doc/security/user_email_confirmation.md
{{< details >}}
{{< /details >}}
GitLab can be configured to require confirmation of a user's email address when the user signs up. When this setting is enabled, the user is unable to sign in until they confirm their email address.
Prerequisites:
By default, a user can confirm their account within 24 hours after the confirmation email was sent. After 24 hours, the confirmation token becomes invalid.
{{< details >}}
{{< /details >}}
When email confirmation is turned on, administrators can enable the setting to automatically delete unconfirmed users.