CommunitySuite Portal logins give donors, grantees, fund advisors, and other external users access to the information and tools your organization shares with them. Because Portal users are external to your organization and the information they can access is sensitive, the security settings governing Portal logins should be reviewed.
Portal login password settings are configured separately from back-end user password settings. This means you can apply a security policy specifically tailored to your Portal users without affecting how your internal staff logs in. If there is no password policy for the Portal, CommunitySuite will use the user password policy in place.
Who: CommunitySuite administrators who manage donor, grantee, fund advisor, or other external Portal access.
When to Review Portal Login Security Settings
Use these Portal login security recommendations when:
- Reviewing or configuring security settings for your CommunitySuite Portal login.
- Looking to improve the security of your donor, grantee, or fund advisor portal without creating unnecessary friction for external users.
Access Portal Settings
To access Portal Settings in CommunitySuite:
- Navigate to the Portal Options page and click Portal Settings in the left-side menu.
- Click Edit in the Settings section.
- Review the password policy settings.
Customize Giving Hub and Portal Settings describes all settings available on the Portal Settings page.
Portal logins that were created before May 7, 2026 will be required to reset their passwords and meet the new requirements only once you opt to enable Password Policy within CommunitySuite Portal Settings. Review your existing Portal users before enabling a policy and consider communicating the change to them in advance.
Why Portal Login Security Requires Special Attention
Portal logins operate in a more exposed environment than back-end user accounts. Information like grantee names, fund holder names, fund names, and donor recognition is intentionally public, and that same visibility can give a bad actor a starting point for attempting to gain unauthorized Portal access.
The Email Login option is enabled by default in CommunitySuite. This allows anyone who knows a grantee's or fund advisor's email address to request a PIN and log in without a password. Because email addresses are often publicly listed, this creates a potential vulnerability that organizations should evaluate carefully.
The Email Login option allows people to access the enabled CommunitySuite Portal tabs (Donor, Grantee, Customer, etc.) without setting up logins or passwords. They simply enter the primary email address associated with a profile in CommunitySuite and receive a PIN by email to log in. This setting is on by default and should be reviewed as part of your Portal security configuration.
Security Setting Recommendations
The table below outlines three tiers of recommended security configurations for CommunitySuite Portal login settings, each building on the one before it. Review the comparison and Understand Each Portal Security Tier section that follows to determine which tier best fits your organization's needs and the sensitivity of the information your Portal users can access.
| Setting | Good | Better | Best |
|---|---|---|---|
| Disable Email Login | Yes | Yes | Yes |
| Unique Login ID (not primary email) | Yes | Yes | Yes |
| Password Policy Enabled | Yes | Yes | Yes |
| Minimum Password Length | 8 characters | 12 characters | 16 characters |
| Character Types Required | All (lower, upper, number, special) | All (lower, upper, number, special) | All (lower, upper, number, special) |
| Minimum Different Character Types | 3 | 3 | 4 |
| Minimum of Each Character Type | 1 | 1 | 1 |
| Require Two Factor Login | No | No | Yes |
| Max Failed Attempts | 5 | 4 | 3 |
| Password/Login Security Training | No | Yes | Yes |
Understand Each Portal Security Tier
The following section provides details on the three tiers of recommended security configurations.
Good: A Secure Starting Point
The Good tier disables Email Login and replaces it with unique login IDs and a password policy. This alone closes one of the most common Portal vulnerabilities. The 8-character minimum is a meaningful improvement over CommunitySuite's default 4-character minimum, and enabling all character types adds practical strength. Max failed attempts is set to 5, allowing some tolerance for external users who may be less familiar with login processes.
Better: Stronger Passwords and User Training
The Better tier raises the minimum password length to 12 characters and reduces max failed attempts to 4. It also adds a recommendation to provide training to those accessing the Portal on password and login security. This includes encouraging the use of passphrases, which combine random words into a memorable but strong password, and recommending the use of a password manager. External users typically have less security awareness than internal staff, making this training step particularly valuable.
Best: Two-Factor Login for Portal Users
The Best tier adds two-factor login as a requirement for Portal access, provides the strongest password requirements, and reduces max failed attempts to 3. This configuration is most appropriate for organizations whose Portal users can access highly sensitive information such as financial data, banking details, full fund statements, or donor records. Consider the impact on your Portal users before enabling 2FA, as it adds a step to their login process that they will need to be prepared for.
Review Portal Profile Access Settings
In addition to login security settings, it is worth reviewing what information Portal users can see and edit once they are logged in. Portal profile access is configured per tab in Portal Settings. Portal tabs contain names, addresses, emails, phone numbers, donation amounts, and downloadable reports. Review who has access to these tabs and what they are able to view and download. Access that is not needed by your Portal users should be restricted.
Email Notify on Profile Edit in the Profile tab is a recommended setting regardless of which security tier you choose. When enabled, your organization receives an email notification any time a Portal user edits their profile. This gives your team visibility into changes made in the Portal without adding friction for users. It is a low-effort setting that provides meaningful visibility into changes made through the Portal and can help your team catch unauthorized changes quickly.
Get Help from Foundant Support
The Foundant Support Team is available to help you review and configure these settings. Contact Support by email or through the chat icon at the bottom of any Foundant site.
Resources: