Managing Multi-Factor Authentication (MFA)
Who is this article for?
Administrators who want to turn on additional security for the organisation's login process
Admin Console access is required
Multi-Factor Authentication (MFA) enhances security for users with internal authentication on Mazlan Home. It does not apply to users logging in via external Single Sign-On (SSO) providers.
This article explains how tenant administrators can enable or disable MFA for the organisation, and how to manage MFA settings at the individual user level.
Enabling MFA
Mazlan Home supports MFA either via email or Authenticator App per organisation.
Enabling Email MFA requires entering a code sent to your email during sign-in.
With Authenticator App MFA enabled, you'll enter a code from your app when signing in.
To enable MFA:
- Navigate to the Admin Console.
- Go to the Security Center.
- Click Off next to Multi-Factor Authentication.
- Set Require Multi-factor authentication to Yes.
- Select one of the Authentication methods.
- Click Save to apply the changes.
You will see a success message if MFA has been enabled correctly.
Future improvements
Currently, MFA supports email or authenticator app, with one method per organisation.
Mixing methods, and adding SMS as an option will be planned for future updates.
Signing in with MFA
Once MFA is enabled, all users are required to verify their identity using a one-time code sent to their registered email address or authenticator app.
To sign in with MFA enabled:
- Enter your Username and Password as usual.
-
Click Sign in.
First time Authenticator App MFA sign in
The first time you sign in after Authenticator App MFA is enabled for your account, you'll be prompted to set up an authenticator app. Once your authenticator app is linked, future sign-ins will just prompt you for a code.
- Access the email or authenticator app associated with your account.
- Copy the code from the email or authenticator app.
- Paste it into the Code field.
- Click Sign in.
Note
We recommend to completing the sign-in within three minutes for email or within one minute for authenticator apps, as the verification code will expire after that time.
If you run into any issues, please try signing in again and a new verification code will be sent to you.
Disabling MFA
To disable MFA:
- Navigate to the Admin Console.
- Go to the Security Center.
- Click On next to Multi-Factor Authentication.
- Set Require Multi-factor authentication to No.
- Click Save to apply the changes.
Once MFA is disabled, users will no longer be prompted for an additional verification code at sign in.
Overriding MFA
The MFA override feature does not apply to organisations that have Authenticator App MFA enabled.
Once Authenticator App MFA is enabled at the organisation level, it becomes mandatory for all native users at sign-in - admins will not be able to override or bypass this requirement on a per-user basis.
If you need to exempt a specific user from MFA email, you can override the organisation-level setting at the individual user level.
To override the MFA setting per-user:
- Navigate to the Admin Console.
- Go to User Management.
- Locate the user you want to manage.
- Open the Actions menu.
- Select MFA Settings.
- Set Require Multi-factor authentication to No to turn off MFA for the user only.
- Click Save to apply the changes.
Once email MFA is disabled for a user, all other users in the organisation will still be asked for an additional verification code when signing in. However, the user for whom MFA has been disabled will no longer be prompted for this extra verification.
Note
Per-user MFA overrides should be used with caution. Disabling MFA for individual users reduces the security coverage of your organisation.