Subscribe and Configure Multi-Factor Authentication (MFA)
This article explains how INSZoom administrators can subscribe and configure Multi-Factor Authentication MFA for their organizations
Getting Started with Multi-factor Authentication
1. Multi-factor Authentication is a Subscription feature and thus, INSZoom superusers/administrators of your firm need to subscribe to the feature from the INSZoom Subscriptions module to let users get started with Multi-factor Authentication.
2. Once Multi-factor authentication is subscribed and enabled, users can start using Multi-factor authentication from their added devices or ‘YubiKey’ security keys after one-time enrollment of their mobile devices or security keys.
How does it work?
Multi-factor Authentication fundamentally has a simple three-step process:
- Subscription- Superuser/administrator subscribes to MFA from the subscription module.
- Configuration & Enablement- Superuser/administrator selects and configures MFA for their Firm’s INSZoom users.
- Enrollment- Users register their device or security key to verify their identity and securely access the INSZoom application.
How to enable and use Multi-factor Authentication?
- A. Subscription and Setup for Multi-factor Authentication
A.1 Subscription: INSZoom Superusers from the Firm can subscribe to Multi-factor Authentication from the Main navigation menu, hover over Setup > Click on Subscriptions > Click on Multi-factor Authentication > Click on the button ‘Subscribe for Multi-Factor Authentication (MFA)’.
INSZoom accounts team will get in touch with your organization to confirm subscription request and activate the feature for your organization.
A.2 Choosing Case Managers and Corporations for enabling MFA:
After Multi-factor Authentication is subscribed and activated for your organization, you could choose to enable MFA for all Internal staff/ Case Managers and/or Corporations, Foreign Nationals. While enabling MFA for Corporation Users and Foreign Nationals, you could choose to enable MFA for all your Corporate clients or Users of specific Corporations.
A.2.1 Case Managers- MFA can be enabled for all the case managers in your Firm by clicking on the ‘Enable for All Case Managers’ button.
A.2.2 Vendor Case Managers- MFA can be enabled for all vendor case managers by clicking on the button ‘Enable for All Vendor Case Managers’.Vendor Case Managers- MFA can be enabled for all vendor case managers by clicking on the button ‘Enable for All Vendor Case Managers’.
A.2.3 Corporation Users and Foreign Nationals- You get to choose from two options to suit your need; enabling MFA for all Corporate customers or for specific customers.
A.2.3.1 All Corporations and Foreign Nationals- Choose this option if you intend to enable MFA for all your Corporate clients. If selected, this provides an option to enable MFA for Corp Users and/or Foreign Nationals.
a. ‘Enable for All Corp Users’- This enables MFA for Corp Users of all Corporations.
b. ‘Enable for All Foreign Nationals’- This enables MFA for Foreign National Users of all Corporations.
A.2.3.2 Specific Corporation and Foreign National- Choose this option if you intend to enable MFA only for specific Corporate clients. If selected, this provides an option to enable MFA for Corp Users and/or Foreign Nationals of specific Corporation.
You can select a specific corporation from the drop-down and add it to the list of corporations for which MFA needs to be enabled.
A.2.4. Count of Total Users Enabled- With MFA enabled for the case managers, vendor case managers, corp users, and foreign national users, INSZoom administrators may keep a tab on MFA user count with the help of Counter available on the top-right of the subscriptions page.
A.2.5 List of Enrolled Users- After MFA is enabled for your organization, the case managers will receive an email alert notifying them that MFA has been enabled for their INSZoom account. This alert essentially invites the case managers to start enrolling their devices or security keys to act as an additional layer of security for INSZoom accounts. Administrators can look at the list of all users who have enrolled their devices or security keys using the ‘Enrolled Users’ list at the bottom of the MFA Subscription page. This also includes the utility to search for users by Name/Organization with ability to Filter enrolled users by Type (All Case Managers, All Vendor Case Managers, etc.)
Corp Users and Foreign Nationals are provided with On-screen instructions about device enrollment upon first login attempt post MFA enablement.
A.2.6 Reset MFA Enrollment- There can be scenarios where MFA enrollment of an enrolled user may need to be reset. Few of such scenarios are-
- The enrolled user needs to change the second form of authentication from his/her mobile phone to a security key such as ‘Yubikey’.
- The enrolled user has changed his/her mobile device or mobile phone number.
- The enrolled user has reset his/her mobile device.
- The enrolled user’s INSZoom account has been deleted.
In such cases, INSZoom superusers/administrators can choose to Reset/Delete MFA enrollment of the enrolled users. You can click on the ‘Reset MFA Enrollment’ button against the specific user’s name to reset the MFA Enrollment.
Click here to learn more on how to enroll your device or security key with MFA.