MFA by Email, SMS

Email and/or SMS Multi-Factor Authentication (MFA) adds an extra layer of security on top of the basic authentication methods. When users access the FintechOS Portal or FintechOS Studio, they will be prompted to provide the login credentials associated with their FintechOS Platform account. To make sure account access is protected, after the login credentials are provided, users are redirected to a secondary login page where they have to enter a one-time security pass code received via email, SMS (the phone number set in the user account profile). Once a user enters the code received via the Email/SMS/IVR(Call Me) option, access to the system is granted.

Follow the instructions below to set up Email/SMS/IVR(Call Me) multi-factor authentication.

1 Create an Authentication Flow

IMPORTANT!  
Make sure that the FintechOS Identity Provider has the MFA plugin installed and uses a theme that includes the MFA login screen.
  1. Log in to the FintechOS Identity Provider admin console.
  2. Select your FintechOS Platform realm.
  3. If you want to set an authentication flow for either Studio or Portal, not both, then go to Clients and search for your Portal or Studio.
  4. In the client settings, go to the Advanced tab and in the Authentication flow overrides section, at Browser Flow select the flow you wish to configure.
  5. In the left menu, select the Authentication option.
  6. In the Flows tab, open a built-in authentication flow and alter its requirements. Built-in flows cannot be modified, but you can alter its settings such as OTP forms, conditions, and so on. You might have multiple flows depending on authentication scenarios, such as an authentication flow for existing users, a registration flow, a reset credentials flow and so on. Read more about authentication flows in the official Keycloack documentation.

2 Configure the Flow's MFA Execution Step

Authentication flows can be configured to use DCI, Data Core or Twilio and Vonage. The settings for DCI - Data Cor, differ from those of Twilio and Vonage. For instance, the latter supports sending the OTP verification code through WhatsApp as well, provided that the account is a company one. For Twilio and Vonage, DCI supports a predefined list of locales (e.g., en, de, it, es, pt, fr).

3 Activate the Authentication Flow

Once the authentication flow is configured, in the FintechOS Identity Provider, navigate to Authentication > Bindings and replace the Browser flow with the newly created flow. This will the set authentication flow globally. However, if you want to enable the flow only for one client, you can navigate to the client page, go to Settings > Authetication Flow Overrides, and change the Browser Flow there.

A user who logs in to FintechOS Portal or FintechOS Studio, will be directed to the one-time password form and will receive the required password via Email, SMS or IVR (Call Me).