2 Factor Authentication
Product line
Standard
|Expert
Operating mode
CLOUD ABO
|ON-PREMISES
Modules
Services & CRM
Budget & Phases
Purchases
Resource Planning
Business Intelligence
As of version 6.3.0.12, Vertec supports a 2nd factor for logging into Cloud Clients (Cloud app, Web app, Phone app) via Authenticator app, e.g. Google Authenticator.
The Authenticator app must be a “soft token” app that generates a one-time password. This principle does not require communication between the Authenticator app and Vertec, only a common secret has to be exchanged once. Because of this secret, the Authenticator app and Vertec can both generate and compare the same codes independently.
The prerequisite is that the time on the mobile device and on the Vertec server match.
Under System settings > Authentication, there is a setting Use 2 Factors for Cloud Clients (Vertec and LDAP). If this setting is enabled, the following happens:
Two-Factor Authentication also works in the Phone app, but the setup of authentication as described here must be done in the Cloud app or the Web app. Only there will the Setup dialog appear. Each user must first log in to a Cloud app or Web app and set up Two-Factor Authentication before using the Phone app with Two-Factor Authentication.
The setup dialog looks like this:
Start your Authenticator app and scan the displayed code or enter the code provided. Once you see a code designation “Vertec” in your app, you can click OK
. From this point on, the two systems will be paired. From then on, when logging in to Vertec, enter the code generated by the Authenticator app as a second factor.
In case of emergency, such as loss of mobile phone or data, the administrator can reset the secret of an user. To do this, the administrator can log in and open the dialog on the corresponding user via the context menu or menu Actions > 2. Edit Factor for Authentication and click on the button Delete Token
.
The next time they log in to a Vertec Cloud App or Web app, the user can then generate and exchange the new code.
If the administrator has self-excluded and a reset is not possible, please contact Vertec support.
A normal user can show the 2FA secret with the code at any time, but cannot regenerate it.