Two-factor authentication (2FA) will be available on ThunderCloud iOS 24.1.2 & WUA 24.1.1.0 on the most recent releases.
User Prerequisites
2FA requires all Thundercloud users to receive a six-character PIN code through e-mail or SMS text. Team administrators must configure individual users to receive their PIN code through Thundercloud SSO. Each user's notification method must be updated before teams have the 2FA feature enabled by Catapult. The notification method must be updated through the edit user form in SSO.
User Workflow
Once 2FA is enabled in SSO, the user will receive a prompt to enter a PIN code. Enabling the Remember Device option will provide the user with 30 days of access to the application before they're prompted to enter a new PIN code.
If the user inputs an invalid code, an error will appear: “Invalid authentication code”:
Users without a valid notification method will receive an error message alerting them of the 2FA requirement.
FAQ
What does my team need to do to enable Two-Factor Authentication?
- Update your Thundercloud users in TC SSO to receive e-mail or SMS notifications and verify each user has valid contact information. Catapult recommends using e-mail as the best option to receive notifications.
- Update all of your users iOS devices to Thundercloud version 24.1.2 and Windows Thundercloud version 24.1.1.0.
- Contact Catapult Support to enable Two-Factor Authentication for your organization.
Does Two-Factor Authentication work with any Thundercloud app version?
No, Two-Factor Authentication will only be supported when users are on Thundercloud iOS version 24.1.2 or Windows app version 24.1.1.0. All future Thundercloud app updates will include support for Two-Factor Authentication.
Do users need to have an internet connection to receive a PIN code?
Yes, users who've opted into e-mail PIN notifications will require internet access to receive and validate their PIN codes.
How often do users need to enter a PIN code?
If Remember Device is checked, a new PIN will not be required for 30 days. If it is unchecked, users will be prompted to enter a PIN code during every login.
What happens if users are working offline without an internet connection?
Users will not be prompted for a PIN code when they log in offline.
Do users need to use Two-Factor Authentication when accessing Imported Media?
No, the Two-Factor Authentication requirement does not extend to accessing the Imported Media section of the Thundercloud apps.
Can users opt out of Two-Factor Authentication?
No, individual users do not have an option to opt out of Two-Factor Authentication. However, a team administrator can configure individual users to bypass 2FA by updating a user setting in Thundercloud SSO. The TC Two-Factor Authentication Bypass can be configured through an individual user Product Permission called TC Two-Factor Authentication Bypass.
Comments
0 comments
Please sign in to leave a comment.