diff --git a/docs/get-started/account-settings-preferences.md b/docs/get-started/account-settings-preferences.md
index fb6a0902521..50c59ba8746 100644
--- a/docs/get-started/account-settings-preferences.md
+++ b/docs/get-started/account-settings-preferences.md
@@ -1,6 +1,6 @@
---
id: account-settings-preferences
-title: Setting Account Preferences and Credentials
+title: Account Preferences and Credentials
sidebar_label: Account Preferences
description: Update and manage your Sumo Logic account.
---
@@ -9,138 +9,102 @@ import useBaseUrl from '@docusaurus/useBaseUrl';
-You can review and update your personal account settings and login credentials at any time. The **Preferences** page contains settings that apply only to your account and do not affect other users in your organization.
+You can review and update your personal account settings and login credentials at any time from your user menu's three settings tabs: **Preferences**, **Personal Access Keys**, and **Personal Authorized Apps**. Settings on all three tabs apply only to your account and do not affect other users in your organization.
-## Accessing preferences
+## Accessing your account settings
-[**New UI**](/docs/get-started/sumo-logic-ui). In the top menu, select the person silhouette icon and then **Preferences**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select your username and then **Preferences**.
+* [**New UI**](/docs/get-started/sumo-logic-ui). In the top menu, select the person silhouette icon
.
+* [**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select your username at the bottom.
-
+From here, select one of the following tabs:
-## My Profile
+* **Preferences**. Your profile, security settings, and personal preferences. Covered below.
+* **Personal Access Keys**. Create and manage access keys for your own use. See [Access Keys](/docs/manage/security/access-keys#from-the-personal-access-keys-tab).
+* **Personal Authorized Apps**. View and revoke third-party apps you've authorized to access Sumo Logic on your behalf. See [Personal Authorized Apps](#personal-authorized-apps) below.
-Under **My Profile**, the following information is displayed:
+## Preferences
-* **First Name**. Your first name as it appears on your account and in the UI.
-* **Last Name**. You last name as it appears on your account and the UI.
-* **Email**. The email address associated with your account.
-* **Password**. The password you entered when activating your account. You can reset your password.
-* **Organization ID**. Your Sumo Logic org ID.
-* **Roles**. The Sumo Logic [roles](/docs/manage/users-roles/roles/add-remove-users-role/) assigned to your user account.
+The **Preferences** tab has three sections: **My Profile** (your account info and login credentials), **My Security Settings** (2-step verification), and **My Preferences** (personal settings for timezone, navigation, search, and alerts).
-
+### My Profile
-If you're an Administrator, you can [manage users](/docs/manage/users-roles/users/), [assign roles](/docs/manage/users-roles/roles), and more.
+Under **My Profile**, the following information is displayed:
+
+* **First Name**. Your first name as it appears on your account and in the UI.
+* **Last Name**. Your last name as it appears on your account and in the UI.
+* **Email**. The Sumo Logic account email address ([you can change this](#change-email-address)).
+* **Password**. Your Sumo Logic account password ([you can change this](#change-password)).
+* **Organization ID**. Your organization's unique identifier in Sumo Logic.
+* **Roles**. The Sumo Logic [roles](/docs/manage/users-roles/roles/add-remove-users-role/) assigned to your user account. If you're an Administrator, you can [manage users](/docs/manage/users-roles/users/), [assign roles](/docs/manage/users-roles/roles), and more.
-### Change email address
+#### Change email address
-1. Access your [Preferences](#accessing-preferences).
+1. Access your [account settings](#accessing-your-account-settings) and select the **Preferences** tab.
1. Under **My Profile**, click **Change Email**.
1. In the dialog that appears, enter your new email address and follow the verification steps.
-### Change password
+#### Change password
-1. Access your [Preferences](#accessing-preferences).
+1. Access your [account settings](#accessing-your-account-settings) and select the **Preferences** tab.
1. Under **My Profile**, click **Change Password**.
1. Enter your current password, and then enter the new password twice to verify it.
1. Click **OK** to finalize the change.
-You can also reset your from your login screen by clicking **Forgot your password?**.
+You can also reset your password from your login screen by clicking **Forgot your password?**.
If you're an Administrator, you can [reset passwords](/docs/manage/users-roles/users/reset-user-password) for users in your org.
-## My Security Settings
-
-This section allows you to enable 2-step verification and view backup codes.
+### My Security Settings
:::note
-The **My Security Settings** section is visible only if an administrator has made 2-step verification mandatory for your organization. For more details, see [2-Step Verification for Administrators](/docs/manage/security/2-step-verification-admins).
+The **My Security Settings** section is visible only if an administrator has made 2-Step Verification mandatory for your organization. For more details, see [2-Step Verification for Administrators](/docs/manage/security/2-step-verification-admins).
:::
-To set up 2-Step Verification, you will need to install a Time-Based One-Time Password (TOTP) app, which will automatically generate an authentication code that changes after a certain period of time.
-
-1. Download one of the following apps:
- - For Android, iOS and Blackberry: [Google Authenticator](https://support.google.com/accounts/answer/1066447?hl=en).
- - For Android and iOS: [Duo Mobile](https://duo.com/product/trusted-users/two-factor-authentication/duo-mobile).
- - For Windows Phone: [Authenticator](https://www.microsoft.com/en-us/store/p/authenticator/9wzdncrfj3rj).
-1. Scan the QR code displayed on your screen with your TOTP app.
-1. After the TOTP app is configured, enter two consecutive authentication codes.
+Set up 2-Step Verification using a TOTP (Time-Based One-Time Password) app, view or regenerate your backup codes, change your verification device, or disable 2-Step Verification if it's optional for your org. See [2-Step Verification for Users](/docs/manage/security/2-step-verification-users) for the full walkthrough.
-## My Preferences
+### My Preferences
These settings apply only to your personal account and do not affect other users in your organization. Changes take effect the next time you sign in.
-
-
-### Timezone and Date Format
-
-#### Default Timezone
-
-If you want the Sumo Logic user interface to use your local time zone, or a time zone different from the time zone used in the timestamp of your log messages, change the setting here. This is a personal setting, and does not change the time zone for anyone else in your organization.
-
-This option overrides the timezone set in your web browser, and affects all hours and minutes displayed in the user interface, including time ranges on the Search page, the Time column in the Messages pane, and in Dashboards. It does not affect the configurations of previously created Scheduled Searches. For more information, see [Timestamps, Time Zones, Time Ranges, and Date Formats](/docs/send-data/reference-information/time-reference).
-
-#### Always show the timezone offset in displayed timestamps
-
-This setting is enabled by default. To not show the timezone offset in displayed timestamps, deselect this checkbox.
-
-#### Date format
-
-Select from the following international date format options:
-
-* Use the browser's default date format.
-* MM/DD/YYYY (04/22/2015)
-* DD/MM/YYYY (22/04/2015)
-* YYYY/MM/DD (2015/04/22)
-
-:::danger
-Changing the date format option will affect your saved searches in the Library. Any saved searches that use absolute dates for their time range must be updated to reflect the new format. Scheduled Searches will continue to run as expected, but you will need to modify the date format if you reschedule a search.
-:::
-
-### General Settings
-
-#### Receive email notifications whenever content is shared with you
-
-Receive an email when [content is shared with you in Sumo Logic](/docs/manage/content-sharing/), such as log searches, metric searches, dashboards, and folders.
-
-#### Enable keyboard shortcuts
-
-[Keyboard shortcuts](/docs/get-started/keyboard-shortcuts) are enabled by default. Press **?** to see the list of shortcuts. To disable keyboard shortcuts, for example, if they conflict with an international keyboard, deselect the checkbox.
-
-:::note
-Keyboard shortcuts are disabled when typing in the [search text box](/docs/search/get-started-with-search/search-page/).
-:::
-
-### Web Session Timeout
+#### Timezone and Date Format
-Choose how long your Sumo Logic session remains active before timing out. Options range from 5 minutes to 7 days.
+* **Default Timezone**. Change this setting if you want the Sumo Logic user interface to use your local time zone, or one different from the time zone in your log message timestamps. This is a personal setting; it doesn't change the time zone for anyone else in your organization. This option overrides the timezone set in your web browser, and affects all hours and minutes displayed in the user interface, including time ranges on the Search page, the Time column in the Messages pane, and in Dashboards. It does not affect the configurations of previously created Scheduled Searches. For more information, see [Timestamps, Time Zones, Time Ranges, and Date Formats](/docs/send-data/reference-information/time-reference).
+* **Always show the timezone offset in displayed timestamps**. This setting is enabled by default. Deselect this checkbox to hide the timezone offset in displayed timestamps.
+* **Date format**. Select from the following international date format options:
+ * Use the browser's default date format.
+ * MM/DD/YYYY (04/22/2026)
+ * DD/MM/YYYY (22/04/2026)
+ * YYYY/MM/DD (2026/04/22)
+ :::danger
+ Changing the date format option will affect your saved searches in your [Library](/docs/get-started/library/). Any saved searches that use absolute dates for their time range must be updated to reflect the new format. [Scheduled Searches](/docs/alerts/scheduled-searches/) will continue to run as expected, but you will need to modify the date format if you reschedule a search.
+ :::
-For details on web session timeouts and multi-account access, see [Multi-Account Access](/docs/manage/users-roles/users/multi-account-access).
+#### General Settings
+* **Receive email notifications whenever content is shared with you**. Receive an email when [content is shared with you in Sumo Logic](/docs/manage/content-sharing/), such as log searches, metric searches, dashboards, and folders.
+* **Enable keyboard shortcuts**. [Keyboard shortcuts](/docs/get-started/keyboard-shortcuts) are enabled by default. Press **?** to see the list of shortcuts. To disable keyboard shortcuts, for example, if they conflict with an international keyboard, deselect the checkbox.
+ :::note
+ Keyboard shortcuts are disabled when typing in the [search text box](/docs/search/get-started-with-search/search-page/).
+ :::
+* **Web Session Timeout**. Choose how long your Sumo Logic session remains active before timing out. Options range from 5 minutes to 7 days. For details on web session timeouts and multi-account access, see [Multi-Account Access](/docs/manage/users-roles/users/multi-account-access).
-### Navigation
+#### Navigation
-#### Open all navigation menu items in new browser tabs by default
+* **Open all navigation menu items in new browser tabs by default**. This preference is disabled by default, so selecting a menu link in the left navigation pane opens it in the same tab. To open a specific link in a new tab instead, hover over it and click the **Open in New Tab** button that appears next to it.
Enabling this preference makes every menu link open in a new tab automatically, and hides the **Open in New Tab** button since it's no longer needed. However, even when this preference is enabled, the **Open in New Tab** button remains visible for menu items with subfolders, allowing you to click the menu item to view its subfolders and open them in a new tab.
-By default, selecting a menu link in the left navigation pane opens it in a new tab.
-
-Enabling this preference hides the **Open in New Tab** button on navigation menu links.
-
-However, even when this preference is enabled, the **Open in New Tab** button remains visible for menu items with subfolders, allowing you to click the menu item to view its subfolders and open them in a new tab.
-
-### Default Starting Page
+#### Default Starting Page
Select the default page to appear when you log in to Sumo Logic. This preference applies only to users of the [**New UI**](/docs/get-started/sumo-logic-ui).
-### Theme
+#### Theme
-Select to show the user interface in a **Dark theme** or **Light theme**.
+Choose whether the user interface displays in **Dark theme** or **Light theme**.
[**New UI**](/docs/get-started/sumo-logic-ui). Dark and Light theme support is available across the Sumo Logic Log Analytics Platform. You can select your preferred theme in **Account Preferences**, or use the global theme button in the top toolbar, located adjacent to the **Go to...** button, to switch themes instantly from anywhere in the platform.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). Select between **Light** or **Dark** mode in the **Account Preferences** page. This setting applies only to the user interface in the [Automation Service](/docs/platform-services/automation-service/), [Cloud SIEM](/docs/cse/), and [Cloud SOAR](/docs/cloud-soar/). A global setting is not supported at this time. You can also apply a [dark theme specifically for dashboards](/docs/dashboards/about/#dark-theme).
-### Query Editing
+#### Query Editing
Select how you want to execute and format queries:
@@ -149,45 +113,43 @@ Select how you want to execute and format queries:
After making any changes, click **Save**.
-### Log Search
-
-#### Show confirmation dialog when closing a tab
-
-On the Search page, enable this option if you want to be prompted with a confirmation dialog before you can close a search tab.
-
-#### Enable autocomplete
-
-Keep this option selected to automatically open the search autocomplete dialog when editing a query.
-
-* To manually open the dialog, use `` or `` ``.
-* Deselect this option to disable [search autocomplete](/docs/search/get-started-with-search/search-basics/search-autocomplete).
-
-#### Automatically run the search after selecting it from a list of saved searches
+#### Log Search
-By default, saved searches run automatically when selected. Deselect this option if you prefer to start searches manually.
+* **Show confirmation dialog when closing a tab**. On the Search page, enable this option if you want to be prompted with a confirmation dialog before you can close a search tab.
+* **Show search autocomplete suggestions while typing**. Keep this option selected to automatically open the search autocomplete dialog when editing a query.
+ * To manually open the dialog, use `` or `` ``.
+ * Deselect this option to disable [search autocomplete](/docs/search/get-started-with-search/search-basics/search-autocomplete).
+* **Automatically run the search after selecting it from a list of saved searches**. By default, saved searches run automatically when selected. Deselect this option if you prefer to start searches manually.
+* **Enable in-app tabs for Logs Search**. Select this checkbox to enable in-app tabs in the [**New UI**](/docs/get-started/sumo-logic-ui), letting you run and manage multiple searches within a single Log Search window instead of separate browser tabs. Keep long-running or reference searches open while you switch between other queries, and compare results across searches without losing context. To use in-app tabs, open a new tab within Log Search and run a query in each one. Switch between tabs at any time, reorder them by dragging, and scroll horizontally when you have more tabs open than fit on screen.
-#### Enable in-app tabs for Logs Search
+#### Alerts
-Select this checkbox to enable in-app tabs, allowing you to run and manage multiple searches within a single Log Search window in the [**New UI**](/docs/get-started/sumo-logic-ui). This feature makes it easier to work on multiple investigations side by side without relying on separate browser tabs. You can keep long-running or reference searches open, switch between queries without losing context, and compare results across searches more efficiently, helping streamline troubleshooting and analysis workflows.
+Click any of the following checkboxes to enable your desired preferences:
-To use this feature, open a new tab directly within Log Search and run a new or existing query in each tab. You can switch between tabs at any time to continue your analysis, reorder tabs using drag-and-drop, and scroll horizontally to navigate across multiple open tabs. This helps you stay organized while working across related searches or datasets.
+* **Enable ingestion throttling notifications**. Only users with Administrator access can enable this option. Select this to be notified when your organization's logs, metrics, or traces ingestion is throttled. See [Ingestion - Throttling Limits](/docs/manage/manage-subscription/organization-usage-limits/#ingestion---throttling-limits) for details on baseline and throttling limits.
+* **Display alert badge when my subscribed monitors are triggered**. Select this option to display a badge icon in the UI when you receive an alert for a monitor you're subscribed to.
+* **Notify about only subscribed monitors**. Select this option to receive notifications only for monitors you're subscribed to.
+* **Enable "Active alerts only" as default filter**. By default, your alerts list only displays alerts with an active status. Alerts with a resolved status are excluded.
+* **Enable "My subscriptions" as default filter**. By default, alerts you are subscribed to will appear in your alerts list.
-### Alerts
+## Personal Access Keys
-Click any of the following checkboxes to enable your desired preferences:
+The **Personal Access Keys** tab lets you create and manage access keys for your own use — to register Collectors, authenticate API requests, or authorize scripts and automation. Keys you create here use your own permissions, and are visible only to you; an administrator (or an Analyst with the Manage Access Keys role capability) can see keys created by everyone in your org from the separate, org-wide **Access Keys** tab under **Administration**.
-#### Display alert badge when my subscribed monitors are triggered
+For the full walkthrough, including CORS domain restrictions, scopes, and how to edit, rotate, or delete a key, see [Access Keys](/docs/manage/security/access-keys/#from-the-personal-access-keys-tab).
-Select this option to display a badge icon in the UI when you receive an alert for a monitor you're subscribed to.
+## Personal Authorized Apps
-#### Notify about only subscribed monitors
+The **Personal Authorized Apps** tab lists third-party apps and OAuth clients you've personally authorized to access Sumo Logic on your behalf, such as AI clients connecting through [OAuth 2.0](/docs/manage/security/oauth). Revoking an app here does not affect other users who have separately authorized it.
-Select this option to receive notifications only for monitors you're subscribed to.
+{/* TODO: add screenshot of the Personal Authorized Apps list view */}
-#### Enable "Active alerts only" as default filter
+The list shows each app's name, when you authorized it, and when it was last used. Click an app to see its details:
-By default, your alerts list only displays alerts with an active status. Alerts with a resolved status are excluded.
+* **Scopes**. The permissions granted to the app, grouped by category (for example, Alerting, Dashboards, Log Search), with a count of permissions in each category. Expand a category to see its individual scopes.
+* **Last Used**. The most recent time the app used its authorization to access Sumo Logic.
+* **Authorized By** and **Authorized At**. Who authorized the app, and when.
-#### Enable "My subscriptions" as default filter
+{/* TODO: add screenshot of the app detail pane with Scopes and Revoke button */}
-By default, alerts you are subscribed to will appear in your alerts list.
+To revoke an app's access, select it from the list and click **Revoke**. This immediately invalidates the app's ability to act on your behalf; you can re-authorize it later if needed.
diff --git a/docs/manage/security/access-keys.md b/docs/manage/security/access-keys.md
index af810f15954..f4ce67d30bf 100644
--- a/docs/manage/security/access-keys.md
+++ b/docs/manage/security/access-keys.md
@@ -28,6 +28,16 @@ Watch this micro lesson to learn about access keys.
/>
:::
+## Prerequisites
+
+* You'll need the [**Create Access Keys** role capability](/docs/manage/users-roles/roles/role-capabilities#security) to create an access key.
+* You'll need the [**Manage Access Keys** capability](/docs/manage/users-roles/roles/role-capabilities#security) to manage access keys created by other users in your org.
+* Access keys use the permissions of the user running the key. The user utilizing an access key must have the [role capabilities](/docs/manage/users-roles/roles/role-capabilities) needed to execute the tasks the access key is needed for.
+
+## Create an access key
+
+You can create an access key from any of the following places: your own [Personal Access Keys tab](#from-the-personal-access-keys-tab), the org-wide [Access Keys tab](#from-the-access-keys-tab), or a [service account](#from-a-service-account).
+
:::training Micro Lesson
Watch this micro lesson to learn how to create access keys.
@@ -44,35 +54,25 @@ Watch this micro lesson to learn how to create access keys.
/>
:::
-
-
-## Prerequisites
-
-* You'll need the [**Create Access Keys** role capability](/docs/manage/users-roles/roles/role-capabilities#security) to create an access key.
-* You'll need the [**Manage Access Keys** capability](/docs/manage/users-roles/roles/role-capabilities#security) to manage access keys created by other users in your org.
-* Access keys use the permissions of the user running the key. The user utilizing an access key must have the [role capabilities](/docs/manage/users-roles/roles/role-capabilities) needed to execute the tasks the access key is needed for.
-
-## Create an access key
-
### From the Personal Access Keys tab
-A *personal access key* is a key that you can create to manage access for personal use.
+A *personal access key* is a key that you can create to manage access for personal use.
:::tip
-If you are an administrator who needs to create an access key for system use (such as for API scripts, third party integrations, or infrastructure as code), we recommend you create the access key on a [service account](#from-a-service-account).
+If you are an administrator who needs to create an access key for system use (such as for API scripts, third party integrations, or infrastructure as code), we recommend you create the access key on a [service account](#from-a-service-account).
:::
1. [**New UI**](/docs/get-started/sumo-logic-ui). In the top menu select your username, and then select **Personal Access Keys**. You can also click the **Go To...** menu at the top of the screen and select **Personal Access Keys**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select your username and then **Personal Access Keys**.
1. On the **Personal Access Keys** tab, click **+ Add Access Key**.
1. The **Add New Access Key** window appears.
1. **Name**. Enter a name for your access key.
- 1. **Allowed CORS Domains (optional)**. Create an allowlist of domains from which the access key can be used to access Sumo Logic APIs. For more information, see [CORS support](#cors-support).
+ 1. **Allowed CORS Domains (optional)**. Create an allowlist of domains from which the access key can be used to access Sumo Logic APIs. For more information, see [CORS support](#cors-support).
:::note
Enter the domains in the [Origin format](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Origin) described in Mozilla help. The URL pattern must include the HTTPS protocol and a domain name. A port is optional.
:::
1. **Scopes**. For additional security, you can select scopes to give the key only the permissions you specify.
:::note
- The user who will be utilizing the access key needs to have all the same [role capabilities](/docs/manage/users-roles/roles/role-capabilities) as the scopes on the access key. Otherwise, once the user views the access key details, the scopes will be displayed as red in the UI red with a message that the user does not have rights for those scopes.
+ The user who will be utilizing the access key needs to have all the same [role capabilities](/docs/manage/users-roles/roles/role-capabilities) as the scopes on the access key. Otherwise, once the user views the access key details, the scopes will be displayed in red in the UI, with a message that the user does not have rights for those scopes.
:::
Select the scopes for the key:
* **Default**. The key has all permissions.
@@ -83,15 +83,17 @@ If you are an administrator who needs to create an access key for system use (su
After you click **Done**, you will not be able to recover this access ID and access key.
:::
-All personal access keys created in the organization are displayed in the **Access Keys** tab, described next.
+All personal access keys created in the organization are displayed in the **Access Keys** tab, described next.
### From the Access Keys tab
-The **Access Keys** tab shows all access keys in the system. It provides a central place for administrators to manage access keys.
+Unlike the [Personal Access Keys tab](#from-the-personal-access-keys-tab) (your own keys) or a [service account](#from-a-service-account) (a specific service account's keys), the **Access Keys** tab spans your entire organization: every personal and service account key created by anyone in your org. It's the central place to view and manage every key in the org, and administrators can also create new keys directly from here.
-Administrators can create access keys under **Access Keys** as an alternative to doing it [from the Personal Access Keys tab](#from-the-personal-access-keys-tab) or [from a service account](#from-a-service-account).
+:::note
+This tab is visible only to Administrators, or Analysts (non-admins) with the [Manage Access Keys role capability](/docs/manage/users-roles/roles/role-capabilities#security). Other users only see their own keys under [Personal Access Keys](#from-the-personal-access-keys-tab).
+:::
-1. [**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Administration**, and then under **Account Security Settings** select **Access Keys**. You can also click the **Go To...** menu at the top of the screen and select **Access Keys**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Administration > Security > Access Keys**.
+1. [**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Administration**, and then under **Account Security Settings** select **Access Keys**. You can also click the **Go To...** menu at the top of the screen and select **Access Keys**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Administration > Security > Access Keys**.
1. At the top right of the table, click **+ Add Access Key**.
1. Follow the steps in [From the Personal Access Keys tab](#from-the-personal-access-keys-tab) section above, starting with step 3.
@@ -99,12 +101,12 @@ Administrators can create access keys under **Access Keys** as an alternative to
Administrators can create access keys on a service account for use in scripts or automation. For more information, see [Service Accounts](/docs/manage/security/service-accounts).
-1. [**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Administration**, and then under **Account Security Settings** select **Service Accounts**. You can also click the **Go To...** menu at the top of the screen and select **Service Accounts**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Administration > Security > Service Accounts**.
+1. [**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Administration**, and then under **Account Security Settings** select **Service Accounts**. You can also click the **Go To...** menu at the top of the screen and select **Service Accounts**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Administration > Security > Service Accounts**.
1. Select a service account.
1. Click **Add Access Key**.
1. Follow the steps in [From the Personal Access Keys tab](#from-the-personal-access-keys-tab) section above, starting with step 3.
-#### CORS support
+### CORS support
Sumo Logic supports cross-origin resource sharing (CORS), a mechanism that uses additional HTTP headers to tell a browser to let a web application running at one origin (domain) have permission to access selected resources from a server at a different origin. When you create an access key, you can optionally define an allowlist of domains that may access Sumo Logic APIs using that access key.
@@ -124,64 +126,64 @@ Sumo Logic accepts:
When Sumo Logic accepts a request, the response includes the ORIGIN header in
an Access-Control-Allow-Origin header.
-## Edit, activate/deactivate, rotate, or delete access keys
+## Edit, deactivate/activate, rotate, or delete access keys
### Personal access keys
-1. [**New UI**](/docs/get-started/sumo-logic-ui). In the top menu select your username, and then under **Preferences** select **Personal Access Keys**. You can also click the **Go To...** menu at the top of the screen and select **Personal Access Keys**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select your username and then **Preferences > Personal Access Keys**.
-1. Hover your mouse over an access key and click the three-dot icon to reveal the modification options:
+1. [**New UI**](/docs/get-started/sumo-logic-ui). In the top menu select your username, and then under **Preferences** select **Personal Access Keys**. You can also click the **Go To...** menu at the top of the screen and select **Personal Access Keys**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select your username and then **Preferences > Personal Access Keys**.
+1. Hover your mouse over an access key and click the three-dot kebab icon to reveal the modification options:
* **Edit**. Opens up a window where you can modify the allowlist for your access key.
- * **Activate/Deactivate**. Depending on the current status of your access key, you'll see either an **Activate** or **Deactivate** option. If you deactivate an access key, Sumo Logic will retain the key credentials, but render the key useless. By default, Sumo Logic will deactivate an access key if it has gone unused for more than 30 days, though the [access keys deactivation policy](#access-keys-deactivation-policy) can be updated by a Sumo Logic administrator. You can reactivate a key at any time to begin using it again.
+ * **Deactivate/Activate**. Deactivates or activates an access key. When you deactivate, Sumo Logic will retain the key credentials, but render the key useless. By default, Sumo Logic will deactivate an access key if it has gone unused for more than 30 days, though the [access keys deactivation policy](#access-keys-deactivation-policy) can be updated by a Sumo Logic administrator. You can reactivate a key at any time to begin using it again.
:::note
After an access key is deactivated, there can be a brief period of time during which a previous successful authentication remains cached and a subsequent API request using the deactivated key will succeed. This could occur if the access key was used to authenticate within 15 minutes prior to the key being deactivated.
:::
- * **Rotate**. Refresh an access key with a new access ID and access key. Copy the new ID and key and use them in all the places where the previous access key was used. (The old key is still usable for 5 minutes after rotation.) Rotate access keys in accordance with your company's rules. By default, access keys are set to never expire after creation or rotation, though the [access keys expiration policy](#access-keys-expiration-policy) can be updated by a Sumo Logic administrator. An access key's expiration date appears in the **Expires At** column.
- * **Delete**. Permanently removes the access key. The key will no longer be usable for API calls. However, deleting a key used to register a collector does not affect the collector, since the only time a collector uses the access key is at installation.
+ * **Rotate**. Refreshes an access key with a new access ID and access key. Copy the new ID and key and use them in all the places where the previous access key was used. (The old key is still usable for 5 minutes after rotation.) Rotate access keys in accordance with your company's rules. By default, access keys are set to never expire after creation or rotation, though the [access keys expiration policy](#access-keys-expiration-policy) can be updated by a Sumo Logic administrator. An access key's expiration date appears in the **Expires At** column.
+ * **Delete**. Removes an access key permanently. The key will no longer be usable for API calls. However, deleting a key used to register a collector does not affect the collector, since the only time a collector uses the access key is at installation.
### Organization access keys
-If you have the [**Manage Access Keys** role capability](/docs/manage/users-roles/roles/role-capabilities#security), you can edit, deactivate, and delete any access keys created by other users in your organization.
+If you're an Administrator, or an Analyst with the [Manage Access Keys role capability](/docs/manage/users-roles/roles/role-capabilities#security), you can edit, deactivate, and delete any access keys created by other users in your organization.
+
+1. [**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Administration**, and then under **Account Security Settings** select **Access Keys**. You can also click the **Go To...** menu at the top of the screen and select **Access Keys**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Administration > Security > Access Keys**.
+1. Hover your mouse over an access key and click the three-dot kebab icon. This reveals the same modification options that appear in [Personal Access Keys](#personal-access-keys).
-1. [**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Administration**, and then under **Account Security Settings** select **Access Keys**. You can also click the **Go To...** menu at the top of the screen and select **Access Keys**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Administration > Security > Access Keys**.
-1. Hover your mouse over an access key and click the three-dot kebab icon. This reveals the same modification options that appear on the **Personal Access Key** page, [as described above](#edit-activatedeactivate-rotate-or-delete-access-keys).
+## Access key policies
+
+Administrators can configure org-wide defaults for when access keys are automatically deactivated or expire.
### Access keys deactivation policy
-To enhance the security of your account, Sumo Logic will by default automatically deactivate access keys that haven’t been used for 30 days or more. As an extra security measure, deactivating an access key that has gone unused will ensure that forgotten keys cannot be used later to access your account.
+By default, Sumo Logic automatically deactivates access keys that haven’t been used for 30 days or more. However, you can adjust the number of days before deactivation. This extra security measure ensures forgotten keys can't be used later to access your account.
-An administrator can adjust the limit to the number of days an access key can go unused before being automatically deactivated. To configure this option, you must be a Sumo Logic administrator or have the **Manage organization settings** role capability.
+:::note
+This section is visible only to Administrators, or Analysts (non-admins) with the **Manage Organization Settings** role capability.
+:::
To configure the access keys deactivation policy:
-1. [**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Administration**, and then under **Account Security Settings** select **Policies**. You can also click the **Go To...** menu at the top of the screen and select **Policies**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Administration > Security > Policies**.
-1. Under the **Access Keys Deactivation** section, select a value in the **No. of Days** field.
-
- :::note
- This section is visible to administrators only.
- :::
+1. [**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Administration**, and then under **Account Security Settings** select **Policies**. You can also click the **Go To...** menu at the top of the screen and select **Policies**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Administration > Security > Policies**.
+1. Under the **Access Keys Deactivation** section, select a value in the **No. of Days** field.
### Access keys expiration policy
-By default, access keys are set to never expire. However, an administrator can use the **Access Keys Expiration** policy to set access keys to expire after a set period. Automatically expiring keys ensures they don't remain in use past your company's access key rotation rules.
+By default, access keys are set to never expire. However, you can use the **Access Keys Expiration** policy to set access keys to expire after a set time period. Automatically expiring keys ensures they don't remain in use past your company's access key rotation rules.
-An access key's expiration date appears in the **Expires At** column on the **Access Keys** tab. You can sort by this column to see when you must rotate keys. To rotate a key, hover your mouse over an access key, click the three-dot kebab icon, and select **Rotate**. (The old key is still usable for 5 minutes after rotation.) Rotating an access key resets its expiration date according to the number of days in the policy.
+:::note
+This section is visible only to Administrators, or Analysts (non-admins) with the **Manage Organization Settings** role capability.
+:::
-An administrator can adjust the time period before access keys expire. To configure this option, you must be a Sumo Logic administrator or have the **Manage organization settings** role capability.
+An access key's expiration date appears in the **Expires At** column on the **Access Keys** tab. You can sort by this column to see when you must rotate keys. To rotate a key, hover your mouse over an access key, click the three-dot kebab icon, and select **Rotate**. (The old key is still usable for 5 minutes after rotation.) Rotating an access key resets its expiration date according to the number of days in the policy.
To configure the access keys expiration policy:
-1. [**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Administration**, and then under **Account Security Settings** select **Policies**. You can also click the **Go To...** menu at the top of the screen and select **Policies**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Administration > Security > Policies**.
-1. Under the **Access Keys Expiration** section, select a value in the **Expiration** field.
-
- :::note
- This section is visible to administrators only.
- :::
+1. [**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Administration**, and then under **Account Security Settings** select **Policies**. You can also click the **Go To...** menu at the top of the screen and select **Policies**.
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Administration > Security > Policies**.
+1. Under the **Access Keys Expiration** section, select a value in the **Expiration** field.
- :::warning
- When you change the policy, all access keys inherit the new policy, and the expiration date for all access keys is reset. For example, if you change the policy to 90 days, then the expiration date is reset on all access keys to 90 days from the date the policy was changed.
- :::
+:::warning
+If you change your access keys expiration policy, all access keys inherit the new policy, and the expiration date for all access keys is reset. For example, if you change the policy to 90 days, then the expiration date is reset on all access keys to 90 days from the date the policy was changed.
+:::
## Audit logging for access key activity
-Access key events are recorded in the Audit Event Index. To search for for access key events, run this query:
+Access key events are recorded in the Audit Event Index. To search for access key events, run this query:
```sumo
_index=sumologic_audit_events _sourceCategory=accessKeys
diff --git a/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/deploy-multiple-accounts-regions.md b/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/deploy-multiple-accounts-regions.md
index 0bf339223e4..49aee489dc9 100644
--- a/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/deploy-multiple-accounts-regions.md
+++ b/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/deploy-multiple-accounts-regions.md
@@ -40,7 +40,7 @@ The below table displays the response to each prompt during Step 2.
| Sumo Logic Deployment Name | Enter au, ca, ch, de, esc, eu, jp, us2, fed, kr, or us1. See [Sumo Logic endpoints by deployment and firewall security](/docs/api/about-apis/getting-started/#sumo-logic-endpoints-by-deployment-and-firewall-security) for more information on Sumo Logic deployments. |
| Sumo Logic Access ID | Sumo Logic Access ID. See [Create an access key](/docs/manage/security/access-keys/#create-an-access-key) for more information. |
| Sumo Logic Access Key | Sumo Logic Access Key. This key is used for Sumo Logic API calls. |
-| Sumo Logic Organization ID | You can find your org on the [Preferences](/docs/get-started/account-settings-preferences/#accessing-preferences) page in the Sumo Logic UI. Your org ID will be used to configure the IAM Role for Sumo Logic AWS Sources. |
+| Sumo Logic Organization ID | You can find your org on the [Preferences](/docs/get-started/account-settings-preferences/#accessing-your-account-settings) page in the Sumo Logic UI. Your org ID will be used to configure the IAM Role for Sumo Logic AWS Sources. |
| Delete Sumo Logic Resources when stack is deleted | To delete collectors, sources and apps in Sumo Logic when the stack is deleted, set this parameter to "True". If this is set to "False", Sumo Logic resources are not deleted when the AWS CloudFormation stack is deleted. Deletion of updated resources will be skipped. |
## Step 3: AWS account alias
diff --git a/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/index.md b/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/index.md
index 0a2213d1245..6a8cef01db4 100644
--- a/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/index.md
+++ b/docs/observability/aws/deploy-use-aws-observability/deploy-with-aws-cloudformation/index.md
@@ -63,7 +63,7 @@ The table below displays the response for each text box in this section.
| Sumo Logic Deployment Name | Enter au, ca, ch, de, esc, eu, jp, us2, fed, kr, or us1. See [Sumo Logic endpoints by deployment and firewall security](/docs/api/about-apis/getting-started/#sumo-logic-endpoints-by-deployment-and-firewall-security) for more information on Sumo Logic deployments. |
| Sumo Logic Access ID | Sumo Logic Access ID. See [Access Keys](/docs/manage/security/access-keys) for more information. |
| Sumo Logic Access Key | Sumo Logic Access Key. This key is used for Sumo Logic API calls. |
-| Sumo Logic Organization ID | You can find your org on the [Preferences](/docs/get-started/account-settings-preferences/#accessing-preferences) page in the Sumo Logic UI. Your org ID will be used to configure the IAM Role for Sumo Logic AWS Sources. |
+| Sumo Logic Organization ID | You can find your org on the [Preferences](/docs/get-started/account-settings-preferences/#accessing-your-account-settings) page in the Sumo Logic UI. Your org ID will be used to configure the IAM Role for Sumo Logic AWS Sources. |
| Delete Sumo Logic Resources when stack is deleted | To delete collectors, sources, and apps in Sumo Logic when the stack is deleted, set this parameter to "True". If this is set to "False", Sumo Logic resources are not deleted when the AWS CloudFormation stack is deleted. Deletion of updated resources will be skipped. |
| Send telemetry to Sumo Logic | To send solution telemetry to Sumo Logic. This will help to troubleshoot the issues occurring during solution installation. To opt-out, change this to `false`. The default value is `true`. |
@@ -235,7 +235,7 @@ Below are some common errors that can occur while using the CloudFormation templ
| The API rate limit for this user has been exceeded. | This error indicates that AWS CloudFormation execution has exceeded the API rate limit set on the Sumo Logic side. It can occur if you install the AWS CloudFormation template in multiple regions or accounts using the same Access Key and Access ID. | - Re-deploy the deployment stack without updating the stack in the template. Re-running will detect the drift and create remaining resources.
- If the throttling problem persists, try to break down the multi-region deployment into parts and use distinct access IDs and access keys for each part. |
| S3 Bucket already exists. | The error can occur if:
- An S3 bucket with the same name exists in S3, or
- The S3 Bucket is not present in S3 but is referenced by some other AWS CloudFormation stack that created it. | - Remove the S3 bucket from S3 or select “No” in the AWS CloudFormation template for S3 bucket creation.
- Remove the AWS CloudFormation Stack which references the S3 bucket. |
| The S3 bucket you tried to delete is not empty. | The error can occur when deleting the stack with a non-empty S3 bucket. | Delete the S3 bucket manually if you do not need the bucket or its content in the future. |
-| Invalid IAM role OR AccessDenied. | This error can occur when Sumo Logic access keys are disabled or do not have the required permissions. | - Refer to [Edit, activate/deactivate, rotate, or delete access keys](/docs/manage/security/access-keys/#edit-activatedeactivate-rotate-or-delete-access-keys) for access keys activation.
- Refer to [Role capabilities](/docs/observability/aws/deploy-use-aws-observability/before-you-deploy/#prerequisites) for permissions related issues. |
+| Invalid IAM role OR AccessDenied. | This error can occur when Sumo Logic access keys are disabled or do not have the required permissions. | - Refer to [Edit, deactivate/activate, rotate, or delete access keys](/docs/manage/security/access-keys/#edit-deactivateactivate-rotate-or-delete-access-keys) for access keys activation.
- Refer to [Role capabilities](/docs/observability/aws/deploy-use-aws-observability/before-you-deploy/#prerequisites) for permissions related issues. |
| Subscription filters are not applied to newly created log groups. | This error can occur when CloudTrail is not enabled for EventBridge to capture `CreateLogGroup` events. | CloudTrail must be enabled for EventBridge to capture `CreateLogGroup` events, since these events are recorded and delivered through CloudTrail. |
| Access logs are not enabled for the Load Balancer. | This error can occur when CloudTrail is not enabled for EventBridge to capture `CreateLoadBalancer` events. | CloudTrail must be enabled for EventBridge to capture `CreateLoadBalancer` events, since these events are recorded and delivered through CloudTrail. |
diff --git a/docs/observability/aws/deploy-use-aws-observability/deploy-with-terraform.md b/docs/observability/aws/deploy-use-aws-observability/deploy-with-terraform.md
index 6a811d4b4da..cbef317af84 100644
--- a/docs/observability/aws/deploy-use-aws-observability/deploy-with-terraform.md
+++ b/docs/observability/aws/deploy-use-aws-observability/deploy-with-terraform.md
@@ -1613,7 +1613,7 @@ Invalid IAM role OR AccessDenied
```
#### Solution
-- Refer to [Edit, activate/deactivate, rotate, or delete access keys](/docs/manage/security/access-keys/#edit-activatedeactivate-rotate-or-delete-access-keys) for access keys activation.
+- Refer to [Edit, deactivate/activate, rotate, or delete access keys](/docs/manage/security/access-keys/#edit-deactivateactivate-rotate-or-delete-access-keys) for access keys activation.
- Refer to [Prerequisites](/docs/observability/aws/deploy-use-aws-observability/before-you-deploy/#prerequisites) for permissions related issues.
diff --git a/static/img/alerts/alert-preferences.png b/static/img/alerts/alert-preferences.png
deleted file mode 100644
index d135cb6d7cd..00000000000
Binary files a/static/img/alerts/alert-preferences.png and /dev/null differ
diff --git a/static/img/get-started/acct-pref.png b/static/img/get-started/acct-pref.png
index e2b6e3c5d1c..d752431d4e2 100644
Binary files a/static/img/get-started/acct-pref.png and b/static/img/get-started/acct-pref.png differ
diff --git a/static/img/get-started/my-preferences.png b/static/img/get-started/my-preferences.png
deleted file mode 100644
index 5438f6434ab..00000000000
Binary files a/static/img/get-started/my-preferences.png and /dev/null differ
diff --git a/static/img/get-started/my-profile.png b/static/img/get-started/my-profile.png
deleted file mode 100644
index 4dae248e1a4..00000000000
Binary files a/static/img/get-started/my-profile.png and /dev/null differ
diff --git a/static/img/security/access-key-security-page.png b/static/img/security/access-key-security-page.png
index 56a38d6c168..d556f13a6b1 100644
Binary files a/static/img/security/access-key-security-page.png and b/static/img/security/access-key-security-page.png differ