To enable Two Factor Authentication please raise a service request. Please note this functionality is only applicable for users with local credentials. Any Two Factor Authentication for users logging in through Single Sign On is managed externally to risr/advance.
Where Two Factor Authentication is enabled, all users logging in through local credentials will be required to setup a second authentication factor before they can continue.
All login credentials and associated Two Factor Authentication options for an individual user are found within the account security area of the profile.
The ability to manage two factor authentication options and to change password is not dependent on any permission. All users have the ability to manage their two factor authentication options and to change their password without needing to be able to edit their profile.
The account security area displays the login credentials, alongside the option to manage the two factor authentication options.
The two factor authentication options available are:
- Authenticator application
Removing, adding or replacing an authentication option requires the user to re-authenticate. This re-authentication will request the user's password and any existing two factor authentication configured on their account. A successful re-authentication will be stored for ten minutes before being requested again, to allow the user time to make multiple changes.
Authenticator
The authenticator option allows the user to store the one-time password in a dedicated password or authenticator management application.
This option will generate an email containing a one-time password and send it to the primary email address of the user. If the user sets and configures this as a new authentication option during the initial login process, or during the creation of a new account using risr/apply, they are not asked to confirm a code if they complete the process within ten minutes.
Login behaviour
When logging into the application and providing a one-time password, the user can choose to remember their device for seven days. This will result in the user being able to login on the same device without needing to enter their one-time password again until the seven days expires. They will still always be prompted for the main password.
Where the user has more than one authentication option setup, they will be presented with the authenticator application option as the default, alongside the ability to switch method.
The authenticator code is a one-time password which is generated every 30 seconds. It is generated from the date and time of the device on which it is generated. It is therefore important that the date, time and timezone of the device generating the code is correct. There is a grace period which allows the user to login with a code which is in the 30-second window either side of the current. For example, the user can login with the code that was generated 30 seconds ago, and the code that will be generated 30 seconds from now. This is to allow for very slight variations in time on the device, or for a user who may take a little longer to enter the code into risr/advance.
Troubleshooting
Should the user lose the ability to retrieve their one-time passwords for their second factor authentication options, they will need to have these options removed from their account. Removing these options will result in them being prompted to setup a new second factor authentication mechanism on their next login.
Comments
0 comments
Please sign in to leave a comment.