Multi-Factor Authentication (MFA) controls access to your SmartSimple system by requiring users to verify their identity with two or more forms of evidence before they can log in. A compromised password alone is not enough to gain access, because an attacker would also need the user's authentication device. SmartSimple offers two MFA methods: Time-Based One-Time Password (TOTP) and Single-Use Verification Code. If a role is assigned to both methods, only TOTP is used.
Who: Global administrators
When to Use Multi-Factor Authentication
Use Multi-Factor Authentication when:
- Your organization requires an additional security layer beyond username and password for users with elevated access.
- Global administrators or internal staff need stronger authentication than a password alone provides.
- Your organization must meet security compliance requirements that mandate multi-factor authentication.
- Reducing risk from compromised passwords across your user base.
Enable Multi-Factor Authentication
To enable multi-factor authentication (MFA) for your instance:
- Click the System Administration gear in the upper navigation bar, select Global Settings from the drop-down menu, and then click the Security tab.
- Locate the Business Security section, and click Password and Activation Policies.
- Locate the Authentication Options section, and then toggle Enable Multi-Factor Authentication on.
- Click the Roles with Time-Based One-Time Password (TOTP) field and select the relevant roles that require TOTP authentication.
- This assigns one or more roles to TOTP authentication, verified through an authenticator app such as Google Authenticator or Microsoft Authenticator.
- Click the Roles with Verification Code via SMS or Email field and select the relevant roles that require email or SMS verification.
- This assigns one or more roles to verification code authentication via email or SMS. Users choose their preferred delivery method at login.
- Click Save.
Configure Time-Based One-Time Password (TOTP) Authentication
Time-Based One-Time Password (TOTP) authentication uses an authenticator app on a mobile device to generate a time-based code.
Configure TOTP for Specific Roles
To configure TOTP for specific roles:
- Click the System Administration gear in the upper navigation bar, select Global Settings from the drop-down menu, and then click the Security tab.
- Click Password and Activation Policies.
- Locate the Authentication Options section, and then toggle Enable Multi-Factor Authentication on.
- Click the Roles with Time-Based One-Time Password (TOTP) field and select the relevant roles that require TOTP authentication.
Toggle Enabled Trusted Device on to allow users to bypass MFA entry on a recognized device, and then click Trusted Device Expiry and enter the number of days before the bypass expires.
- Click Save.
Log In for the First Time With TOTP
When TOTP is enabled for a user's role, the user sees the Set Up Multi-Factor Authentication screen on their next login. To log in using TOTP:
- Download and install an authenticator app on your mobile device. Supported apps include Google Authenticator, Microsoft Authenticator, and 2FAS.
- Open the authenticator app and select the option to add a new account or scan a QR code.
- On the Set Up Multi-Factor Authentication screen, click Show TOTP Key and QR Code to display the QR code and secret key.
- In the authenticator app, scan the QR code or enter the secret key manually.
- The app adds a new account entry.
- The app generates a time-based verification code. Click the Enter Verification Code field and enter this code, and then click Submit.
Set Roles That Can Reset TOTP
To set which roles can reset TOTP for other roles:
- Click the System Administration gear in the upper navigation bar, select Global Settings from the drop-down menu, and then click the Users tab.
- Locate the General Settings section, and then click Roles.
- Click the edit [pencil] icon next to the role to authorize for resetting TOTP.
- Click the Permissions tab.
- Click the Roles this role can reset TOTP for field, select the relevant roles from the drop-down menu, and then click Save.
Reset a User's TOTP
TOTP can be reset by a global administrator or by a user in a role that has been granted permission to reset TOTP for other roles. To reset TOTP for a user:
- Click the Menu icon in the upper navigation bar, and then select People from the drop-down menu.
- Click the profile of the user whose TOTP needs to be reset.
- Click the Actions tab.
- Select Edit Roles and Access from the drop-down menu.
- In the modal window, click Reset TOTP.
The user can now log in and follow the prompts on the Set Up Multi-Factor Authentication screen.
Configure Verification Codes
A single-use verification code is a uniquely generated number sent to the user via email or SMS. Verification codes expire within a few minutes, so users are prompted for a new code at each login. Use the procedures in this section to configure email or SMS verification.
Configure Verification Codes for Email
To configure email verification:
- Click the System Administration gear in the upper navigation bar, select Global Settings from the drop-down menu, and then click the Security tab.
- Locate the Business Security section, and then click Password and Activation Policies.
- Locate the Authentication Options section, and then toggle Enable Multi-Factor Authentication on.
- Click the Roles with Verification Code via SMS or Email field and select the relevant roles that require email or SMS verification.
- Click Save.
Log In With a Verification Code
To log in when a verification code is required:
- Log in with your email address and password. The MFA verification screen appears.
- Click Send Code by Email.
- Open your email and locate the verification code message.
- Enter the verification code in the field provided, and then click Submit.
Configure Verification Codes for SMS
To send SMS verification codes, set up a Vonage account for your organization.
After setting up your Vonage account:
- Click the System Administration gear in the upper navigation bar, select Global Settings from the drop-down menu, and then click the Integrations tab.
- Locate the Services Settings section, and then click Integration Key Management.
- Click the New Integration Key [+] button.
- Click the Type field and select Vonage from the drop-down menu.
- Enter your Vonage API Key, API Secret, and either a North American or International virtual number, and then click Save.
Log In With an SMS Verification Code
To log in when an SMS verification code is required:
- Log in with your email address and password. The MFA verification screen appears.
- Click Send Code by Text Message.
- Open your mobile messages and locate the verification code.
- Enter the verification code in the field provided, and then click Submit.
Bypass MFA for Single Sign-On
When MFA is enabled, you can configure individual SSO settings to bypass MFA for users who log in through single sign-on. To bypass MFA for single sign-on:
- Click the System Administration gear in the upper navigation bar, select Global Settings from the drop-down menu, and then click the Integrations tab.
- Click Single Sign-On.
- Click the edit [pencil] icon next to the SSO setting to update.
- Toggle Bypass Multi-Factor Authentication (MFA) when logging in with Single Sign-On (SSO) on, and then click Save.
Set Up a Default Email Address
A default email address is required for MFA verification emails to send correctly. If you use SMTP relay or a dedicated instance with your own domain, set the default email address to match that domain. Otherwise, use the appropriate SmartSimple mailer address for your region:
donotreply@smartsimplemailer.com (US),
donotreply@smartsimplemailer.eu (Europe), or
donotreply@smartsimplemailer.ca (Canada).
To set up a default email address:
- Click the System Administration gear in the upper navigation bar, select Global Settings from the drop-down menu, and then click the Communications.
- Locate the General Settings section and click Email Options and Security.
- Toggle Enable Default From Address on.
- Enter your preferred From Address, and then click Save.