Multi Factor User Manual v3

Download as pdf or txt
Download as pdf or txt
You are on page 1of 14

Multi Factor Authentication

User Manual

Information in this document is subject to change without notice.


No part of this document may be reproduced or transmitted in any form or by any means, for any
purpose, without the express written permission of TEMENOS HEADQUARTERS SA.

© 2016 Temenos Headquarters SA - all rights reserved.


Multi Factor Authentication – User Manual

Contents
Contents ...................................................................................................................................................................... 2
Multi Factor Authentication @ Temenos ..................................................................................................................... 3
Temenos MFA Portal .................................................................................................................................................. 4
How to Enroll in MFA ............................................................................................................................................................... 4
Microsoft Authenticator App ..................................................................................................................................................... 6
Changing MFA Method ............................................................................................................................................................ 7
Changing phone number ......................................................................................................................................................... 8
Changing language .................................................................................................................................................................. 9
Temenos Secure Access Portal with MFA .................................................................................................................. 9
Secure Access Portal with Mobile Phone Call ......................................................................................................................... 9
Secure Access Portal with SMS ............................................................................................................................................ 10
Secure Access Portal with Authenticator App........................................................................................................................ 10
Secure Access Portal with OATH .......................................................................................................................................... 11
Temenos Emails Access with MFA ........................................................................................................................... 11
Outlook Web Access with Mobile Phone Call ........................................................................................................................ 12
Outlook Web Access with SMS ............................................................................................................................................. 12
Outlook Web Access with Authenticator App......................................................................................................................... 13
Outlook Web Access with OATH ........................................................................................................................................... 13

Temenos IT Security

2
Multi Factor Authentication – User Manual

Multi Factor Authentication @ Temenos

Unauthorized access to Temenos resources is a key concern for our company. The main goal of the
Multi-Factor Authentication solution implemented by Temenos is to reduce this risk, by making it more
difficult for cyber criminals to breach your account.
Multi-Factor Authentication (MFA) is a best practice that
adds an extra layer of protection on top of your user name and password.
At Temenos, The MFA is currently used for providing multi-factor authentication for access to:
 Temenos Email, via Outlook client or Outlook Web Access (OWA)
 Temenos corporate resources via the Secure Access Portal

This purpose of this document is to:


 Help Temenos members of staff enroll in the Multifactor Authentication solution using a
dedicated Portal
 Explain the functionality of the Multifactor Authentication Solution when accessing Temenos
Corporate Assets from outside of the Temenos corporate network

Multi-Factor Authentication (MFA) is a second step of authentication required for accessing company
assets when working away from the Temenos Corporate network (i.e. home networks, mobile
networks, public networks or client networks). Using the enrollment process, you will be able to
specify your preferred method of identity verification. This can be any of the following options listed in
the table below:
• Mobile Phone Call - Places an automated voice call to the authentication phone
number. The user answers the call and presses # in the phone keypad to
authenticate.
• Mobile Phone Text Message - Sends a text message containing a verification code
to the user. The user is prompted to enter the verification code into the sign-in
interface.
• Mobile App - Pushes a notification to the Authenticator mobile app on the user’s
smartphone or tablet. The user taps Verify in the app to authenticate. Alternately, the
app can also be used as an OTP token for offline authentication. The user enters the
token into the sign-in screen to authenticate.

Temenos IT Security

3
Multi Factor Authentication – User Manual

Temenos MFA Portal


How to Enroll in MFA
Once your Temenos account has been configured for MFA by the IT Security Team (you will receive
an email from mfa@temenos.com with this instructions), you will need to go through the enrolment
process in order to specify the preferred method of identity verification.
Temenos members of staff will need to enroll their mobile device in the Temenos MFA portal that can
be accessed using the below URL:
https://mfa.temenos.com
Please use your domain credentials to login to the MFA portal:

Figure 1 – Microsoft MFA Enrolment Login

Right after login, you will be requested to specify the mobile phone Area Code and Phone number,
then press Next button. (It is recommended to use your corporate mobile phone if you have one)

Figure 2 – Microsoft MFA Phone number setup

Next step is to set the 4 security questions and their answers. These security questions will be used
in case the mobile devices are unavailable for MFA authentication:

Temenos IT Security

4
Multi Factor Authentication – User Manual

Figure 3 – Microsoft MFA Security questions setup

Please click “Continue” to submit the form. Next page will be displaying the Welcome message:

Temenos IT Security

5
Multi Factor Authentication – User Manual

Figure 4 – Microsoft MFA Welcome screen

Microsoft Authenticator App


Once enrolment is complete, we recommend that you install the Microsoft Authenticator app.
The Authenticator app is available for Windows Phone, Android, and IOS and can be downloaded
and installed from Microsoft Store, Google Play or App Store.
After the app has been installed on your device, you will need to activate the mobile app. Please
go to the “Activate Mobile App” in the MFA portal and click on “Generate Activation Code”. The
activation code will be entered in the mobile app to complete the activation process. The
activation code expires in 10 minutes. You may generate a new code at any time.

Temenos IT Security

6
Multi Factor Authentication – User Manual

Figure 5 – Microsoft MFA Mobile App Activation

Launch the app on your mobile device and add a “New work or school account”. Use your device's camera to
scan the QR code, and then select “Done” to close the QR code screen.

Changing MFA Method


You may change the identity verification method at any time after enrolment.

Temenos IT Security

7
Multi Factor Authentication – User Manual

This can be done from the MFA portal using the “Change Method” option available on the left side
pane.
The available verification methods are:
1. Phone Call
2. Text Message
3. Mobile App
4. OATH Token
Please use the drop-down list to select the preferred identity verification method and click “Save”.

Figure 6 – Change MFA method

Changing phone number


You may change the registered phone number in the “Change Phone” section of the MFA portal.
Please enter the new phone number and click “Save”:

Figure 7 – Change MFA phone number

Temenos IT Security

8
Multi Factor Authentication – User Manual

Changing language
You many change the language for each method of identity verification in the “Change Language”
section of the MFA portal.

Figure 8 – Change MFA Language

Temenos Secure Access Portal with MFA

To access Temenos Secure Access Portal you may use the below URL:
https://portal.temenos.com
Please choose the portal nearest to your location from the available list.
You will need to use your corporate domain credentials to login, and, depending on the selected
Multi-Factor Authentication method:
• allow access from mobile App
• enter the number shown in the mobile app answer the
phone call and press # key enter the PIN number received via
SMS.
Please note that you will be required to use the secondary identity verification method only when
accessing the portal from non-Temenos networks (i.e. home, client, public networks).

Secure Access Portal with Mobile Phone Call


If the MFA method is set to “Phone call”, after entering the username and password, you will receive
a phone call. Please answer the call and press “#” key in order to confirm the identity.

Temenos IT Security

9
Multi Factor Authentication – User Manual

Figure 9 Secure Access Portal using Mobile Phone Call

Please note that the login page will remain in “loading” state for 30 second, until access is approved
or denied from the mobile phone.

Secure Access Portal with SMS


When using the SMS method, after entering the username and password, a new page is shown
where you will be asked to enter the code received via the SMS message:

Figure 10 Secure Access Portal using SMS method

Secure Access Portal with Authenticator App


When using the Mobile Authenticator App, after entering username and password, you will receive a
PUSH message on your phone that will give you the option to approve or deny access to the Secure
Access Portal. The PUSH message will work as long as the mobile device has Internet Connectivity
(via Wi-Fi or mobile data).

10

Temenos IT Security

10
Multi Factor Authentication – User Manual

Figure 11 Secure Access Portal using Mobile App

Secure Access Portal with OATH


When using the OATH method, then the one time code from the Mobile Authenticator app will need to
be entered in the login page.

Figure 12 Secure Access Portal using OATH Mobile App Authentication

Temenos Emails Access with MFA


11

Temenos IT Security

11
Multi Factor Authentication – User Manual

To access your Temenos emails in a web browser on a mobile device, please use the below URL:
https://outlook.office.com
The same method of authentication method you have selected in the previous steps will apply here.
In order to access your emails via an email client on your mobile device we recommend that you
install the Microsoft Outlook mobile client (this is available in Google Play/App Store). Other email
clients, including the native clients for Android and iOS are not fully compatible with MFA. For any
issues with the email mobile client we recommend that you remove the Temenos Exchange
ActiveSync account from your mobile device and re-add it. If the issue persists, please contact IT
Service Desk at itservicedesk@temenos.com

Outlook Web Access with Mobile Phone Call


If the MFA method is set to “Phone call”, after entering the username and password, you will receive
a phone call. Please answer the call and press “#” key in order to confirm the identity.

Figure 13 Outlook Web Access with Phone Call

Outlook Web Access with SMS


When using the SMS method, after entering the username and password, a new page is shown
where you will be asked to enter the code received via the SMS message:

12

Temenos IT Security

12
Multi Factor Authentication – User Manual

Figure 14 Logging to Office365 using SMS authentication

Outlook Web Access with Authenticator App


When using the Mobile Authenticator App, after entering username and password, you will receive a
PUSH message on your phone that will give you the option to approve or deny access to the Outlook
Web App. The PUSH message will work as long as the mobile device has Internet Connectivity (via
Wi-Fi or mobile data).

Figure 15 Logging to Office365 using Mobile App authentication

Outlook Web Access with OATH


When using the OATH method, then the one time code from the Mobile Authenticator app will need to
be entered in the Passphrase field.

13

Temenos IT Security

13
Multi Factor Authentication – User Manual

Figure 16 Logging to Office365 using OATH Mobile App authentication

14

Temenos IT Security

14

You might also like