Skip to main content

Multi-factor authentication

Multi-factor authentication (MFA) adds an extra layer of security to your Cloud Intelligence account. When using MFA, you enter a time-based one-time password (TOTP) from an authenticator app in addition to your email and password when you sign in.

By default, MFA is mandatory for users who sign in with email and password. If you are an Admin, you can manage MFA for your entire organization or exempt individual users. Users who sign in with Google, Microsoft, or SSO are protected by their identity provider's security policies and are not prompted for an additional authentication code.

Authenticator apps

The following TOTP-compatible authenticator apps are supported:

  • Google Authenticator

  • Microsoft Authenticator

  • Authy

  • 2FA Authenticator (2FAS)

  • Bitwarden

  • Ente Auth

Set up MFA for the first time

The first time you sign in with email and password, the console prompts you to enroll in MFA before you can continue.

  1. Select Join DoiT Console from your invitation email. The console is displayed.

  2. Enter your email address and password.

    The sign in screen

  3. Select Sign up. The Set up two-factor authentication page is displayed.

    The MFA QR scan screen

  4. Open your authenticator app (for example, Google Authenticator or Authy).

  5. In your authenticator app, add the Cloud Intelligence account by scanning the QR code shown. If you cannot scan the QR code, select Can't scan code manually? to display a unique secret key that you can use instead. Once the Cloud Intelligence account is linked to your authenticator app, the app generates the 6-digit security code you need to log in.

  6. Select Next.

  7. Enter the six-digit code generated by your authenticator app.

    Enter the MFA 6 figure authentication code

  8. Select Verify and continue to complete enrollment.

  9. Select Continue to DoiT Console.

    MFA is enabled

Verify your identity with MFA

After you have enrolled in MFA, each time you sign in with email and password you are prompted to enter a six-digit authentication code from your authenticator app.

The MFA challenge screen

  1. Open your authenticator app (for example, Google Authenticator or Authy) and locate the entry for Cloud Intelligence.

  2. Enter the six-digit code displayed in the app. The code refreshes every 30 seconds.

  3. Select Sign in.

    If you enter an incorrect code, an error message appears and the input field is cleared so you can try again. If the code has expired, wait for your authenticator app to generate a new code before resubmitting.

    To sign in with a different account, select Use a different account to return to the email entry screen.

Note

If you submit too many incorrect codes in a short period, your account may be temporarily locked for security reasons.

Manage MFA for your organization

If you are an Admin, you can enable or disable MFA for all users in your organization. This applies to every user who signs in with email and password. Per-user exemptions set through individual user management continue to apply. While the organization requirement is off, turning on Require MFA for an individual user has no effect.

When you enable MFA, users who have not yet enrolled are prompted to set up an authenticator on their next sign-in.

Required permissions

You must have the Admin role.

To enable or disable MFA for your organization:

  1. Sign in to the DoiT console, select the gear icon () from the top navigation bar, and then select Users and access.

  2. Select Settings from the left-hand menu.

  3. In the Multi-factor authentication section, turn the Require multi-factor authentication toggle on or off.

  4. If you are disabling MFA, a confirmation dialog is displayed. Select Disable MFA to confirm.

    Caution

    Turning this toggle off disables MFA for the whole organization which unenrolls every user and removes their additional sign-in protection. If you later turn the requirement back on, all users except those exempted individually must enroll again.

Changes to the organization MFA setting are recorded in the audit log.

Manage MFA for individual users

If you are an Admin, you can exempt individual users from MFA. Use the Require MFA toggle in the Multi-factor authentication section of a user's profile to turn this requirement on or off.

When you turn it on, the user is prompted to enroll in MFA on their next sign-in.

Caution
  • Disabling MFA removes the user's enrolled authenticator. If you later re-enable MFA for this user, they must enroll again on their next sign-in.

Required permissions

You must have the Admin role.

To manage MFA for a user:

  1. Sign in to the DoiT console, select the gear icon () from the top navigation bar, and then select Users and access.

  2. Select the user's email on the Users page.

  3. In the Multi-factor authentication section of the user's profile, turn the Require MFA toggle on or off, as necessary.

See also