Multi-Factor Authentication (MFA) controls access to your SmartSimple system by requiring users to verify their identity with two or more forms of evidence before they can log in. A compromised password alone is not enough to gain access, because an attacker would also need the user's authentication device. SmartSimple offers two MFA methods: Time-Based One-Time Password (TOTP) and Single-Use Verification Code. If a role is assigned to both methods, only TOTP is used.
Who: Global administrators
When to Use Multi-Factor Authentication
Use Multi-Factor Authentication when:
- Your organization requires an additional security layer beyond username and password for users with elevated access.
- Global administrators or internal staff need stronger authentication than a password alone provides.
- Your organization must meet security compliance requirements that mandate multi-factor authentication.
- You want to reduce risk from compromised passwords across your user base.
How Multi-Factor Authentication Works
Time-Based One-Time Password (TOTP)
TOTP generates a time-based verification code through an authenticator app installed on the user's mobile device. The code changes at regular intervals. On first login after TOTP is enabled for their role, users pair the app with their SmartSimple account by scanning a QR code displayed on the setup screen. Supported apps include Google Authenticator, Microsoft Authenticator, and 2FAS.
Single-Use Verification Code
A single-use verification code is a uniquely generated number sent to the user via email or SMS. Verification codes expire within a few minutes, so users are prompted for a new code each time they log in. Email is available without additional setup. SMS requires a Vonage account and must be enabled by SmartSimple.
Trusted Device
When Trusted Device is enabled for a role, users who successfully enter a TOTP code on a recognized device can bypass MFA entry for a specified number of days. Administrators set the expiry period. When the period lapses, the user is prompted for a code again.
Single Sign-On Bypass
If MFA is enabled, administrators can configure specific Single Sign-On Bypass (SSO) settings to bypass MFA for users logging in through single sign-on. This setting is configured per SSO integration.
Security Implications
- MFA significantly reduces unauthorized access risk. A compromised password alone is not sufficient when the user's authentication device is secure.
- TOTP is more secure than verification codes because it does not depend on email or SMS delivery. Assign TOTP to roles with elevated system access.
- Verification codes sent via email depend on the security of the user's email account.
- Trusted Device reduces MFA friction for trusted users. Configure the expiry period to balance security and usability.
Resources
For more information about Multi-Factor Authentication, see: