Multi-Factor Authentication (MFA) within the Cyturus Application
Gain an understanding of what MFA is, and how it's employed within the Cyturus application.
Last Updated: February 14, 2024
The use of MFA has become more and more common in various industries and sectors. MFA is a security measure that adds an extra layer of protection to the authentication process. It requires users to provide multiple forms of identification before they can access a system or application. This added security significantly reduces the risk of unauthorized access and potential data breaches.
Implementing MFA involves integrating different authentication factors. These factors include something the user knows (like a password or PIN), something the user has (like a physical token or smartphone), and something the user is (like biometric data such as fingerprints or facial recognition). By combining these factors, MFA ensures a higher level of security compared to traditional single-factor authentication methods.
MFA can be implemented in various ways, depending on the specific requirements and resources of an organization. For example, some companies may choose to employ MFA through the use of hardware tokens that generate unique codes. Users are then required to enter these codes along with their passwords. Alternatively, software-based solutions can be utilized, which leverage mobile apps to generate one-time passwords or send push notifications for authentication. Moreover, biometric authentication methods like fingerprint or facial recognition can also be integrated into MFA systems, providing an additional layer of security. In today's digital landscape, the adoption of MFA is essential for safeguarding sensitive information and preventing unauthorized access.
In the Cyturus application, MFA is automatically enabled for all users not utilizing SSO capabilities. However, PBC customers who self-administrate their system have the flexibility to enable or disable MFA functionality, as well as specific MFA types, to suit their business requirements. We offer two MFA methods: email and authenticator app, and a third non-standard option of SMS.
1. Email (Default) - A six-digit code will be sent to the user's registered email address.
2. Authenticator App - Users can request a code from their registered authenticator app (such as Microsoft or Authy).
3. SMS (PBC customers with an SMS subscription only) - A six-digit code will be sent to the user's registered mobile phone number.
Users who utilize SSO for logging into the Cyturus application are exempt from MFA requirements.