Security & Sign-in Protection
DSM Version
7.4 7.3 7.2

Security & Sign-in Protection

General Security Settings

DSM provides system-level security controls.

  • Protect and encrypt data with multiple security standards.
  • Enable protection against cross-site scripting attacks.
  • Use HTTP Content Security Policy headers to accept data only from trusted sources and restrict inline script execution.
  • Prevent users from embedding DSM in other webpages using iFrames.
  • Manage multiple access profiles.

Login Settings

DSM login settings control session behavior and second-factor recovery paths.

  • Allow users to customize the automatic logout timer. By default, DSM logs users out after 15 minutes of inactivity.
  • Allow users to stay signed in from web browsers.
  • Allow users to trust devices in web browsers to skip 2-factor authentication (2FA).
  • Allow enabled users to sign in with an emergency verification code sent by email to complete 2FA.
  • Allows clearing all saved login sessions when the system restarts.

Two-Factor & Adaptive Multi-Factor Authentication

DSM supports both 2FA enforcement and Adaptive Multi-Factor Authentication (MFA) enforcement.

  • Enforce 2FA for specific users or groups.
  • Enable Adaptive MFA for all users or only users in the administrators group.
  • Only users in the administrators group can disable 2FA for regular users.
  • Email reset is disabled for users in the administrators group. Users in the administrators group must use a soft reset to remove 2FA.

Account Protection

Account Protection applies separate rules for trusted and untrusted clients.

  • Configures login attempt limits.
  • Configures attempt frequency.
  • Configures protection cancellation rules.
  • Counts failed login attempts and failed identity verification as login failures.
  • Supports adding the following services to the protection list:
    • DSM
    • Active Backup for Business Portal
    • Active Backup for Google Workspace Portal
    • Active Backup for Microsoft 365 Portal
    • Audio Station
    • Synology Calendar
    • Synology Chat
    • Synology Contacts
    • Download Station
    • File Station
    • Synology MailPlus
    • Note Station
    • Synology SSO
    • Surveillance Station
    • Mail Station
    • Synology Drive
    • Synology Photos
    • Virtual Machine Manager
    • Synology mobile applications
    • Other packages that support sign-in through a web portal
  • SSH, rsync, and FTP can be blocked but cannot be automatically added to the protection list.

Auto Block

Auto Block blocks IP addresses at the IP layer based on login failures on protected services.

  • Supports the following protected services:
    • DSM web login
    • SSH
    • Telnet
    • SMB
    • NFS
    • FTP
    • AFP
    • WebDAV
    • rsync
    • Shared Folder Sync
    • VPN
    • Mobile application access
  • Blocks an IP address after a specified number of login failures within a predefined period.
  • Supports block lists and allow lists.

Firewall

  • Supports multiple firewall rule sets, allowing separate rules to be created and managed for different network environments.
  • Filters traffic by source IP address, IP range, port, or location, with a configurable default action for unmatched traffic.
  • The GeoIP database can be updated only through DSM updates.

Certificates

  • Supports third-party or self-signed certificates.
  • Certificates must be in X.509 PEM format.
  • Private keys must be in RSA format and cannot be protected by a passphrase.
  • Let's Encrypt certificates are valid for 90 days.
  • DSM can automatically renew Let's Encrypt certificates before expiration.
  • Port 80 must be open on both the Synology NAS and the router for certificate renewal.