For the complete documentation index, see llms.txt. This page is also available as Markdown.

Multi-factor Authentication

Safeguard against potential unauthorized access to your tools

Multi-factor authentication (MFA) is a best-practice authentication method that improves security for user accounts and access requests. It adds an extra layer of verification beyond traditional username and password credentials.

Apono's implementation of MFA allows administrators to enforce additional authentication for specific access flows, particularly for sensitive environments or data.

When MFA is enabled for an access flow, you gain the following key benefits:

  • Enhanced security that blocks nearly 100% of automated account attacks

  • Access to Apono logs that record when MFA was performed

  • Support for all major authenticator apps


Enable MFA for a requester account

If an administrator has enabled MFA for a resource you are requesting, you will need to enable MFA for your account.

Multi-Factor Authentication widget

Follow these steps to complete the integration:

  1. In the Apono UI, in the banner at the top of the page, click Set Up MFA. The Privacy & Security window appears.

lightbulb
  1. Under Multi-Factor Authentication, in the Add Authentication App box, click Set up. The Multi-Factor Authentication pop-up window appears.

  2. Follow the on-screen prompts to complete the authentication setup. The MFA callout banner will disappear.

For any MFA-protected request, you will need to enter the six-digit code from your authenticator app. Your successful MFA will persist for an hour and apply to any requests made within this time.


Reset MFA for a requester account

Only account admins can reset multi-factor authentication, including for themselves.

In instances when a user is unable to complete MFA verification due to a lost device or misconfigured authenticator, the user's MFA can be reset. The user can then log in and set up MFA again.

Resetting MFA removes the user’s current MFA enrollment. This change takes effect immediately and applies to the user across all Apono UIs they can access.

Users tab

Follow these steps to reset MFA for a user account:

  1. On the Users tab, enter the user's name or email address in the search box. The list is filtered to the matching user.

lightbulb
  1. In the row of the user, click (reset MFA icon). The Reset MFA confirmation pop-up window appears.

  2. Click Reset MFA. The pop-up window closes. The user is unenrolled from multi-factor authentication.

Once unenrolled, the user can enable MFA for their account again.

Last updated

Was this helpful?