Skip to main content

Multi-Factor Authentication (MFA) Guide for redOrange.ai

Updated over a month ago

1. Introduction

Multi-Factor Authentication (MFA) adds an extra layer of security to user accounts by requiring more than just a password to log in. This guide explains how MFA works in redOrange.ai, how to enable it, and best practices to ensure your account remains secure.


2. What is MFA?

MFA requires users to provide two or more verification factors to gain access:

  • Something you know: your password

  • Something you have: a mobile device app or hardware token generating a time-based code

  • Something you are: biometric verification (not currently supported in redOrange.ai)

By combining these factors, MFA significantly reduces the risk of unauthorized access.


3. Benefits of Using MFA

  • Protects your account even if your password is compromised.

  • Helps prevent unauthorized logins and data breaches.

  • Meets compliance and security best practices.


4. How MFA Works in redOrange.ai

  • When MFA is enabled, after entering your password, you will be prompted to enter a verification code generated by an authenticator app.

  • redOrange.ai supports common authenticator apps such as Google Authenticator, Microsoft Authenticator, Authy, and others that support TOTP (Time-based One-Time Password).


5. Enabling MFA

For Administrators (Organizational Level)

  • Log in as an Administrator.

  • Navigate to Settings > Security > MFA.

  • Toggle the option to enable MFA enforcement for all users.

  • Once enabled, users will be required to set up MFA at their next login.

Note: MFA should be enabled at Organisation level by admin in order to enforce MFA enablement for individual users in the User Settings

For Individual Users (User Level)

  • Log in to your redOrange.ai account.

  • Go to your User Profile (top-right corner).

  • Navigate to User Profile Settings > MFA > Setup MFA.

  • Scan the displayed QR code using your authenticator app.

  • Enter the generated code to verify and activate MFA on your account.


6. MFA During Login

  • After entering your username and password, you will be prompted to enter a verification code from your authenticator app.

  • Enter the current code displayed in your app to complete login.


7. Resetting or Disabling MFA

Users

  • If you lose access to your authenticator app, contact your Administrator or support team for MFA reset assistance.

Administrators

  • Can reset MFA for users under Access Management > Manage Users > [User Name] > Quick Actions.

  • Users will be prompted to set up MFA again at their next login.


8. Best Practices

  • Use a trusted authenticator app that supports TOTP.

  • Do not share your MFA codes with anyone.

  • Enable MFA on all accounts that support it for maximum security.

  • Educate users on recognizing phishing attempts and protecting their authentication devices.


9. Troubleshooting

Issue

Solution

Authenticator app code not accepted

Ensure device time is synced; re-scan QR code if needed

Lost or reset authenticator device

Contact admin to reset MFA on your account

MFA prompt not appearing

Confirm MFA is enabled at org level or user level


10. Contact Support

For assistance with MFA setup, issues, or resets, please contact:

Did this answer your question?