Multi-Factor Authentication
Multi-factor authentication (MFA) allows securing of users' credentials within Stax that are not associated with a Single Sign-On (SSO) provider. Enabling MFA provides additional security by requiring that a second proof of identity be provided before a user is granted access to the Stax Console.
If your organization uses single sign-on to access Stax, you must configure MFA using your organization's SSO provider.
Configure MFA
- Log in to the Stax console
- Choose your name from the bottom of the left-hand nav, below the option for Support
- In the Personal Details section, under the Multi-Factor Authentication heading, choose Configure
- Choose Set up Authenticator Application
- Using Microsoft Authenticator, Google Authenticator, or another similar MFA application that supports TOTP, scan the QR code on the web page. Enter a name for the device, as well as the current One-time code, then choose Submit.
Next time you log in to the Stax console, or using stax2aws, you will be prompted to provide a one-time code from your TOTP application. Upon successfully entering the code, you will be logged in to Stax
Disable MFA
- Log in to the Stax console
- Choose your name from the bottom of the left-hand nav, below the option for Support
- In the Personal Details section, under the Multi-Factor Authentication heading, choose Configure
- Click Remove next to to the authentication device. The authenticator will be removed immediately and MFA will be disabled for the user
Reset MFA Token
If you've lost your MFA token, you'll require assistance from both an administrator of your Stax tenancy, and the Stax support team. Have someone who is a member of the Admin role in your Stax tenancy raise a support case requesting that your MFA token be reset.
Considerations
- MFA must be enabled on a per-user basis, by the user, and cannot be enforced organization-wide at this time
- MFA status is not currently exposed in the Stax API, and as such cannot be reliably determined at an organization-wide level. If you require this detail, please raise a support case requesting a report of MFA status
- Administrators cannot currently reset MFA tokens on behalf of users, this must be achieved by raising a support case for assistance