MFA Handover Notes
Overview: Implementing the option for all users to enable multifactor authentication on their account. Providers (Organisation Managers) can enable/disable MFA for specific user types.
Order of events:
- Admin enable MFA on an organisation
- Organisation manager has the option to enable on user types (OMs, Teachers, Students)
- Individual User then has the option to enable on their own account
- This includes setting up MFA by inputting a code sent to their email
- At present, non organisation users won't have the option to set up MFA
- Currently, once a user has MFA enabled and set up on their account, the only way to disable it for the user is for their OM to disable it for their user type, or for admin to disable it for their organisation (obviously both of these have effects on other users within the org)
MFA needs to be enabled on the site relevant to the organisation for it to work for the organisation.
- At present, it is only enabled on PFS
(ADMIN) How to enable MFA for an organisation within Nova:
https://app.supademo.com/demo/cmg6g3mxcar0910k8rt3275wb?utm_source=link
How to enable MFA per user (as an OM):
https://app.supademo.com/demo/cmg6hb15uat3510k8cxy10rki?utm_source=link
How to set up MFA as a user:
- Visit their profile page on the platform
- Click enable Multifactor Authentication
- View the code sent to their email inbox
- Input the code
- Any future login will require the same steps (unless disabled for the user's user type by an organisation OM)