Assign MFA Types to Password Manager Policies

In EmpowerID, multi-factor authentication (MFA) is a versatile, points-based system that allows administrators to determine the number and types of factors users must present during authentication and the weight or point value associated with each factor. When users reach the designated point threshold, they are authenticated and granted access to the system. EmpowerID supports a variety of MFA types out-of-the-box to facilitate user adoption, including:

  1. DUO Two-Factor Authentication – When required by a Password Manager Policy, users must approve a secondary authentication request pushed to their mobile phones, sent as a one-time passcode, or delivered via a phone call. This MFA type requires a Duo account registered in EmpowerID and user enrollment in Duo, registering a mobile phone, tablet, landline, or U2F token. If you do not have a Duo account, you can sign up for one by visiting https://signup.duo.com/.

  2. EmpowerID Mobile Authenticator – When required by a Password Manager Policy, users must approve a secondary authentication request pushed to their mobile phones. To utilize this MFA type, EmpowerID must be configured EmpowerID for the mobile app.

  3. EmpowerID One-Time Password – When required by a Password Manager Policy, users must verify their identity by entering a one-time passcode generated by EmpowerID, delivered via email, SMS, or voice call. To use SMS and voice calling features, organizations must register a Twilio account in EmpowerID.

  4. FIDO WebAuthN – When required by a Password Manager Policy, users are prompted to insert their security key (e.g., Yubikey device) and press the button or gold disk on the key. EmpowerID generates a certificate linking the Yubikey to the person authenticating upon first use.

  5. OATH Time-Based One-Time Password – When required by a Password Manager Policy, users must verify their identity by entering a time-based code generated by a client application installed on their mobile devices, such as Google Authenticator or DUO.

  6. Yubico OTP – When required by a Password Manager Policy, users must verify their identity by generating a one-time password via their Yubikey. Yubico OTP requires an API key from Yubico and registration in EmpowerID. Users must also possess a Yubikey device.



Assign MFA Types

  1. On the navbar, expand Password Management and click Password & Login Policies.

  2. From the Policies tab of the Find Password Manager Policies page, search for the policy you want to apply LoA points to and then click the Display Name link for that policy.

     

  3. On the Policy Details page that appears, expand the Multifactor Authentication accordion and then click the Add-Type (+) button to the right of the grid.

     

  4. In the dialog that appears, click the Type drop-down and select one of the MFA Types mentioned above.

     

  5. Set the priority for the type in the Priority field. The lower the number, the higher the priority. Priority is only applicable when the MFA Type is required.

  6. Specify whether the MFA type is required. If required, users with the policy must authenticate using the type. When a policy requires more than one MFA Type, users must authenticate using each type in the order specified by the priority for the type.

  7. Click Save.



Â