Multi-Factor Authentication (MFA) Updated 09/05/2017 10:00 AM EST Modified by HM Riggert 10/17/17
Multi-Factor Authentication (MFA) What is it? Utilizing something other than normal login information to authenticate yourself. Why implement MFA? Due to the heightened awareness of personal identity theft and the growing world of cyber threats, With sites using borrowed computers and/or computers in locations such as libraries and community centers, MFA adds an additional layer of protection. It takes less than 10 minutes for a cyber criminal to crack an eight characters strong password
Implementing MFA What is the implementation plan? Currently, the MFA is fully implemented except for selecting the re-authenticate interval Login changed to just be User Name and Password and volunteer secret questions are deleted. What can site admins do before the start of tax season? Review the active users currently setup at your site to ensure they have unique email addresses. The MFA system will validate the uniqueness of the email address during the authentication process. Receiving a text message with the code is also an option and will also require a unique cell phone number.
Step 1: Updating your Preparer Information At first login since last season You will be prompted to complete an Account Update page Enter or change the cell phone number Enter or change the email address Enter your existing password Click Update Note: Email addresses must be unique unless designated for multiple use by the administrator
Finishing the Update Process MFA will trigger for the user in 7 days after completing the update page By default, it is set to re- authenticate after 7 days. Site Admin will have the ability to change this from 1 to 30 days depending on the site needs.
Automatic updates to the Preparer Information Information entered or changed during the update process automatically updates the information for the user name in the Preparer(s) menu.
MFA Challenges My volunteers have multiple user names Site Administrator has the ability to designate an email address to be used with multiple user names I am not sure if my host site will allow access to retrieve the code from the email account on file. Allow your SPEC relationship manager to work with your host site.
Designating an email address to be used by multiple usernames Site administrator can allow multiple usernames to use the same email address if: The same person volunteers at multiple sites The same person has multiple usernames per site due to tracking different SIDNs for ‘ad hoc’ locations
Step 2: Time to Authenticate When required to authenticate, the Account Verification page will be displayed Select a delivery option If a cell phone number is not listed for the user, they will not see the Text option Select Send Code The user will see a verification that the code has been sent – Code is sent within a few seconds
Step 3: Enter the Authentication Code Enter the verification code Click Verify Once the code is authenticated the user will be taken to the Welcome page
When is authentication required? The first time a user logs in from a different computer I logged in to a different computer and had to authenticate. I went back to the original computer and did not have to authenticate. When their authentication has expired Defaults to 7 days When a computer is re-imaged Three failed login attempts
Questions and Answers Q: Would a TaxSlayer update wipe out the MFA Authentication? A: No, we do not anticipate this happening. Q: Would a computer or browser update wipe out the MFA Authentication? A: We have not experienced this with our other software applications currently using MFA. If the host site performs some type of maintenance on the computers on a nightly basis (such as wiping them and applying a fresh profile), the users will have to authenticate each day Q: Can I turn MFA off at my site? A: No
Authorization Code FAQs Q: Does the authorization code reference the user that it is for? A: No, Both Text and email notifications indicate it is a code for TaxSlayer (No URL) and a 6 digit code. Q: Once a code is used, does it immediately become cancelled, or can it potentially be used more than once? A: The authorization code is a one-time use code. Q: Is there a number of times the user can attempt to enter the code before the application locks? A: We do not lock the application based on attempts to enter the authentication code. However, if you have 3 missed login attempts, you will be prompted for MFA Q: Is there a limit for how many requests can be made for a specific user name? A: No, not at this time.