Skip to main content

OrgChart Help Guide

Multi-Factor Authentication

Audience

Audience: Administrators Edition: Enterprise

Overview

Multi-Factor Authentication (MFA) is a security feature that adds an additional layer of protection to your account by requiring users to enter a unique code, in addition to their username and password, in order to sign in.

OrgChart users can enable MFA and use any popular authentication app (i.e. Google Authenticator) to access their account.

Admins can require users to use MFA, easily audit which users have MFA configured, and even override the requirement for certain users.

This article provides step-by-step instructions for enabling MFA in your OrgChart account.

Important

MFA does not interfere with SSO configurations or embedded web links.

Users that access the application via SSO or via a link embedded in your company's intranet will not be asked to re-authenticate with MFA.

Enabling MFA

  1. Log in to OrgChart.

  2. Click on the My Settings menu in the top right corner, and then select the Preferences option.

    My_Settings_Select_Preferences.png
  3. Click on the Multi-Factor Authentication Settings button.

    Pref_MFA_Select.png
  4. Follow the three steps outlined in the MFA Settings dialog, and then click on Verify Code and Activate.

    MFA2.png
  5. MFA is now activated.

Signing In with MFA

  1. Navigate to your OrgChart server.

  2. Enter your username and password, and then click on Sign In.

  3. Open your authenticator app, and locate the entry for OrgChart.

  4. Enter the unique six digit code into the text boxes, and then click on Sign In Securely.

    Sign_in_MFA.png

Administering MFA

After an Admin configures MFA for themselves, they will have access to the following additional MFA options:

Requiring MFA for All Users

Admins can require all users to use MFA in order to sign in to the application. We suggest that Admins prompt their users to set up their MFA before requiring it at the account level.

  1. Log in to OrgChart.

  2. Click on the Mode Switcher icon in the Top Toolbar, and then select the Setup option. The Setup panel is displayed.

    Setup_Account_Settings_Select.png
  3. Click on the Account Settings tile, and then select the Authorization option from the left side menu.

    5_3_1_Account_Settings_Authorization.png
  4. Check the Multi-Factor Authentication is Required to Login checkbox.

    Require_MFA.png

    Important

    Admins have to configure MFA for themselves before they can require it for all users. If you have not yet configured MFA for your own user, you will be prompted to do so.

  5. If some users have not yet configured MFA, the following alert is spawned:

    MFA_Users_Not_Configured.png

    Click on No to not require users to sign in with MFA. You can then audit user MFA status and contact those who still need to configure MFA. Reference the Audit User MFA Status section below for more information.

    Click on Yes to require users to sign in with MFA. You can send one-time login emails to users that have not yet configured MFA, or override MFA for certain users. Reference the MFA Setup Link and Overriding MFA sections below for more information.

Audit User MFA Status

Admins can easily audit the MFA status of each user in the Account Settings: Manage Users panel.

Audit_MFA_Status_Manage_Users.png

Optionally, you can click on the 5_2_DownloadData_FileManager.png icon in the top right corner to export an Excel Spreadsheet of your users. You can filter by MFA status in this report.

MFA Setup Link

Once MFA is required for users to sign in, Admins can send individual users a one-time login email containing MFA setup instructions directly from the Account Settings: Manage Users panel.

  1. Mouse over the user, and then click on the 5_2_1_Pencil.png icon.

  2. Click on the Email MFA Setup Link option.

    MFA_One_Time_Login_Email.png
  3. An email containing setup instructions is sent to the user. The user's MFA status will update as soon as the user configures MFA.

Overriding MFA

Admins can choose to override the MFA requirement for certain users in the Account Settings: Manage Users panel.

  1. Mouse over the user, and then click on the 5_2_1_Pencil.png icon.

  2. Check the Override Multi-Factor Authentication checkbox. The MFA Status is changed to 'Bypassed.'

    Override_MFA.png
  3. Click on Update.

Note

MFA does not apply to users signing in to the application via SSO, or users who click on web links embedded in their intranet. You do not need to override MFA for users who sign in via SSO or for users that are attached to web links.