Multi-factor authentication (MFA) is a security measure that requires users to enter a dynamically generated eight-digit verification code in addition to their username and password when logging into the application.
With Email MFA, non-native users will be restricted from signing into the application. Even if someone manages to get your identity, they would still be stopped from getting into your application account unless they identify themselves with the OTP.
From the the Users Configuration settings, specify the Username(valid email address), set the login method to Native and finally enable the Email OTP verification(check box).
When MFA is activated for your business user, an Email alert is sent to the user prompting to use the verification code to log into the application.
Step-by-step Instructions
Step 1: Login as Site administrator
Step 2: Navigate to the User Settings page
Step 3: Click the Add New button from the All Users list view. The Create User page displays.
Step 4: In the Create User page, specify the Login method as Native
Step 5: Select the checkbox to enable "Email OTP verification"
Remember: If you change the login method to "SSO", then understand that Email MFA is no longer valid and the checkbox disappears from the screen.
Step 6: Save your settings
Result: An email alert is sent to the specified Username(email address).
The email triggers based only on the value in Username field and not the Email id field.
To authenticate, users must enter a One-Time Password (OTP) within the allotted time. Each OTP code remains valid for about five minutes. If a user takes too long to enter the OTP code, the login session expires, and the authentication attempt fails. In such cases, the user must request the administrator to resend the OTP and restart the login process. As an administrator, you can reset the OTP and provide the new code to the user to initiate the login process.
Q. What if Exto refuses to authenticate user with OTP code?
A. Each code is valid for about 30 seconds only. If the user dosen't enter the code quickly, a new code has to get generated. Users need to request the administrator to resend the OTP. If the problem continues, please contact Support.
Q. Which users will be allowed to log into Exto?
A. Only users who have enrolled for Multi-factor authentication will be allowed to sign-in to the system. The site administrator needs to enable MFA for these users.
Q. How do I get MFA enabled for my users?
A. As of now, enable by sending a request.