Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
minLevel1
maxLevel7

...

The user first logs into the system with his their username and password and then he gets they get a second verification request (SMS, Email, or Google authenticator) which provides the user with a code that he needs they need to enter.

The default authentication manner in OOONA Manager is Email.

Authentication manners

Note

Please note that activating 2-factor authentication from Administrator > Web Administrator > Configuration > Security, as explained in the https://ooona.atlassian.net/wiki/spaces/OHC/pages/edit-v2/1833730049#System-Administrator--Initial-activation-of-2FA-in-OOONA-Manager section, it will activate it for all users in the system. To change the authentication manner for individual users, follow the steps bellow.

The system is set with a default authentication manner set by the Admin, but each user can set his their preferred default authentication manner.

From: My menu > Resource information > Default authentication manner

  • Email

  • Google Authenticator (requires setup before it can be usedinitial setup by the user)

  • SMS via Twilio (requires having a valid mobile number updated in the system)

Users can set their preferred authentication manner from: My menu > Resource information > Default authentication manner

Note

When the authentication manner is set to “Google authenticator”, and the initial setup wasn’t done by the user yet, on the first login the user will change the authentication manner to Email so they can log in to OOONA Manager and then they can perform the initial setup of their Google authenticator

...

Info

The Authentication manner can also be changed by the user on every login without presetting a user default

Email authentication manner

This authentication manner is the system default.

Initial setup by the user

Steps to change the default authentication to Emal Email verification:

From: My menu > Resource information

  1. Select “Email” in the “Default authenticator” field (fig 2)

  2. Make sure the login email is set correctly (fig 3). The authentication email will be sent to this email.

...

  1. Optional: To ensure the data was entered correctly, use the “Test authentication manner” button (4).

...

Log in with Email authentication

When logging in, after entering the Username and password the 2FA page will prompt and the verification email will be sent to the Login email of the user.

...

The verification code received in the mail should be entered to gain access to the system (fig 1).

Note

In case of issues, another authentication manner can be selected upon login for this login attempt

...

3. Download the Google Authenticator app to your phoneAdd links to google play and apple store

Google Authenticator for Android

‎Google Authenticator for IOS

4. Open the Google Authenticator app on your phone

...

Info

If scanning is not available to you, you can perform the initial setup using the number code received in step 2

...

First, the OOONA user must be linked to a browser’s Google authenticatorAuthenticator

  1. Add the Google Authenticator add-on to your browser https://chrome.google.com/webstore/detail/authenticator/bhghoamapcdpbohphigoooaddinpkbai?hl=en

  2. Pin the Authenticator add-on for easy access

  3. Navigate to your Resource info page: My menu > Resource information

  4. Select “Google authenticator” in the “Default authenticator” field (fig 21)

  5. Click “Generate google authenticator” info (fig 12)

  6. Click the pinned authenticator icon (fig 23)

  7. Click scan QR code“scan QR code” (fig 4)

  8. Scan by dragging with the mouse over your Google authenticator QR code (fig 45)

...

...

Log in with a Browser’s Google Authenticator

...

Note

In case of issues, another authentication manner can be selected upon login for this login attempt

SMS (Twilio)

Initial setup by the user

In order to use the SMS Twilio authentication method, the user needs to have a valid phone number in their resource profile.

  1. Go to My menu > Resource information

  2. Add a valid mobile phone number to the Mobile, Phone or Home phone fields

  3. Select “Sms using Twilio” as the default authentication manner.

  4. (Optional)

...

  1. Click on “Test authentication manner” to confirm the code is received.

...

Info

If multiple phone numbers are provided, the system will check the fields in the following order:

Mobile > Phone > Home phone

Log in with SMS authentication

When logging in, after entering the Username and password, the 2FA page will prompt and the verification code will be sent to the phone number of the user via SMS.

If not received, the code can be resent using the “Re-send code” button, but this action is limited to 1 SMS per minute, for a maximum of 5 SMS in an hour.

...

System Administrator- Initial activation of 2FA in OOONA Manager

...

Activating 2-factor authentication

2-factor authentication is activated at a system level by default (fig 4), and can only be turned off by OOONA users.

To change the authentication manner follow these steps:
From: Administrator > Web Administrator > Configuration > Security

  1. Switch ON “Enable two-factor authentication” (fig 4)

  2. Select the default authentication manner (fig 5):

    1. Email

    2. SMS (Twilio)

    3. Google Authenticator (requires initial setup by the user)

Info

All users can independently change the authentication manner to their preferred one out of the three available methods.

They can set a user default, or manually select the authentication manner upon every login

...

Note

When the authentication manner is set to “Google authenticator”, and the initial setup wasn’t done by the user yet, on the first login the user will change the authentication manner to Email so they can log in to OOONA Manager and then they can perform the initial setup of their Google authenticator

...

When activating the 2-factor authentication on a system level, you can also make sure it works as expecting by clicking the “Test authentication manner” button next to the default authentication manner chosen.

...

2-factor authentication for Subcontractor links

2-factor authentication for Subcontractor is activated at a system level by default, and can only be turned off by OOONA users.
All Subcontractor links will require 2-factor authentication when the subcontractors open them.

...

Info

Note that 2-factor authentication for Subcontractor links will automatically send the verification code to the subcontractor email. It does not allow choosing any other authentication method.

...

Additional authentication methods

If additional security is required, or your company already has an established authentication method, these can also be used to log in to the OOONA Manager system.

Additional authentication methods can be configured from Administrator > Web administrator > Configuration > Security.

...

After selecting an alternative authentication method, the corresponding fields to populate will become available:

...

Info

For security reasons, this configuration by itself will not enable the selected authentication method, as it also requires configuration to be done by the OOONA team.

If this configuration is only partially done, the system will fall back to the standard login page.