Manage authenticators

Introduction

Your users can use IdentifyMe to register or reset multi-factor authentication methods, and enable Biometric login as the first factor. To use these features, you need to go to Safewhere Admin > Settings > System to enable them.

manage-authenticators

After that, you need to specify what OTP connections can show up on IdentifyMe for your users to use. You need to enable the settings in the red rectangle boxes on the Edit OTP connection page:

otp-allow-register-from-profile-page

T-OTP authenticators

You can find the T-OTP authenticators card on the homepage:

totp-authenticator-homepage

The T-OTP authenticators page is where your users can manage their T-OTP authenticators such as Microsoft authentication, Google authenticator, Authy.

totp-authenticator-page

Register TOTP authenticator

You can register a T-OTP authenticator by clicking on the Register button:

totp-click-register-button

The following example assumes that you have had an Authenticator app installed:

  1. Click on the I have already set it up button:

totp-authenticator-already-set-up

  1. Scan and enter the code to continue:

totp-authenticator-register

  1. Safely save the recovery code:

totp-authenticator-continue

  1. After you have registered an T-OTP authenticator successfully:

totp-reset-button

Reset T-OTP authenticator

You can reset your authenticators by clicking on the Reset button.

totp-click-reset-button

The T-OTP authenticator is then reset and you can re-register it.

totp-register-button-after-reset

WebAuthn authenticators

You can find the WebAuthn authenticators card on the homepage:

webauthn-authenticator-homepage

The WebAuthn authenticators page is where your users can manage their WebAuthn authenticators such as Windows Hello, biometrics, FIDO2 keys.

webauthn-authenticator-page

Register WebAuthn authenticator

You can register a WebAuthn authenticator by clicking on the Register button:

webauthn-click-register-button

The following example assumes that you have WebAuthn software ready:

  1. Click on the I have already set it up button:

webauthn-authenticator-already-set-up

  1. Click on the Register button then complete the registration on your device:

webauthn-authenticator-register

  1. Safely save the recovery code:

webauthn-authenticator-continue

  1. After you have registered an T-OTP authenticator successfully:

webauthn-reset-button

Reset WebAuthn authenticator

You can reset your authenticators by clicking on the Reset button.

webauthn-click-reset-button

The WebAuthn authenticator is reset and you can re-register it:

webauthn-register-button-after-reset