Skip to main content
Version: 6.14

Multi-Factor Authentication (MFA)

Multi-Factor Authentication provides additional account security by prompting users to enter an additional code when logging in to ICA.

The code is generated automatically by the user's authenticator device, typically an app on their smartphone, and changes frequently.

note

Logins to the Patriot smartphone app (Plink) support all ICA login features as of Patriot version 6.13.2.0, Plink version 13.2.2.

Enable Multi-Factor Authentication

Log in to ICA and open the user's account menu in the top right.

Select Manage MFA to open the Manage Multi-Factor Authentication modal, then click the + button next to Authenticator app.

Manage MFA Menu
Account Menu > Manage MFA
Add Authenticator App
Add Authenticator App
Enable MFA Modal
Enable Multi-Factor Authentication modal

Any authenticator app will do; below are links to the Google Authenticator app.

Get it on Google Play

Download on the App Store

Use an authenticator app to scan the QR Code that is displayed.

Once the app has scanned the QR Code, it will provide the user with a code that changes every 30 seconds. Enter this code into the Authentication Code field and click Save.

That account is now registered for Multi-Factor Authentication.

Log in with Multi-Factor Authentication enabled

When a user logs in with Multi-Factor Authentication enabled, they will be prompted for an authentication code.

The user must enter the current code from their authenticator app.

MFA Login
Login using MFA

Mandatory Multi-Factor Authentication

Mandatory Multi-Factor Authentication can be enabled for specific Security Groups. Any user or operator in the security group will be required to set up a Multi-Factor Authentication method when logging in to ICA.

Email Multi-Factor Authentication

note

The Email Task must be installed to use Email Multi-Factor Authentication.

Email Multi-Factor Authentication can be enabled for user or operator use. Allowing Email as a Multi-Factor Authentication Method must be enabled for specific Security Groups.

Any user or operator in the security group will have the option to use an Authenticator app or Email as a Multi-Factor Authentication method. During setup, a 6-digit code is sent to the account email that must be used to authenticate. The same happens at each login. If the user has not set up an account email, they will be prompted to do so first.

Enable MFA Menu With Email
Add Authenticator App or Email code
Enable MFA Email Modal
Enable Email Multi-Factor Authentication modal

If an Authenticator app and Email code have both been set up, the user will be able to choose either authentication option on login.

Disable Multi-Factor Authentication

note

This option is not available if Mandatory Multi-Factor Authentication is enabled for the user.

Log in to ICA and open the user's account menu in the top right.

Select Manage MFA to open the Manage Multi-Factor Authentication modal, then click the - button next to the enabled method.

Manage Enabled MFA Menu
Account Menu > Manage MFA
Remove Authenticator App or Email
Remove Authenticator App or Email
Disable Multi-Factor Authentication modal
Disable Multi-Factor Authentication modal

Enter the current code that appears in the user's Authenticator app, or the code sent to the user's email, and click Save.

Disable Multi-Factor Authentication as an operator

This requires an operator with privileges to edit operators.

Disabling Multi-Factor Authentication for operators

Log in to Patriot, then navigate to the operator menu.

Operator menu on the security tab
Operator menu on the security tab

Select the operator that needs Multi-Factor Authentication turned off.

Disable Multi-Factor Authentication on an operator
Disable Multi-Factor Authentication on an operator

Select the Disable Multi-Factor Auth button.

If the operator has Mandatory Multi-Factor Authentication, they will be prompted to re-enable this on next login.

Disabling Multi-Factor Authentication for users

Open the user's User Details page in either the Users tab of a client or under User Maintenance.

In the Remote Access tab select the Disable Multi-Factor Auth button.

If the user has Mandatory Multi-Factor Authentication, they will be prompted to re-enable this on next login.

Disable Multi-Factor Authentication on a user
Disable Multi-Factor Authentication on a user