Secure administrators and settings
Open Settings → Access & security.
Open Settings → Access & security.
Two-factor authentication
Check Require MFA for all company admins to enforce it. Each admin then sets it up at Profile → Two-factor authentication: scan a QR code with an authenticator app, then enter a code. Once enabled, an admin with no registered factor is denied sign-in.
Admin accounts
Open the Accounts tab to manage every Company Admin account on your tenant yourself. You do not need to contact Phishtime support.
- Add an admin: email, optional first and last name, and a password that meets the platform password policy. The new admin can sign in right away.
- Edit an admin's name or email.
- Send a password reset link to an admin who is locked out or has forgotten their password.
- Unlock an account that was locked after too many failed sign-ins.
- Remove an admin who no longer needs access.
Every action here affects only your own tenant. You cannot remove your own account this way (ask another admin, or contact support if you are the only one), and you cannot see or manage admins on another company's account.
Event-log retention
On the Event log retention tab, set how long Phishtime keeps individual opens, clicks, submissions, and bounces, from 1 to 60 months. After that, a daily job deletes the rows. Aggregated campaign figures (in the audit log and the summary counters) are kept. Audit-log retention is a separate setting on the same tab, from 12 to 60 months. See Audit log and data retention.
Verified domains
A campaign can only target employees whose email is on a verified domain. Open Settings → Domains & network → Verified domains, add a domain, publish the DNS TXT record shown, then click Verify. A verified domain does two things at once: you can send simulation email from it, and you can target employees whose addresses belong to it. Each domain needs its own TXT record.
Link safety in templates and landing pages
When you save a custom email template or a hand-edited landing page, Phishtime checks every link in it. This is so a compromised, rogue, or careless admin account cannot turn Phishtime's own sending infrastructure into a real phishing tool against your employees.
A link is allowed only if it is the built-in tracking link, a mailto: address, or points to one of your verified domains. Phone numbers, tel: links, and a few other risky patterns (embedded scripts, forms that post outside Phishtime) are always blocked, on any domain.
If a save is rejected, the error names the exact link or content that caused it and what to use instead, usually the tracking-link macro, or adding the domain under Verified domains first if it should be allowed.
Directory connections and SSO
The Access & security page also has a Directory connections tab, to sync employees from Microsoft Entra ID, and a Single Sign-On tab for Entra SSO (Tenant ID, Client ID, Client secret) for admin sign-in. See Configure directory synchronization.

