CloudCodes For Business gives high security against any kind of suspicious attempts to account for any access with its multifactor authentication method. 

 


For Apply the Policy Click on the "Add" button. You will get the below MFA policy page.





  1. Title: Name your policy to identify it later when you want to make changes quickly.

  2. Description: Short description for helping understand the policy if more than one admin is managing the account

  3. Enabled: For some reason, if you want the policy to be disabled for some time and re-enable it, you can check/uncheck “Enabled” option as shown above.

  4. Valid Always: You can decide the validity of the policy with Valid Always button. Toggling this you can say whether you want a policy for a stipulated time or a policy which is always applied

  5. Valid From and Valid To: If Valid Always is off, then you will have to provide the date range for which the policy needs to be applied. This way admin need not manually turn off the policy

  6. Validation: After this, the admin has to select the validation method;

    There are three options.
    1)OTP
    2)Google Authenticator.
    3)Duo Push


  1. Save Device: This policy allows users to log in with the saved devices without the multi-factor authentication from next time. 

  2. Expiration Days: The number of days after which the user will be asked multi-factor authentication after saving his/her device.


     9. Enforce: Enforce Policy includes: 

  1. Always

  2. Corporate Network

  3. Remember User IP -
    • A. Block Access :

    • B. Notify the admin and allow access.

    • C. Re-Register IP


9.1. On selecting Always, the users will be asked for multifactor authentication on each login.
9.2. Alternatively, if admin opts for Corporate Network; all the users logging from the company’s network IPs will not be enforced for multi-factor authentication.
9.3. In Remember User IP option includes three more options, the users accessing the account with not registered IP address then 

  • “Block access” option will block logging in from unregistered IP

  • The "Notify" option will notify the admin when the user logins from unregistered IP through email notification. 

  • “Re-register IP” option the unregistered IP also gets registered and is not prompted for multifactor authentication.


10. Re-register : Allow the end user to re-register his/her account on Google Authenticator.