Overview
Fourth360 lets an administrator manage Multi-Factor Authentication (MFA) for their organisation directly, without needing to raise a support ticket. From Fourth360, administrators can:
- Enable or restrict MFA across the whole user base – for example, turning MFA on for all users, with named exceptions
- Trigger an MFA reset for an individual user – for example, someone who has lost access to their authenticator app
This guide walks through both of these tasks, and explains how MFA can be managed at organisation level or for individual users.
For more detail on how MFA works for your users, see:
- New Release | Fourth App: Multi-factor Authentication
- New Release | Fourth App: Email Multi-factor Authentication
Enable MFA for Your Whole Organisation
Use this option to require every user in your organisation to sign in with MFA.
- In Fourth360, go to Administration > Settings
- On the General properties tab, against the Multi-factor authentication group drop-down, select Require MFA – Authenticator App, then select Save
All users in the organisation will now be required to sign in using MFA. Because the setting is applied at organisation level, it will not show against individual user records.
Please don't change any other settings in this section of Fourth360 – these are managed separately from MFA.
Enable/Disable MFA for a Single User
Use this option to configuMFA for a specific user, rather than the whole organisation.
- In Fourth360, go to Administration > Users
- Search for the user, then either click on the row or select Edit user from the context menu
- Go to Settings. Under the MFA drop-down, choose Require MFA – Authenticator App or Require MFA – Email or MFA Disabled, then select Save
This user will now be required to sign in using the selected MFA method (or none), overriding any setting applied at organisation level.
Set a User to Inherit MFA Settings from the Organisation
If a user has been set individually and you'd like them to instead follow the organisation-wide MFA setting:
- Go to the user's record and, under the Settings > MFA drop-down, select Inherit Settings from Customer
This user will now automatically follow whatever MFA setting is applied at organisation level, rather than having their own individual setting.
Reset MFA for a Single User
If a user has lost access to their authenticator app, or needs their MFA reset for any other reason:
- In Fourth360, go to Administration > Users
- Search for the user, then either click on the row or select Edit user from the context menu
- Go to Account Tools, then under Reset sign-in credentials, select Reset, then in the subsequent confirmation dialogue, confirm Reset.
Once reset, the user is prompted to set up MFA again the next time they sign in.
Please don't change any other settings in this section of Fourth360.
Summary
- Organisation-wide – Administration > General properties > select Multi-factor authentication group > Save
- Single user – Administration > Users > Edit user > Settings > select MFA type > Save
- Inherit setting – Administration > Users > Edit user > Settings > select MFA type: Inherit Settings from Customer > Save
- Reset a user's MFA – Administration > Users > Edit user > Account Tools > Reset sign-in credentials > Reset > Reset
If you need further help managing MFA for your organisation, contact your Fourth support team.
Comments
Please sign in to leave a comment.