, or Shield admin, you will see the KMS menu option in the Security dropdown in the left-hand menu. If you haven’t yet enabled KMS, contact support.

If there is evidence that the key has been compromised, you can rotate your Master Key from the KMS page in the Lucid admin panel. To do so:

  1. Navigate to the KMS page in the Lucid admin panel.
  2. Select Rotate key.

User feature controls

Developer controls enterprise-tag.png

Restricting Developer controls is only available to Enterprise accounts. When you restrict access to Developer tools, users on your account cannot unlock Developer tools themselves through their Account Settings, but the account owner, account admins, and Shield admins can still assign the role manually through the Users page of the Lucid admin panel.

To see the steps and learn more, read our Developer tools in Lucid article and check out the Admin Controls section of the Lucid Development Guide.

section-of-the-lucid-admin-panel-to-restrict-access-to-developer-tools.png

Team hub access enterprise-tag.png

With Lucid’s team hub experience, account members on Enterprise accounts can organize themselves into teams for more efficient collaboration. You can control what degree of access users on your account have to this feature under “Team creation and management” as well as who can view and manage teams in the admin panel under “Team management for admins”.

team-hub-security-settings-in-admin-panel.png

Note: If an audit log event includes a hidden team, the account owner, account admins, and Shield admins can view the hidden team name in the event.

Team folder setup enterprise-tag.png

By default, all users on your Enterprise account can create team folders. To restrict team folder creation capabilities to Enterprise account admins only, follow these steps:

  1. Scroll down to the “Team Folder setup” section of the feature controls page.
  2. Select “Allow only admins to create Team Folders”.
  3. In the text box that appears, add relevant details for how users can request the creation of a team folder. 
    • For example, you may type an admin name, email, phone number, or weblink they can use for their request.
  4. Click Save changes.

Generate an account-wide support PIN  premium-tag.png

Account-wide document support PIN

Generate a temporary support PIN that allows a Lucid support agent to view all documents on your Enterprise account. This option is only available to account owners, Shield admins, and users who are both account and document admins.

To generate the document support PIN, follow these steps:

  1. Select Support PINS from the Security dropdown in the left-hand menu.
  2. In the Document Support PIN section, click Generate document support PIN.
  3. In the pop up that appears, select how long the PIN should be active.
  4. Click Generate.

You can now share the support PIN with a Lucid support agent by clicking on copy-lucid-support-pin-icon.png the copy icon on the right of the PIN so that they can assist you in troubleshooting. The PIN you generated is a temporary PIN.

Account-wide technical support PIN

Generate a temporary support PIN that allows a Lucid support agent to access any user on your account to troubleshoot issues. This option is only available to account owners, account admins, and Shield admins.

To generate the technical support PIN, follow these steps:

  1. Select Support PINS from the Security dropdown in the left-hand menu.
  2. In the Technical support PIN section, click Generate technical support PIN.
  3. In the pop up that appears, select how long the PIN should be active.
  4. Click Generate.

You can now share the support PIN with a Lucid support agent by clicking on copy-lucid-support-pin-icon.png the copy icon on the right of the PIN so that they can assist you in troubleshooting. The PIN you generated is a temporary PIN.

Any active document and technical support PINs will show in the Support PINS section from the Security dropdown. Here you can access the PIN, see the time it was created and who created the PIN, see the time remaining before the PIN expires, revoke access to an active PIN, or generate a new PIN.

generate-an-account-wide-document-and-technical-support-pin.png

Give feedback on this article

Have feedback about this article? Tell us about your experience here

Did you find what you were looking for?

Still have a question or want to share what you have learned? Visit our Community   to get help and collaborate with others.