Multi-factor Authentication (MFA) without using Authenticator Applications

mageshbtech_kum
Kilo Contributor

In Multi-factor Authentication (MFA), User should Download and install any one of the Authenticator Application for first time.

From next login onwards they can use the Authenticator Application or request a verification to be sent via email by clicking "click here to receive a onetime code via email” Option.

Do we have any option to request the code via email without installing the APP for the First time.

1 ACCEPTED SOLUTION

MFA 

https://docs.servicenow.com/bundle/paris-platform-administration/page/integrate/authentication/reference/mfa-authenticator-supported.html

You need to configure a supported solution in ServiceNow. ServiceNow relies on "your" MFA. So, if your MFA supports email then you are all set.

 

 

View solution in original post

14 REPLIES 14

What do you mean by "your" MFA? Are you referring to Google, Microsoft etc provider? if so how can we configure it such that only specific provider is being used.

Bmcrimmon
Tera Contributor

We need the capability to check a box when configuring MFA in ServiceNow to require Authenticator App or Email?   If email is selected as the option over AuthenticatorAPp and the user MFA enabled

User logins in with UserName/Password.  

User receives email with passcode.   (passcode is delivered to the user's email that is logging in) 

User lands on enter passcode page.   User enters passcode and if accurate user has access to ServiceNow.  

Obviously,  simpler said than done.  

Randheer Singh
ServiceNow Employee
ServiceNow Employee

Hi @mageshbtech_kum 
This feature is coming as part of the Utah release. Admins can configure adaptive Authentication Policies to enable SMS/Email OTP-based MFA without requiring an authenticator app setup.

 

cc: @Chris McDevitt 

Thanks,

Randheer

Hi @Randheer Singh 

I have configured an adaptive authentication policy to enable email based MFA.  It works good. Now, I want to use the [Remember Browser] feature to no longer require MFA authentication when logging in for the next 8 hours when using email to accept verification codes. What settings should I make to implement it?

 

Hi Randheer, 

 

This is great, is there any documentation which outline how to make this specific configuration? If not, could  you provide some high-level steps to accomplish this? I have a client who would like to avoid using the Authenticator App altogether. 

 

Thanks,

Dylan