Command Palette

Search for a command to run...

Log In
  1. Administration
  2. Settings
  3. Security Settings
  4. Enforcing 2FA on your Astalty account

Enforcing 2FA on your Astalty account

Overview

This guide will outline the process of enforcing 2FA (Two-Factor Authentication) on your Astalty account. This is done via the Security Settings menu.

Enforcing 2FA

Astalty allows the Account Owner to enforce the use of 2FA on users with specific user roles.

Once you head to the Security settings menu you will see the option to Edit 2FA Enforcement. Click this option to update 2FA enforcement within your account.

The Two-Factor Authentication menu will slide open, where you can select the option to Enforce MFA on your account.

If selected, you will be provided with a multi-selection drop down where you can select the roles that would be required to have 2FA setup on their account.

Once you have selected the option to enable enforcement and you select Update, it will then enforce 2FA on all the users within the roles selected in your Astalty account.

Enforcement is set by role, not for individual users:

  • Admin is always included and can't be removed from Target User Roles.
  • Switching Enforce MFA on selects all four roles: Admin, Manager, Team Member and Support Worker. Remove the ones you don't want to target.
  • Auditors can't be targeted, so enforcement never applies to Auditor accounts.
  • To ask one user to set up 2FA without enforcing it, see Sending 2FA Setup Instructions.

User View After Enforcement

After enforcing 2FA, any impacted users who have not already implemented 2FA will need to immediately action this if they are currently logged in, or the next time they log in. They will not be able to navigate to any other part of Astalty until this has been completed.

Enforcement applies to the Astalty app as well as the web. A user in a targeted role without 2FA is signed out of the app the next time it loads anything from Astalty, with the message Please enable two-factor authentication by logging in again. When they sign in again, the app takes them through setup. See Setting up 2FA on the Mobile App.

Resetting Two-Factor Authentication (2FA) for a User

If a User is unable to access their account because Two-Factor Authentication (2FA) is enabled and they no longer have access to their recovery codes, the Account Owner will need to disable and then re-enable 2FA on the User’s behalf.

To do this, follow the steps below:

  1. Navigate to the Users page from the main menu and open the relevant User’s profile.
  2. Select Security from the User’s profile menu.
  3. Click Disable Two-Factor Authentication.
    A confirmation pop-up will appear—tick the confirmation box and select Disable 2FA to proceed.
  1. Once 2FA has been disabled, click Send 2FA Setup Instructions.
  1. A confirmation message will appear advising that the setup instructions have been sent to the User.

The User can then follow the emailed instructions to set up Two-Factor Authentication again and regain access to their account.

Sending 2FA Setup Instructions

While a user hasn't set up 2FA, their Security tab shows Send 2FA Setup Instructions to the Account Owner. It emails the user a link to Two Factor Authentication, with the subject You've been asked to set up Two-Factor Authentication.

The email doesn't enforce anything. The user can keep using Astalty on the web and in the app without setting up 2FA. To require it, enforce 2FA for their role.

The email doesn't help a Support Worker set up 2FA. On the web, a Support Worker is shown a prompt to use the app instead, and the app only offers 2FA setup once 2FA is enforced for the Support Worker role.

Disabling the Ability to Disable 2FA

To learn more about how to disable a users ability to disable their 2FA access click the guide article link here.