Table of Contents
MFA Setup
Users must complete the following steps to setup MFA once the Ordway enablement steps are completed by an Ordway Admin.
Preconditions:
- An Ordway Admin must first enable MFA for your organization.
- Users must download an Authenticator application on a mobile device to complete this process. The most widely used are Microsoft or Google Authenticator. You can download an authenticator app from either the App Store or Google Play Store.
Steps:
- Log into Ordway. The following is displayed. Click Set Up Authentication.
- Follow the prompts on screen and scan the provided QR code via your authenticator app on your mobile device.
- Follow the prompts on your mobile device.
Click Work or school account.
Click Scan QR code and use your mobile device to scan the code provided in Ordway. - Return to Ordway and enter the 6 digit code provided in the authenticator app and click Verify.
- Click Download to save a copy of the Recovery Codes for future reference. Keep these recovery codes, should you ever need to use another authentication method.
Example: If the authenticator app is not working, you can use one of the 6 digit recovery codes instead. Do not share these recovery codes.
Then click Finish.
Once MFA is set up, users are required to use their authentication app via mobile device for a new code after logging out and also based on User Session timeout settings.
MFA Frequently Asked Questions (FAQs)
What is MFA?
MFA is the process of requiring two or more credentials upon login to further protect user accounts from common security threats such as phishing and account hacking. Using MFA provides security for user accounts, but also further protects your valuable customer data as well.
Does Ordway require we use MFA?
No. MFA is not required by Ordway at this time. Each organization has the option to utilize MFA as an added security measure. At a future date, Ordway will require MFA for all users as an extra layer of security.
How do we enable MFA for our whole organization?
Instructions for enabling MFA are found in the Multi-Factor Authentication (MFA) article. The user must have Admin access in Ordway to manage Menu > Setup > General Settings in order to enable MFA.
What authentication app should we use?
There are multiple choices for an authentication app. The most widely used are Google or Microsoft Authenticator. You can download an authentication app from either the App Store or Google Play Store on any mobile device.
If MFA is required for my organization, can I turn it off for my specific user account?
No. If your organization has selected to enforce MFA, all users are required to use the MFA security feature.
Should we enable MFA in our Sandbox environment?
As with all new features in Ordway releases, MFA will be available to enable in your Sandbox environment first. You can enable MFA and test it out in Sandbox prior to the Production release date. After testing and evaluation, your organization should decide if you want to keep MFA enabled in Sandbox and whether to enable it in Production as well.
Is MFA required to access the Ordway Customer Portal?
No. MFA is not required to access Ordway’s Customer Portal at this time but will be introduced in a future release.
If we enable MFA for our Ordway instance, does the authentication requirement carry over to mobile devices?
Yes. When MFA is enabled in Ordway, the MFA prompts will be present via mobile devices including tablets and mobile phones. The requirement to use MFA on a mobile device will depend on if your organization has required MFA for all users.
Can I skip the authentication requirement?
Depends. If your organization has required MFA for all users, you cannot skip the authentication step. If your organization has enabled MFA for all users, but has not chosen to enforce it, you can skip the authentication step upon login.
When MFA is enabled but not enforced for users, you can click Skip For Now.
Can we use a password management app instead of MFA?
Ordway does not recommend using a password management app instead of MFA which provides increase security and data protection. Password management apps are helpful in enforcing strong passwords that should be changed on a regular basis. However, hard to guess passwords alone are not as strong as using MFA which requires two methods of authentication.
How often will Ordway users be prompted for authentication?
Authentication is required each time you log into Ordway and also based on User Session Settings.
Is access to Ordway APIs affected by MFA?
No. Authentication is not required when accessing Ordway via APIs.
Comments
0 comments
Please sign in to leave a comment.