Multi-factor authentication for Customer and Consumer Service Portals

  • Release version: Australia
  • Updated March 12, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Multi-factor Authentication for Customer and Consumer Service Portals

    Multi-factor authentication (MFA) enhances security for users accessing Customer and Consumer Service Portals by requiring multiple credentials. This feature protects against potential vulnerabilities and ensures secure self-service access.

    Show full answer Show less

    Key Features

    • Enable Multi-factor Authentication: Activate MFA for users and administrators. Default is enabled.
    • Bypass Count: Set the number of times a user can skip MFA setup. Default allows 3 bypasses.
    • One-time Code Validity: Configure how long a one-time code sent via email remains valid. Default is 10 minutes.
    • Clock Skew Adjustment: Allow for time discrepancies by adjusting the validity window of one-time codes up to 60 seconds.
    • Role Configuration: Assign external roles (sncustomerservice.customer, sncustomerservice.consumer) to enforce MFA requirements for specific users.

    Key Outcomes

    Implementing MFA helps ensure that only authorized users can access sensitive portal information, significantly reducing security risks and enhancing overall user confidence in the system's protections.

    Multi-factor authentication, also known as two-step verification, is a security requirement that asserts a user enter more than one set of credentials.

    Enable multi-factor authentication for Customer and Consumer Service Portal users so that access to the self-service web portals is more secure from potential vulnerabilities. For more information, see Multifactor authentication (MFA).

    Multi-factor authentication properties

    Use properties to enable role-based multi-factor authentication criteria and configure the behavior.
    Table 1. Properties for multi-factor authentication
    Property Description
    Enable Multi-factor authentication

    [glide.authenticate.multifactor]

    Select this check box to enable users and administrators to use this feature.
    • Type: enabled | disabled
    • Default value: enabled
    • Location: Multi-factor Authentication > Properties
    Number of times a user can bypass setting up multi-factor authentication

    [glide.authenticate.multifactor.setup.bypass.count]

    Enter a number that represents how many times a user can skip the additional passcode requirement, allowing them to log in even without their mobile device. If you disable this feature and then re-enable it, the counter starts over again.
    • Type: string
    • Default value: 3
    • Location: Multi-factor Authentication > Properties
    The time in minutes, the one-time code sent to user's email address is valid for

    [glide.multifactor.onetime.code.validity]

    Enter a number in minutes that specifies how long the reset code is valid. See Log on with multi-factor authentication.
    • Type: string
    • Default value: 10
    • Location: Multi-factor Authentication > Properties
    Additional time in seconds for which the code will be valid to accommodate for the clock skew. Max value is 60 seconds.

    [glide.authenticate.multifactor.clock_skew]

    Enter a number in seconds with a maximum of 60.

    By default, the instance validates the code entered by you against the single app-generated code generated at whatever the current time is. You can skew the time window with this property and allow one or more codes generated during a time window to be considered valid.

    The property's value is used in the following calculation: current time - x/2 and current time + x/2, where 'x' is the value of this property. If you use the value of 10, for example, the instance considers any codes generated by the app between the time range [the current time - 5 seconds] and [current time + 5 seconds] to be valid.

    Use this property to help prevent log in issues where you’re unable to enter the correct code in the default time allotted.

    Configure roles for multi-factor authentication

    Add the following external roles to the multi-factor roles:
    • sn_customerservice.customer
    • sn_customerservice.consumer
    Users with these roles are required to use multi-factor authentication. For more information, see Configure user-based multi-factor criteria.