2-FACTOR AUTHENTICATION WITH 2X JUNE 2014
Two-Factor Authentication and Authy What is Two-Factor Authentication? Two-Factor Authentication is a process involving two stages to verify the identity of someone trying to access services in a computer or in a network. It provides an extra layer of protection. Two-factor authentication is a simple feature that asks for more than just your password. It requires both something you know (like a password) and something you have (like your phone). After you enter your password, you ll get a second code sent to your phone, and only after you enter it will you get into your account. Think of it as entering a PIN number, then getting a retina scan, like you see in every spy movie ever made. It s simply added security for your online accounts. What is Authy? Authy is a third-party provider of a token-based authentication process. Authy can be used for a number of online applications like Gmail, Wordpress, Evernote and Facebook. Most of these applications involve a normal sign-in process (username and password) which is the first authentication. Authy provides the second authentication via mobile app, browser or SMS. Visit www.authy.com to learn more. Authy and has chosen Authy to provide it s Two-Factor Authentication process. Two-Factor Authentication is available for customers using Enterprise and is enabled by contacting your Transparency Concierge or support@viewabill.com. Once enabled, the Administrator has complete control of which users are required to use two-factor authentication and when it will be enabled for each user. 2
Administrator (Admin) Assigning Two-Factor Authentication to new and existing users Two-Factor Authentication is enabled by the Firm or Client Admin on a per user basis. To enable or disable this feature, follow these steps: 1. After signing into, select the Enterprise/Administration toggle. 2. Select Users icon in the main menu. Assign to Existing User: Select a user. In that user s Overview section you will see a checkbox that says Require Two-Factor Auth. Checking the box will require this user to perform a few easy steps to configure their Two-Factor Authentication and then require their use of Two-Factor Authentication for all subsequent logins. To disable this feature, simply deselect the checkbox. Assign to New User: To enable Two-Factor Authentication for a new user, create a new user by selecting the icon. Fill out the new user s information and check the box that says Require Two-Factor Auth. Finally, click the Create User button. The new user now requires Two-Factor Authentication to sign into. To disable this feature for the user, follow the instructions for Existing Users and deselect the Require Two Factor Auth checkbox. 3
Users Signing into with Two-Factor Authentication If an Admin has enabled Two-Factor Authentication for your user account, you will see the following screens when you log into. Only the Admin can determine if you have this security feature. Go to page 7 to see the 2-Factor Authentication Sequence Diagram. 2 1. Log into by entering your username and password on the sign in page. 2. You will be prompted to enter your Authy credentials, which is your mobile number. 3. Clicking Enable initiates your Authy account. (You will not have to repeat this process again.) 3 4. If you have an Authy account, will be added to your list of applications and you can immediately access authentication tokens. 7 5. If you do NOT have an account with Authy, you will receive a text message containing a link to install the Authy App. The Authy App is available for the following mobile devices: ios, Android and Blackberry. A Google Chrome App is also available for desktop users at chrome.google. com/webstore. 7a 6. Once the Authy App is downloaded, follow the instructions to complete the set up of your account. (See pages 5 and 6 for more information about the Mobile and Chrome Apps.) 8 7. Once this process is completed, you must Verify your Authy Account by supplying an authentication token on the Website. Access this token via: a. SMS (by clicking the link located below the token input field). Doing this will send your authentication token via text message to your mobile device. 9 b. Authy s Mobile App c. Authy s Chrome App 8. Click Enable. 9. Now that your account is enabled, every time you log into, you will be required to provide an authentication token. 4
Users Using Authy Mobile App to create authentication tokens Download the application to your mobile device through the respective app store and perform the steps below: 1. Once downloaded, open the Authy App. You will be prompted to enter your phone number s country code, which is 1 for the United States, and your mobile phone number. 2. Then enter your email address. 3. Choose to Get Account Verification via: Phone Call or SMS. 4. You will be prompted to Enter Your Registration PIN. 5. Select Don t Allow or OK to receive push notifications on your mobile device for Authy. 6. Once this process is complete you will notice that is visible in the App, and by selecting you will see the 7-digit verification code that expires and refreshes every 20 seconds. 7. Finally, use the Authentication Token provided when you sign into. 1 3 4 6 7 5
Users Using Authy Chrome App to create authentication tokens 2 5 4 1. In the Chrome browser, go to chrome.google.com/webstore. 2. Search the store for Authy and download it. 3. Once downloaded, open Chrome App Launcher. 4. Click on the Authy logo in your Chrome App Launcher. 5. You will be prompted to enter your country code and mobile number with a message underneath that states: Cellphone number should be the same you use for Authy on your mobile phone and all your other devices. Select OK. 6. You will be prompted to enter your email to create a new account. 7. Select to have verification sent via SMS or Call. 8. You will be prompted to Enter Your Registration PIN that you receive via SMS. 9. You will now see the full Authy application, however you must register a mobile device. Before doing so select the Devices tab in the Chrome App and enable Multi-Device by checking the box. 10. Finally, use the Authentication Token provided when you sign into. 7 8 9 6
2-Factor Authentication Sequence Diagram CAN BE DONE AT ANY TIME Download Authy App Create Account Login to Authy App added to Authy App Get Token 1234567 (123) 456-7890 Joe@email.com Must be same information Login to requires 2-Factor Authentication Enter Authy Credentials Verify Token LOG INTO VIEWABILL WITH 1234567 Access 7