When 2FA is in use, Access Identity provides multiple security options for users to protect their accounts:
Users can opt-in to 2FA and register a trusted device such as their phone to receive a code that can be entered in the second step of their sign-in process, protecting users who may have had their password compromised.
The option to use SMS and the ability to use a broader set of authenticator apps such as Google Authenticator, Authy or FIDO2 to secure and log into your Identity account.
There is also the option for forced 2FA, where all users with that domain have it applied to their logins.
Enable 2FA individually
To enable 2FA for an individual account, follow the steps below:
Log in using this link: https://identity.accessacloud.com
Click Two Factor Authentication then click Get started with two-factor authentication.
You have three options:
Use a hardware security key or biometric features on your device.
Add a phone number to receive an SMS message containing a verification code.
Use an authentication app on your phone. The advantage of this is that it is a lot faster and more convenient in getting the required verification code compared to SMS.
On the preferred option, click Add authenticator.
Take note of the backup codes.
confirm you understand the use of backup codes, then click Enable Two Factor.
Backup codes importance
Backup codes are crucial for the user to store as these enable them to get back into their account if the phone they’ve registered has been lost or stolen.
An additional feature lets a domain owner switch off a user’s 2FA if that user has lost their phone, but this is only applicable if their organisation has proven ownership of their company domain first.