Overview
Fourth360 lets an administrator manage Multi-Factor Authentication (MFA) for their organisation directly, without needing to raise a support ticket. From Fourth360, administrators can:
- Enable or restrict MFA across the whole user base – for example, turning MFA on for all users, with named exceptions
- Trigger an MFA reset for an individual user – for example, someone who has lost access to their authenticator app
This guide walks through both of these tasks, and explains how MFA can be managed at organisation level or for individual users.
For more detail on how MFA works for your users, see:
- New Release | Fourth App: Multi-factor Authentication
- New Release | Fourth App: Email Multi-factor Authentication
Enable MFA for Your Whole Organisation
Use this option to require every user in your organisation to sign in with MFA.
- In Fourth360, go to Admin > Settings
- Under the MFA Group drop-down, select Require MFA – Authenticator App, then select Save
All users in the organisation will now be required to sign in using MFA. Because the setting is applied at organisation level, it will not show against individual user records.
Please don't change any other settings on this section of Fourth360 – these are managed separately from MFA.
Enable MFA for a Single User
Use this option to require MFA for a specific user, rather than the whole organisation.
- In Fourth360, go to Admin > Users
- Search for the user, then select the Action icon next to their name
- Go to Group Assignments. Under the MFA Group drop-down, choose either Require MFA – Authenticator App or Require MFA – Email, then select Save Changes
Set a User to Inherit MFA Settings from the Organisation
If a user has been set individually and you'd like them to instead follow the organisation-wide MFA setting:
- Go to the user's record and, under the MFA Group drop-down, select Inherit Settings from Customer
This means the user will automatically follow whatever MFA setting is applied at organisation level, rather than having their own individual setting.
Reset MFA for a Single User
If a user has lost access to their authenticator app, or needs their MFA reset for any other reason:
- In Fourth360, go to Admin > Users
- Search for the user, then select the Action icon next to their name
- Go to User Tools, then under Reset User MFA, select Reset All Registered MFA Devices, then Save Changes
Once reset, the user is prompted to set up MFA again the next time they sign in.
Please don't change any other settings on this section of Fourth360.
Summary
- Organisation-wide – Admin > Settings > MFA Group > Save
- Single user – Admin > Users > Action icon > Group Assignments > MFA Group > Save Changes
- Inherit setting – Admin > Users > Action icon > MFA Group > Inherit Settings from Customer
- Reset a user's MFA – Admin > Users > Action icon > User Tools > Reset User MFA > Reset All Registered MFA Devices > Save Changes
If you need further help managing MFA for your organisation, contact your Fourth support team.
Comments
Please sign in to leave a comment.