User Tools

Site Tools


faq:security:2auth

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
faq:security:2auth [2023/09/27 12:00] – [Frequently Asked Questions (FAQs)] vikkifaq:security:2auth [2024/04/02 09:48] (current) – [Frequently Asked Questions (FAQs)] vikki
Line 1: Line 1:
-[[:start|Home]] > [[:faq|FAQ]] > [[faq:security|Security]] > [[faq:security#account_security|Account Security]] > **2Auth Second Factor Authentication (Beta Release)**+[[:start|Home]] > [[:faq|FAQ]] > [[faq:security|Security]] > [[faq:security#account_security|Account Security]] > **2Auth Second Factor Authentication**
  
-====== 2Auth Second Factor Authentication (Beta Release) ======+====== 2Auth Second Factor Authentication ======
  
 Welcome to the User Guide for **2Auth** - the Second Factor Authentication for Lookafter Virtual Office (VO) and webmail system. This guide will walk you through the process of setting up and using 2FA to enhance the security of your webmail account. Welcome to the User Guide for **2Auth** - the Second Factor Authentication for Lookafter Virtual Office (VO) and webmail system. This guide will walk you through the process of setting up and using 2FA to enhance the security of your webmail account.
Line 23: Line 23:
  
 1. Log in to your VO or webmail with your email address and password. 1. Log in to your VO or webmail with your email address and password.
 +
 +|{{:faq:security:2auth:enabling-2auth:1.jpg|}}|
  
 2. Go to **Profile** > **2Auth**. 2. Go to **Profile** > **2Auth**.
 +
 +|{{:faq:security:2auth:enabling-2auth:2.jpg|}}|
  
 3. Tick the **"Enable Second Factor Authentication"** checkbox. 3. Tick the **"Enable Second Factor Authentication"** checkbox.
 +
 +|{{:faq:security:2auth:enabling-2auth:3.jpg|}}|
  
 4. **Enter an email address** that will act as your 2Auth Email. This email will receive the OTP codes generated by the 2Auth system on your subsequent logins. 4. **Enter an email address** that will act as your 2Auth Email. This email will receive the OTP codes generated by the 2Auth system on your subsequent logins.
 +
 +|{{:faq:security:2auth:enabling-2auth:4.jpg|}}|
  
 5. Click **Update** to save your 2Auth setting. 5. Click **Update** to save your 2Auth setting.
  
-Once you have saved the setting, you will see the email verification status as "Pending". This means your 2Auth Email has not been verified. This status will be automatically updated to "Verified" on your next successful login with 2Auth.+|{{:faq:security:2auth:enabling-2auth:5.jpg|}}| 
 + 
 +6. Once you have saved the setting, you will see the email verification status as "Pending". This means your 2Auth Email has not been verified. This status will be automatically updated to "Verified" on your next successful login with 2Auth. 
 + 
 +|{{:faq:security:2auth:enabling-2auth:6.jpg|}}|
  
 ==== Logging in with 2Auth ==== ==== Logging in with 2Auth ====
Line 38: Line 50:
 1. Once 2Auth is enabled, log in to your VO or webmail with your email address and password. 1. Once 2Auth is enabled, log in to your VO or webmail with your email address and password.
  
-2. An OTP will be sent to your 2Auth Email. Check for the email and obtain the code, then enter the code into the given field.+|{{:faq:security:2auth:logging-in-with-2auth:1.jpg|}}|
  
-<color #00a2e8>**Note:**</color> You will see the Skip button on your first 2Auth login with the new 2Auth Email. Clicking Skip allows you to access your account but your 2Auth Email remains unverified. +2. You will see the following screen, prompting you to input the OTP code, which has been sent to your 2Auth Email.
-The Skip button will be unavailable after your 2Auth Email has been verified on a successful login with 2Auth.+
  
-3. Click Login to proceed. If the OTP is entered correctly, access to your account will be granted.+|{{:faq:security:2auth:logging-in-with-2auth:2.jpg|}}|
  
 +3. Check the email received at your 2Auth Email to obtain the OTP. A sample of the OTP email is shown in the following image.
 +
 +//Note:// If you did not see the email in your Inbox, please check the spam or junk folder as well.
 +
 +|{{:faq:security:2auth:logging-in-with-2auth:3.jpg|}}|
 +
 +
 +4. Enter the OTP code that you received into the given field and click **Go**.
 +
 +|{{:faq:security:2auth:logging-in-with-2auth:4.jpg|}}|
 +
 +
 +If the OTP is entered correctly, access to your account will be granted.
  
 ---- ----
Line 56: Line 80:
  
 === 2. Can I use the same email address as the 2Auth Email of multiple user accounts? === === 2. Can I use the same email address as the 2Auth Email of multiple user accounts? ===
-Yes. A single email address can be set as the 2Auth Email for multiple user accounts. All OTP messages will be sent to this 2Auth Email.\\ +Yes. A single email address can be set as the 2Auth Email for multiple different user accounts.
-In order to distinguish which OTP is for which email address, you can match the unique character displayed in the login page against the one displayed in the OTP message.+
  
  
Line 65: Line 88:
   * **Wait a few minutes:** Occasionally, email delivery can experience delays. Give it a few minutes to see if the OTP arrives.   * **Wait a few minutes:** Occasionally, email delivery can experience delays. Give it a few minutes to see if the OTP arrives.
   * **Verify your 2Auth Email:**  If this is your first time signing in with 2Auth enabled, you can click the Skip button to access your account without entering the OTP. Then, double-check if the email address registered as your 2Auth Email is correct and accurate.    * **Verify your 2Auth Email:**  If this is your first time signing in with 2Auth enabled, you can click the Skip button to access your account without entering the OTP. Then, double-check if the email address registered as your 2Auth Email is correct and accurate. 
-  * **Ensure helpdesk@lookafter.com is whitelisted:** If you are using a third party or personal email address as your 2Auth Email, make sure its email service or spam filter does not block emails sending from lookafter.com. +  * **Ensure helpdesk@lookafter.com is whitelisted:** If you are using a third party or personal email address as your 2Auth Email, make sure its email service or spam filter does not block emails that are sending from lookafter.com. 
  
-If you've tried all the above steps and still haven't received the OTP, reach out to our support team at helpdesk@lookafter.com.+If you've tried all the above steps and still haven't received the OTP, please reach out to our support team at helpdesk@lookafter.com for further assistance.
  
  
-=== 4. How long does the OTP expired? ===+=== 4. I have voadmin/avomaster access, what is my role in 2Auth in terms of user management? === 
 +As a voadmin or avomaster, you have the administrative rights in the setup, update, reset, and deactivation of 2Auth for your users.\\  
 +Please refer to: [[faq:administrator:2auth_admin_guide|Administrator's Guide to 2Auth]] 
 + 
 + 
 +=== 5. How long does the OTP expired? ===
 The 2Auth OTP expires after 20 minutes from the moment it is generated. After this time period elapses, the OTP becomes invalid and cannot be used for authentication purposes. The 2Auth OTP expires after 20 minutes from the moment it is generated. After this time period elapses, the OTP becomes invalid and cannot be used for authentication purposes.
  
  
-=== 5. Can I change my 2Auth Email for OTP delivery? === +=== 6. Can I change my 2Auth Email for OTP delivery? === 
-Yes. To update your 2Auth Email, log in to your account and navigate to your Profile > 2Auth.+Yes. To update your 2Auth Email, log in to your account and navigate to Profile > 2Auth.
  
  
-=== 6. What if I receive an OTP email but didn't request it? === +=== 7. What if I receive an OTP email but didn't request it? === 
 If you receive an unexpected OTP email, it is possible that someone is attempting unauthorized access to your account. Please take immediate action to protect your account: If you receive an unexpected OTP email, it is possible that someone is attempting unauthorized access to your account. Please take immediate action to protect your account:
   * **Do not use the OTP:** First and foremost, do not use the OTP if you didn't request it. Using the OTP in this situation could potentially compromise your account's security.   * **Do not use the OTP:** First and foremost, do not use the OTP if you didn't request it. Using the OTP in this situation could potentially compromise your account's security.
Line 86: Line 114:
  
  
-=== 7. Is it safe to share my OTP with anyone? ===+=== 8. Is it safe to share my OTP with anyone? ===
 No, OTPs are confidential and should not be shared with anyone. They are meant for your use only and are a crucial part of your account security. No, OTPs are confidential and should not be shared with anyone. They are meant for your use only and are a crucial part of your account security.
  
  
-=== 8. Why is my "Email verify status" showing as "Pending"? ===+=== 9. Why is my "Email verify status" showing as "Pending"? ===
 If your email verification status is "Pending", it means your 2Auth Email has not been verified by the 2Auth system. This status will be automatically updated to “Verified” on your next successful login using the OTP received at your 2Auth Email. If your email verification status is "Pending", it means your 2Auth Email has not been verified by the 2Auth system. This status will be automatically updated to “Verified” on your next successful login using the OTP received at your 2Auth Email.
  
  
-=== 9. Can I use two or more email to receive OTP? === +=== 10. Can I use the original email address as the 2Auth Email? === 
-At the moment, 2Auth only allows one email address to be registered per account for OTP delivery.+Using your original email address as the 2Auth Email is possible over IMAP or POP3 access, but it is not a recommended practice from a security perspective. If your email address is compromised, it could potentially lead to unauthorized access to other data, settings or features associated to the account. 
 + 
 + 
 +=== 11. Can I use two or more email address to receive OTP? === 
 +Currently, 2Auth only allows one email address to be registered per account for OTP delivery
 + 
 + 
 +=== 12. Can I opt for SMS instead of email to receive OTP? === 
 +2Auth only provides OTP delivery through email at the moment. 
 + 
 + 
 +=== 13. Can I disable 2Auth for my account? === 
 +If you decide to not use 2Auth, you can disable the feature by unchecking the "Enable Second Factor Authentication" option at your Profile > 2Auth.
  
  
-=== 10Can I opt for SMS instead of email to receive OTP? === +=== 14What if the email address registered as my 2Auth Email no longer able to receive emails? === 
-2Auth only provides OTP delivery through email currently.+You can request your voadmin or avomaster to [[faq:administrator:2auth_admin_guide#editing_user_s_2auth_email|change your 2Auth Email]] to an email address that can receive the 2Auth OTP emails.
  
  
-=== 10. I'm having problems accessing my account after enabling 2Auth. What should I do? ===+=== 15. I'm having problems accessing my account after enabling 2Auth. What should I do? ===
 If you experienced any issues related to 2Auth, please send the description of issue along with screenshots to helpdesk@lookafter.com for further assistance.  If you experienced any issues related to 2Auth, please send the description of issue along with screenshots to helpdesk@lookafter.com for further assistance. 
  
faq/security/2auth.1695787231.txt.gz · Last modified: 2023/09/27 12:00 by vikki