Managing Multi-Factor Authentication (MFA)
Who is this article for?
Administrators who want to turn on additional security for the organisation's login process
Admin Console access is required
Multi-Factor Authentication (MFA) enhances security for users with internal authentication on Ideagen Hub. It does not apply to users logging in via external Single Sign-On (SSO) providers.
This article explains how tenant administrators can enable or disable MFA for the organisation, and how to manage MFA settings at the individual user level.
Enabling MFA
To enable email MFA for your organisation:
- Navigate to the Admin Console.
- Go to the Security Center.
- Click Off next to Multi-Factor Authentication.
- Set Require Multi-factor authentication to Yes.
- Click Save to apply the changes.
You will see a success message if MFA has been enabled correctly.
Other methods
At this time, email is the only supported MFA method. Support for phone (SMS) and authenticator apps (TOTP) is planned for a future release.
Signing in with MFA
Once MFA is enabled, all users are required to verify their identity using a one-time code sent to their registered email address.
To sign in with MFA enabled:
- Enter your Username and Password as usual.
- Click Sign in.
You will be prompted to check your registered email address for a one-time verification code.
- Access the email associated with your account.
- Copy the code from the email.
- Paste it into the Code field.
- Click Sign in.
Note
It’s recommended to complete the sign-in within 3 minutes, as the verification code will expire soon. If you run into any issues, please try signing in again and a new verification code will be sent to you.
Disabling MFA
To disable MFA:
- Navigate to the Admin Console.
- Go to the Security Center.
- Click On next to Multi-Factor Authentication.
- Set Require Multi-factor authentication to No.
- Click Save to apply the changes.
Once MFA is disabled, users will no longer be prompted for an additional verification code at sign in.
Overriding MFA
If you need to exempt a specific user from MFA, you can override the organisation-level setting at the individual user level.
To override the MFA setting per-user:
- Navigate to the Admin Console.
- Go to User Management.
- Locate the user you want to manage.
- Open the Actions menu.
- Select MFA Settings.
- Set Require Multi-factor authentication to No to turn off MFA for the user only.
- Click Save to apply the changes.
Once Email MFA is disabled for a user, all other users in the organisation will still be asked for an additional verification code when signing in. However, the user for whom MFA has been disabled will no longer be prompted for this extra verification.
Note
Per-user MFA overrides should be used with caution. Disabling MFA for individual users reduces the security coverage of your organisation.