Enabling MFA

SGS1
Tera Contributor

Hello team,

 

 My customer is planning to enable MFA - EMail(mandatory)  and AUthenticator (optional) for users.

 

My question is 

1. If users enable authenticator , can they still receive the one time code via email even if Authenticator is default one . Can they choose between two ?

2. Can users reset Autheticator validation as a self service ? or it has to be always system administrator?

 

Thanks.

 

 

2 REPLIES 2

Pratiksha
Mega Sage
Mega Sage
  1. Options for Receiving One-Time Codes: Typically, if users have enabled authenticator as an optional factor, they should still be able to receive one-time codes via email, especially if email is set as a mandatory factor. Users may have the option to choose between receiving the one-time code via email or using their authenticator app. However, this specific configuration might depend on how MFA is implemented and configured in your ServiceNow instance. It's advisable to check the specific settings and configurations within your ServiceNow environment to confirm this behavior.

  2. Self-Service Reset for Authenticator Validation: Whether users can reset authenticator validation as a self-service action or if it requires system administrator intervention depends on the configuration and policies set up in your ServiceNow instance. ServiceNow typically provides flexibility in configuring self-service options for users, including resetting MFA factors like authenticator validation. This can usually be configured based on your organization's security policies and requirements. You can check the ServiceNow documentation or consult with your ServiceNow administrator to understand how self-service reset for authenticator validation can be configured in your environment.

For both questions, it's essential to review your organization's specific configurations and policies within ServiceNow, as these capabilities can be tailored to meet your organization's security and usability needs.

 

Mark it Helpful and Accept Solution !! If this helps you to understand.

 

Randheer Singh
ServiceNow Employee
ServiceNow Employee

Hi @SGS1 ,
The answer to both of your questions is Yes.

  1. Users get both options after configuring the authenticator app. They can choose the option on the MFA validation screen.
  2. Yes, users can log in with email OTP-based MFA and navigate to their user profile section to reset the authenticator app.


    RandheerSingh_0-1714988559052.png

     

 

 

RandheerSingh_1-1714988682813.png

 

 

RandheerSingh_2-1714988751060.png

 

 

Thanks,

Randheer