Logon Settings

General logon settings

Under the General tab of Logon Settings, you can configure the following settings.

CAPTCHA Settings

Login CAPTCHA serves as a security measure against bot-based brute force attacks. Enabling this setting will display a CAPTCHA image on the login page. End-users must enter the characters shown in the CAPTCHA image to log into the Log360 MSSP web portal.

You can configure whether to show CAPTCHA always or only after a certain number of invalid login attempts. Apart from the CAPTCHA image, you can also enable Audio CAPTCHA to assist visually-impaired users.

Steps to enable CAPTCHA:

  1. Log into Log360 MSSP as an administrator.
  2. Navigate to Settings → Administration → Logon Settings, and click the General tab.
  3. Select the option Enable CAPTCHA on the login page.
  4. Select Always show CAPTCHA if you want users to go through CAPTCHA verification every time they login.
  5. Select Show CAPTCHA after invalid login attempts if you want only those users who failed at login to go through the CATPCHA verification process.
    • Enter the number of invalid login attempts after which the CAPTCHA verification should appear.
    • Enter the threshold (in minutes) to reset the invalid login attempts. After the specified time period, the invalid login attempts will be reset.
    • Illustration: Consider the following limits:
      • Invalid login attempts limit 3
      • Reset the invalid attempts limit after 30 minutes
    • In the above illustration, if a user fails to login 3 times consecutively in a 30-minute time interval, then a CATPCHA image will be displayed. The user now has to enter the correct credentials, plus the characters shown in the CAPTCHA image, to successfully log into Log360 MSSP.
  6. Select Enable Audio CAPTCHA to assist visually impaired users.

    Note: When audio CAPTCHA is enabled, only digits will be shown in the CAPTCHA image. If a browser doesn’t support audio CAPTCHA, then the default CAPTCHA image (with letters and digits) will be shown.

  7. Click Save Settings.

Block Users Settings

Using this option you can block users from accessing Log360 MSSP after a certain number of invalid login attempts for a defined time interval. A blocked user cannot log into Log360 MSSP.

Steps to block users:

  1. Log into Log360 MSSP as an administrator.
  2. Navigate to Settings → Administration → Logon Settings, and click the General tab.
  3. Select the option Block users after invalid login attempts.
    • Enter the number of invalid login attempts after which users should be blocked.
    • Enter the threshold (in minutes) to reset the invalid login attempts. After the specified time period, the invalid login attempts will be reset.
    • Enter the number of minutes users should be blocked.
    • Illustration: Consider the following limits:
      • Invalid login attempts limit ‘3’ within ‘5’ minutes.
      • Reset the invalid attempts limit after ’30’ minutes
    • In the above illustration, if a user fails login 3 times in a 5-minute time interval, then the user will be blocked from logging into Log360 MSSP for 30 minutes.
  4. Click Save Settings.

Other Settings

If you want to hide the ‘Forgot Password?’ link in the login page, then enable the Hide ‘Forgot Password?’ link in login page option.

Two-factor Authentication

To strengthen user logon security, Log360 MSSP supports two-factor authentication. Once enabled, Log360 MSSP will require users to authenticate using one of the authentication mechanisms below in addition to the Active Directory credentials whenever they log in.

Setting up 2-factor authentication

Email Verification

When this option is selected, Log360 MSSP sends a verification code via email to the user’s email address. The user has to enter the verification code to login successfully.

Configuration steps:

SMS Verification

When this option is selected, Log360 MSSP sends a verification code via SMS to the user’s mobile number. The user has to enter the verification code to login successfully.

Configuration steps:

Google Authenticator

Google Authenticator adds an extra layer of protection to the reset password/unlock account process. Once enabled, users will be required to enter a six-digit security code generated by the Google Authenticator app for identity verification.

Configuration Steps:

Once enabled, users can enroll themselves for two-factor authentication using the Google Authenticator app.

RSA SecurID

RSA SecurID is a mechanism developed for performing two-factor authentication for a user to a network resource. Users can use the security codes generated by the RSA SecurID mobile app, hardware tokens, or tokens received via mail or SMS to log in to Log360 MSSP.

Configuration steps:

Logon Settings

Duo Security

Duo Security is a two-step verification service that provides additional security while accessing applications. Users can use the six digit security codes generated by the Duo mobile app or push notification to log in to Log360 MSSP.

Configuration Steps:

Logon Settings

Note: Please make sure you select the exact username pattern you use in Duo Security.

Microsoft Authenticator

Administrators can add Microsoft authenticator as an additional factor for verifying identities during login.

Configuration Steps:

Once enabled, users can enroll themselves for two-factor authentication using the Microsoft Authenticator app when they log in to the application.

Custom TOTP Authenticator

In addition to the authenticators mentioned above, you can also add a custom TOTP authenticator as a means of verifying identities, provided the application satisfies the following criteria:

Configuration steps:

  1. Select Enable Custom TOTP Authenticator.
  2. Enter the name of the authenticator application.
  3. Select the Passcode Length and the Passcode Expiration Time from the available options.
  4. Select the Password Hashing Algorithm of the TOTP authenticator.
  5. Provide the format in which the username will be displayed in the authenticator.
  6. Select the logo of the authenticator. The supported formats for the image are PNG, JPG, JPEG, BMP, and GIF. Please ensure the dimensions of the logo does not exceed 45x45 pixels and the size is less than 2MB.
  7. Click Save.

Logon Settings

Note: If the values for the passcode hashing algorithm, passcode expiration time, or the passcode length fields are modified, the user enrollment data for the configured custom TOTP authenticator will be deleted. The enrollment data will also be deleted when this configuration is disabled.

Once enabled, users can enroll themselves for two-factor authentication using the Custom TOTP Authenticator when they next log in to Log360 MSSP.

Backup Verification Codes

Backup verification codes allow users to log in when they don’t have access to their phone or face issues with one of the second-factor authentication method. When enabled, a total of five codes will be generated. A code once used will become obsolete and cannot be used again. Users also have the option to generate new codes.

Enabling backup verification code

Registering for backup verification code

Using the backup verification code to login

Managing users for two-factor authentication

As an admin, you can view which authentication method users have enrolled for and remove users’ enrollment for two-factor authentication using the Manage Users option.

To do so, follow the steps below:

Note: This process will reset both the default admin password and the two-factor authentication (2FA) settings.

Copyright © 2023, ZOHO Corp. All Rights Reserved.