Enable OTP in Unified Workspace

Enable OTP in Unified Workspace

Question:

Does Unified Workspace support One-Time-Password?


Solution:

As of 6.4.1.24, Unified Workspace includes support for One-Time-Password.
  1. Enable OTP:
    1. Go to the DefaultLoginPolicy (in the stoneware OU, under webAdmin's Tree Root).
    2. Select  the Options tab.
    3. Check OTP Challenge Enable.
  2. Assign the OTP Challenge link to users:
    1. Go to Link-Menu Admin.
    2. Expand Account Mgmt, then expand Authentication.
    3. Select the OTP Challenge link and assign that to OU, user group, or individual user you want to use OTP.
  3. Activate OTP for users:
    1. Go to an OU, user group, or individual user.
    2. Select the Authentication tab.
    3.  Check OTP Challenge Enable.
  4. Download and install an OTP authenticator app, such as Google Authenticator, on your iPhone or Android.
  5. Login as a user who has OTP Challenge enabled. The first time you login you will be taken to a page where it will instruct you how to configure your OTP authenticator app. It will present a QR code that you can scan. You will take a 6-digit code from the app and enter it to complete the configuration. If you enter the code correctly, then it will log you in. If you enter it incorrectly, then you will be taken to login page and you will have to repeat this process.
  6. Once the OTP is configured properly, then every subsequent login with this user will require you to enter in a 6-digit code that you get from the OTP authenticator app. This will be done on a subsequent page, after entering in your username and password. If you enter the code correct, then it will complete the login. If you enter it incorrect, then it will take you back to the login page.
  7. If at any time you need to reset your OTP authenticator code (because you've lost your device, etc), then go through the Reset Password process. If it detects that you have an OTP secret key on your user, then it will ask if you want to reset it. If you choose yes, then you will need to delete the previous configuration from your OTP authenticator (or create a new one) and on your next login to UW it will ask you to go through the OTP authenticator app configuration again.

    A UW admin can also reset OTP, through webAdmin.  The admin will find an OTP Reset button at the bottom of the user's Authentication tab.