Announcement: Login and Account Status Improvements
October 30th
We’re updating the login and account management flow to make it clearer and more secure.
Previously, users with deactivated accounts could see a “blocked after multiple failed attempts” message and still receive password reset emails, which caused confusion.
The new workflow introduces clear, accurate messaging for each account state:
- Active – normal login and password reset behavior.
- Locked – temporary rate-limit after failed attempts, with clear guidance on how to unlock.
- Deactivated – login and reset attempts now display a direct message: “Your account is deactivated. Contact your administrator.”
Admins will also see clearer account status indicators, audit logs, and reactivation options.
These improvements ensure transparency for users, reduce confusion, and bring our authentication flow in line with best practices for both security and user experience.