Registering to One Identity Starling 2FA
In order to use Starling 2FA, you must first register to the product. When you register to Starling 2FA using your mobile number, an SMS is delivered with the mobile app download link. Click on the link to access the App Store or Play Store from where you can download the Starling mobile application. Alternatively, you can go to the App Store or Play Store and search and download the Starling.
The following 2FA options are supported:
- Push Notification: After the Starling app is downloaded and registered with user’s email id and mobile number, the user will get a push notification to Approve or Deny Starling Authentication.
- Voice: The user will get a voice call on the registered mobile number and on call user will get an OTP.
- SMS OTP: The user will get an OTP through SMS on the registered mobile number.
- The user can open the Starling app and copy and paste the code form the Starling app to Active Roles, and then click on Verify.
Logging in to Web interface through 2FA authentication
When a Starling 2FA enabled user tries to log in to the Active Roles Web interface, the user is prompted to enter the Starling Two-factor token response. Based on the option selected by the user, the token response is provided through SMS, Phone Call or Push Notifications.
On entering the token response and after successful verification the Web interface is displayed.
|
NOTE: Push Notification works only if the Starling App is installed on the device with registered mobile number. The link to install the Starling App will be send to your registered mobile number at the time of registering to Starling. |
Logging in to MMC interface through 2FA authentication
When a Starling 2FA enabled user tries to log in to the Active Roles MMC interface, the user is prompted to enter the Starling Two-factor token response. Based on the option selected by the user, the token response is provided through SMS, Phone Call or Push Notifications. After the token is generated the token request options are disabled.
In case the token must be generated again, you need to wait for the minimum notification retry interval for the request options to get enabled. The default value for the notification retry interval period is 30 seconds.
On entering the token response and after successful verification the MMC interface is displayed.
|
NOTE: Push Notification works only if the Starling App is installed on the device with registered mobile number. The link to install the Starling App will be send to your registered mobile number at the time of registering to Starling. |
If the system is kept idle for more than 30 minutes, the 2FA session expires and the MMC console gets disconnected with a session timeout warning.
Disallowing two-factor authentication for Active Roles users
To disable Active Roles users for two-factor authentication, remove the users from the ARS 2FA Users group. Removing the users from the ARS 2FA Users group disables the minimal permissions on the users applied through the Starling - Two Factor Authentication User Access template that authorize the users for two-factor authentication.