Multi-Factor Authentication (MFA) or One-Time Passwords (OTP)

Why is the NCEdCloud MFA called a "One Time" Password if I have to use it every time?

The "One-Time" in One-Time Password (OTP) refers to the number of times you can USE a specific 6-digit passcode to login (one time), not something you only enter once.  A new valid password is generated for your account every 30 seconds so that someone can't look over your shoulder and see your 6-digit code, or a "hacker" can't capture what you enter and try to reuse it at a later time.  It's purpose is to add a "second factor" in addition to your account password, to make your login more secure.  It is usually only implemented for user accounts that have access to highe

How do I set up more than one device to use my OTP?

The One-Time Password (OTP) is tied to your NCEdCloud ACCOUNT, not to a device.  Therefore, when you login the first time after MFA is implemented (or after an OTP Reset) and see the OTP Setup Page, the QR Code and the AlphaNumeric Code below it are what links the NCEdCloud MFA to the 6-digit code presented by your authentication application (Google Authenticator, RapidIdentity, Authy Desktop).  The QR code and the AlphaNumeric Code are "identical", as far as providing the same information to authentication apps - as long as they're taken from the s

How often will I need to enter my OTP?

The short answer is once per day.  Your OTP (6-digit code) is part of the login process to NCEdCloud, so if you typically login to NCEdCloud more than once during the day (you use different clients or close your browser during the day) you will need to enter your OTP on the 3rd screen of the login.  If you use the same client throughout the day, then you’ll only login (and enter your OTP) once.

Do I need to provide my mobile phone number to set up MFA?

It depends on the app.  Both the Google Authenticator and RapidIdentity app that run on your mobile device use a time-based one-time password (TOTP) algorithm to provide a valid 6-digit code (it is not texted to your phone).  However, Authy requires that you enter your cell number when installing and registering the app.

Pages