The Access Identity 2FA enforcement links directly to a domain rather than a user. Once you set up a domain for forced 2FA, this covers all users with email addresses within the domain.
Note: When configuring SSO or 2FA please ensure your business allows emails from noreply@accessacloud.com so you can receive the verification emails.
To configure 2FA for a domain in Access Identity, follow the steps in each section below.
Identify your domains
Your domains are on the right-hand side of your email addresses after the @ symbol. Usually, it's your company name followed by .com or .co.uk, for example, if the email address is test.test@theaccessgroup.com, the domain is theaccessgroup.com.
β
We recommend you use at least one email address from each domain you need to register, and ensure you can test emails with at least one user per domain.
β
If you're unsure, we recommend you contact your IT team.
Identify who manages your domain
Usually, someone from your IT department or HR team has access to the domain name server (DNS). You need to identify who can add a TXT record to this, to verify ownership of the domain.
Register for Access Identity
If you haven't already, you need to register each domain with Access Identity, and register at least one email address per domain. To do this, go to https://identity.accessacloud.com/ and click Create New Account.
β
Once you've done this, all other users automatically move to Access Identity, without any impact on how they log in.
Set up your domain
Complete the Access Identity Federation configuration for each domain. Your domain manager can assist you with this.
Note: 2FA and SSO are included in all Paycircle packages.
Set up forced 2FA
All users from a registered domain need to use 2FA to log in. To set this up, follow the steps below.
In your Access Identity account, click Security policies.
Select Add security policy.
Under Two-factor authentication, click Force two-factor authentication.
Click Save changes then click Domains.
Next to the relevant domain, click the Edit icon.
Assign your security policy.
Run a test
To test your setup, log out of Access Identity then go back to the homepage https://identity.accessacloud.com/ and enter your email address. When you click Next, if forced 2FA has applied, a prompt appears to set up 2FA.
β
Going forward, this becomes a mandatory login step for all users with the same email domain.