Learning Center/OneLogin Documentation/User Documentation

One-Time Passwords

Thomas Pedersen
posted this on March 18, 2010 01:34 pm

Using multiple authentication factors is an effective way of preventing someone from accessing your sensitive data even if they manage to get hold of your username or password. For a brief introduction to the topic, read the article Authentication Factors.

OneLogin supports both VeriSign VIP Access and Yubico's YubiKey for one-time password generation. These solutions fall the "something you have" category, which means that if you successfully authenticate, the authenticating party knows that the user has the key in their possession. This significantly reduces the chances of someone else hacking into that user's account.

Enabling OTP

In order to use OTP with OneLogin, one of your account's admins has to turn it on. This is done under Security -> OTP.

otp_config.png

OneLogin lets you use VIP Access and YubiKey at the same time, which is an advantage if you have different users with different needs. For example, someone who works from an office all day maybe prefer YubiKey because of its easy-of-use while someone who travels may prefer VIP Access because always it's in their phone.

OTP can be required for all administrators only, all users or select users. 

Registering OTP Devices

In order for an OTP device to be used, it must be associated with a user. This can be done manually by the administrator user by user, but that's not practical on a large scale, especially with VIP Access where only the employee has access to the device. If OTP is required for a user, the user will be prompted to register the device at the first successful login.

Configuring users

Once OTP is enabled for, you will be able to register the device on the individual users as shown below. Go to People -> Users and select a user. This is also where you deregister OTP devices.

otp_edit_user.png

To register a YubiKey, insert the key in the USB port and press the button. This will insert a 30 long string in the field of which the first 12 will be stored on the user. These 12 character uniquely identify the key and are now tied to this user.

To register VIP Access, enter the Credential ID shown in the mobile application.

Make sure you that you register your own key before you log out, or you will not be able to log in again.

When is OTP Required?

Use the required setting to enforce whether users have to use OTP at every login or just when they log in from an unknown or expired browser.

Logging in

Once OTP has been turned all, all users will see a login page as shown below. Once Email and Password have been entered, a YubiKey or VIP Access field will appear.

otp-login.png

YubiKey users simply press the button while the key is inserted in the USB port and the one-time password will automatically be inserted in the OTP field. VIP Access users will have to launch their VIP Access Mobile application and manually enter the generated one-time password within 30 seconds.

 

Comments

User photo
Tyler Hall

Just got my Yubikey and i'm loving it, but what happens if I lose my Yubikey?  Is there any sort of backup mechanism, or something of the sorts?

June 05, 2010 04:06 pm.
User photo
Thomas Pedersen
OneLogin Support

Regular users should contact their OneLogin administrator who can then disable OTP for their account or issue a new token. If the OneLogin administrator loses their key, they should contact OneLogin. We're planning on adding phone-based authentication as a backup as well. 

June 05, 2010 05:24 pm.
User photo
Dilip Mohapatra

I beleive you mean SMS based authentication here. Do you know when can we expect that feature to be implemented.

Also is it feasible to add custom providers here e.g. smspasscode

January 27, 2011 09:39 pm.
User photo
Dylan Hodge

Any updates here?  I just activated VIP access using iPhone app and love it but need to know my backup plan should my iPhone fail or get lost or whatever.  

April 06, 2011 09:36 pm.