Using two-factor authentication

Introduction

To protect portal data and prevent unauthorized access, you can enable two-factor authentication as an additional security layer. Even if someone obtains your password, they will also need access to your phone. This guide explains how it works and how to enable this option.

For the SaaS version, the SMS provider used on your portal is selected depending on the portal region: smsc is used for CIS, Clickatell and Twilio are used for all other regions. You can add available SMS providers in the Settings > Integration > Third-Party Services section.

If you are using the server version, you first need to connect at least one SMS provider in the Settings > Integration > Third-Party Services section so that you can enable the Two-factor authentication option.

It is also possible to enable two-step verification with authenticator apps.

To enable two-factor authentication, you must be the portal owner or a full-access administrator.

Connecting an SMS provider to your portal

To connect an SMS provider:

  1. Sign in to your portal.
  2. Click the Settings Icon icon at the top of the page or open the Choose drop-down list next to your portal logo and select the Apps option.
  3. Go to the Integration section and open the Third-Party Services page.
    How to use two-factor authentication on portals? How to use two-factor authentication on portals?
  4. In the list of third-party services, click the toggle next to Clickatell, smsc, or Twilio to open the window that contains the integration settings for this service.
  5. Now you need to specify the keys used to integrate the selected service with your portal. To obtain these keys, follow the corresponding instructions:
    You can add more than one SMS provider. The SMS provider used on your portal is selected depending on the portal region: smsc is used for CIS, Clickatell and Twilio are used for all other regions.
  6. Once you paste the keys into the corresponding fields, click Enable to save the settings.
How to use two-factor authentication on portals? How to use two-factor authentication on portals?

When the SMS provider is added, you can proceed to the next step.

SMS messages can only be sent when your account balance is positive. You can always check your current balance in your SMS provider account. Maintain a sufficient account balance to prevent service interruptions.

Enabling two-factor authentication

To set up two-factor authentication:

  1. In the portal settings, go to the Security section and open the Portal access page.
  2. Go to the Two-factor authentication section and
    • select the By SMS radio button to use the SMS verification, or
    • select the By authenticator app radio button to use an authenticator app.
  3. To specify detailed settings, you can use the advanced settings. Click Show Advanced Settings and set the options you need:
    • in the Mandatory Two-factor authentication section, you can add users or groups for which two-factor verification will be performed even if the user comes from a trusted IP address. For other users who are not included in the Trusted Networks list, two-factor verification is performed as usual.
    • in the Trusted Networks section, you can add trusted IP addresses for which two-factor verification will not be performed. Specify separate IP addresses in the IPv4 format (#.#.#.#, where # is a numeric value from 0 to 255), or set an IP address range by entering the starting and ending IP addresses of the range in the #.#.#.#-#.#.#.# format, or use CIDR masking in the #.#.#.#/# format.
  4. Click Save below the Two-factor authentication section.
How to use two-factor authentication on portals? How to use two-factor authentication on portals?

Two-factor authentication is now enabled.

Accessing your online office account using SMS verification

When two-factor authentication with SMS is enabled, the process of signing in to the online office account will work a little differently and include two steps:

  • Step 1: Enter your credentials: email and password as usual.
  • Step 2: Enter a six-digit verification code received via SMS.
The sent code is valid for 10 minutes. To resend a verification code, use the Send code again button, but no more often than five times per five minutes.

When you access your online office account for the first time after enabling two-factor authentication, you will need to perform one more step: Specify the phone number you want the SMS to be sent to. If necessary, you will be able to change it later at any moment on your profile page.

How to use two-factor authentication on portals? How to use two-factor authentication on portals?

To make the sign-in process simpler, your online office offers the possibility to remember that a particular browser was already successfully used for two-factor authentication. When you access your account for the second time using the same browser, it will ask you for your email and password only. However, if you or someone else tries to access your account from any other computer or browser, the verification code will be required, so your account will still be protected. The verification code will also be required when the two-factor authentication cookie has expired or if you decide to delete cookies from your browser.

Accessing your online office account using an authenticator app

When two-factor authentication with an authenticator app is enabled, the process of signing in to the online office account will work a little differently and include two steps:

  • Step 1: Enter your credentials: email and password as usual.
  • Step 2: Enter a six-digit verification code or a backup code generated by the authenticator app.

To access the portal for the first time after enabling two-factor authentication:

  1. Enter your regular credentials to access the portal. The QR code and your secret key are displayed on your portal login confirmation page.
    How to use two-factor authentication on portals? How to use two-factor authentication on portals?
  2. Install an authenticator app on your mobile device. You can use Google Authenticator for Android and iOS or Microsoft Authenticator for Android/iOS.
  3. Open the authenticator app on your mobile device and configure it in one of the following ways:
    • Scan the QR code displayed in the browser, or
    • Manually enter your secret key displayed in the browser.
  4. On your portal login confirmation page, enter a six-digit code generated by your application.
  5. Click Connect app.

Then you will be redirected to your profile page where the backup codes will be displayed in a new window. You can use the backup codes when you do not have access to your mobile device. Print the backup codes by clicking the corresponding button and use them when necessary. To get new codes, you can use the Request new button. Only the codes that were generated most recently are valid. It is also possible to connect a new authenticator app using the corresponding link on your profile page.

When you access your account the next time, you will be asked for your email and password, as well as for a verification code. You can use either a code generated by the application or a backup code.

Article with the tag:
Browse all tags