Security Policies

Security Policies

Full access allowed to the following roles: Server Admin, PEN Manager
The security policies determine which group new users belong too, as well as specific rules for which domains/email addresses are blocked or allowed.

New PEN members are created one of two ways: Either they create themselves by registering for a Private Email Network, or they are invited by an existing member with sufficient privileges.

Default Group for New Members
When a new member is created, he or she is placed in pre-defined group (Active or Passive). This group determines his or her privileges on the Private Email Network. Some PENs may restrict the actions of Passive members so, for example, they can only retrieve messages and not send them.

Access
Access to the PEN is defined as either Open System or Controlled Access. With an Open System, only users that are explicitly blocked in the Access List are unable to join the PEN. With Controlled Access, only users that are explicitly allowed by the Access List are able to join the PEN.

Additionally, administrators can mark a PEN as Invitation Only which means that members cannot register themselves and must be invited by an existing user with sufficient privileges. Privileges are determined by the "Can Invite" property (editable for individual users in the user information section). Administrators can also select whether or not new members have privileges to send invitations immediately after registering.

Quick Authentication
When this option is enabled, the identity confirmation process for new members will be streamlined and much easier. Quick Authentication assumes that a person that has access to a specific basic email inbox is the owner of that associated basic email address. This is a secure process, but some advanced users may want to disable Quick Authentication in order to verify identity an additional time.

Access Control List
The Access List is a collection of rules which determines whether or not a member is able to join a PEN. Either domains ("@sys-national.com") or specific email addresses ("JoeUser@sys-national.com") can be explicitly blocked or explicitly allowed.

An example of a PEN with an Open Access system, Quick Authentication enabled, and one blocked individual ("spammer@sys-national.com") is provided below.


penadmin-security
(click for full size)