Previous Topic

Next Topic

Book Contents

Book Index

Requiring Multi-Factor Authentication

TIP Require multi-factor authentication according to risk and the level of access for a specific user class. For example, information system best practices and regulatory compliance typically require the use of these controls for administrator accounts --based on the business value and range of resources they manage.

You can require multi-factor authentication by registered user class. You can also exempt users individually.

Note: It is best practice to notify users of any security policies that alter the sequence of steps or information needed at sign on before you apply these controls.

Require/Enforce MFA on a User Class

This setting enables you to require a specific class of user (Administrators, for example) validate their identity with another means such as mobile authenticator or email. It is an organization-wide setting for each selected user class.

If you enforce Email-only MFA on a user class and a user from that class has no email address associated with his account, enforcing Email-only MFA limits his availability to sign-on until the account has a valid email address.

Registered User Class

Level of Access/Function

Administrators

SysAdmins and Administrators

  • User account creation.
  • Organization/business group creation.
  • Security policy settings.
  • Other admin tasks...

File Administrators

  • Daily administration.
  • Folder creation.
  • File upload/download.

Users

Users and Users designated as GroupAdmins for a particular group.

  • All users will need to verify identity at next sign on unless exempted.
  • Users can elect alternate verification methods in user settings.
  • Admins can allow users to remember verified devices as part of sign in.

Temp Users

  • Temporary users receiving Ad Hoc package notifications.
  • Ad Hoc transfer must be configured for the current organization for this user class to be available.

See Also

User Authentication - Multi-Factor Authentication

Allow MFA Site Wide

Available Methods

Remember this Device

Exempt Users from MFA