PhoneFactor Authentication13 minutes to read
ManageEngine and PhoneFactor has partnered to provide you with seamless integration with PhoneFactor's authentication services. PhoneFactor is a leading global provider of phone-based Two-Factor Authentication. This enables access to the user with simple and effective Two-Factor security for Access Manager Plus. During the login process, PhoneFactor places a confirmation call to the registered number. You would have to answer the call and enter the PIN you have set or press #. The call is placed only after completing the initial authentication. To know more about the other authentication methods, click here. Summary of Steps
1. How does PhoneFactor Work with Access Manager Plus?You will be specifying the phone numbers for your users, which results in a mapping between the users and the corresponding phone numbers. In PhoneFactor agent mode, the details about the user, including the phone numbers are maintained at the agent. In Direct SDK mode, the phone numbers are maintained in Access Manager Plus database itself. When a user tries to login to Access Manager Plus, PhoneFactor finds out the phone number of the respective user and triggers a call. 2. Sequence of Events
3. Enabling PhoneFactor Authentication3.1 PrerequisitePrior to enabling PhoneFactor authentication, you need to buy PhoneFactor. After getting PhoneFactor, you need to decide about the specific authentication method - whether you want to install PhoneFactor agent in your environment or deploy PhoneFactor Direct SDK. 3.2 Setting up Two-Factor Authentication in Access Manager Plus
Note: Before proceeding further, ensure that you have entered the phone numbers for all the users for whom you wish to enable Two-Factor Authentication through PhoneFactor in Access Manager Plus. You can enter a landline number or a mobile number as the primary contact number for PhoneFactor authentication. 3.3 Deciding the type of PhoneFactor AuthenticationYou can choose to deploy PhoneFactor Agent or PhoneFactor Direct SDK.
3.3.1 Configurations in PhoneFactor AuthenticationThe PhoneFactor agent runs on a Windows server within your network. It includes a configuration wizard that guides you through the setup process for securing Access Manager Plus with PhoneFactor. The PhoneFactor agent can also integrate with your existing Active Directory or LDAP server for centralized user provisioning and management. All user data is stored within the corporate network for additional security. Extensive logging is available for reporting and auditing. Obtain and install the PhoneFactor Agent and Web Services SDK on a Windows server within your network. The wizard will guide you through the installation process. 1. Configurations in PhoneFactor
2. Configurations in Access Manager Plus
While installing the PhoneFactor agent/ Web Services SDK, you would have either created a self-signed SSL certificate or you would have used an already available internal certificate (your own certificate). Here, in Access Manager Plus, you need import the root of the CA. If you are using a certificate signed by third-party CA, you may skip this step. To import the root of the CA:
(In Windows) In the case of Self-signed certificates importPhoneFactorCert.bat <absolute path of the Self-signed certificate> In the case of your own certificates or already available internal CAs importPhoneFactorCert.bat <absolute path of the root of the CA> (In Linux) In the case of Self-signed certificates sh importPhoneFactorCert.sh <absolute path of the Self-signed certificate> In the case of your own certificates or already available internal CAs sh importPhoneFactorCert.sh <absolute path of the root of the CA>
3.3.2 Configurations in PhoneFactor Direct SDKInstead of using the Agent, you can also use PhoneFactor Direct SDK, which can be used to integrate with Access Manager Plus and it leverages Access Manager Plus's existing user database. 1. Configurations in SDK PhoneFactor jars have been bundled with Access Manager Plus. So, it is enough if you buy PhoneFactor and supply the license details as explained in Step 2 below. 2. Configurations in Access Manager Plus GUI
3.4 Enforcing Two-Factor Authentication for the Required Users
4. Connecting to Access Manager Plus Web Interface when TFA through PhoneFactor is Enabled
5. Workflow (TFA using PhoneFactor)If the administrator has chosen TFA through PhoneFactor, the Two-Factor Authentication will happen as detailed below:
See also:
©2025, Zoho Corporation Pvt. Ltd. All Rights Reserved. |