Enabling Two-Factor Authentication (2FA)

The two-factor authentication can be set up for access to the System's main administrative interface. Authentication is performed with the help of the Google Authenticator app.

It can be configured as follows:

1. A user with the permission Security policy control can enable two-factor authentication for their own account in the Administration/User settings interface by selecting the Enable two factor authentication checkbox:

When selected, the QR code section becomes available, which contains the buttons Show actual QR and Regenerate QR. This QR code (the actual or re-generated one) must be fed to the Google Authenticator app. Based on the code, the app provides an additional numeric password that can be used to access the System (after entering a correct login and password). If the specified code is incorrect, the following error message will appear: "Incorrect TOTP please try again".

2. A user with the permission Security policy control can select the checkbox 2FA enabled for other users in Sart/Administration/Users:

In this case, a user for which the checkbox was enabled will receive an email with instructions on Google Authenticator installation and access to the System. Please note that a user cannot enable this checkbox for its own users in Start/Administration/Users, it can be done only in Start/User settings. The email template is configured in the Administration/Template manager interface and is called 2FA enabled for your account:

Users without the Security policy control role enabled in the Administration/User settings interface cannot change the 2FA settings for their own accounts or for other users. Thus, if you check the 2FA enabled checkbox for a user with no Security policy control role, this user will not be able to uncheck it:

The enabled checkbox is not saved on the user level for System users such as Alaris, Monitoring, monitoring, and invoice_mon.

The maximum number of entry attempts (including login and password entry with no TOTP) is 5 within one minute; the interval between attempts must be 3 seconds.

Starting from version 3.8, two-factor authentication (2FA) has been implemented for the Alaris Labs Campaign portal and new Partner Portal. This feature is enabled via a new System setting, Enable 2FA for portals (0 - no, 1 - yes).
When enabled:

  • Self-registered users are created with the Enable two factor authentication flag activated;
  • Users created by the System Owner will receive an email using the new template 2FA enabled for Partner\Campaign portal account.

To regenerate the email and code, toggle the Enable two factor authentication flag off then on for the user, and save each change. 2FA can be disabled at user level even when the global setting is enabled.

In case you have issues with 2FA activation, please submit a ticket on our Helpdesk and provide the user IDs.

 

AKBSMS - Alaris Knowledge Base

2-Step Verification setup.
How to enable two-factor authentication?
2FA access.
2-factor authentication for Client portal.
2-factor authentication for Wholesale portal.
2-factor authentication for retail users.

Link to this Article: https://helpdesk.alarislabs.com/en/knowledge_base/article/255/category/132/