Skip to main content

Release Notes December 5, 2024: Optional HR Module MFA Login

Security enhancement to the HR login process

Evan Nelson avatar
Written by Evan Nelson
Updated over a year ago

What’s New

We have introduced Multi-Factor Authentication (MFA) to enhance the security of the HR module. Users can now enroll in MFA using their phone numbers, providing an additional layer of protection for their accounts. Administrators gain visibility into MFA adoption through a dedicated section in the Admin Panel.


Key Updates

  1. User Self-Enrollment for MFA

    • Users can enroll in MFA through their account settings in the HR module.

    • MFA activation requires phone number verification via an SMS-based One-Time Password (OTP).

    • NOTE: THIS OPTION WILL NOT APPEAR IF YOU LOG IN FROM THE ADMIN

    • Once enrolled, users can enable or disable MFA as needed.

  1. Admin Visibility into MFA Status

    • A new section in the Admin Panel displays all users and their MFA enrollment statuses ("Yes" or "No"). A blank entry means that the user has not yet setup MFA enrollment

    • Administrators can monitor MFA adoption.

  2. Enhanced Security Measures

    • Phone numbers and MFA-related data are encrypted at rest and in transit.

    • Integration with a reliable SMS gateway ensures secure OTP delivery.

    • Comprehensive error handling addresses issues like invalid phone numbers or SMS gateway failures.


Impact

  • For Users:
    MFA adds a robust layer of security, reducing the risk of unauthorized account access.
    Simple enrollment and activation processes ensure ease of use.

  • For Administrators:
    The new Admin Panel view provides transparency into MFA adoption across users.
    Administrators can monitor account security effectively.

  • Overall:
    This update aligns with best practices in account security, bolstering user trust and compliance with security standards.

Did this answer your question?