Logging in to MMC interface through 2FA authentication
When a Starling 2FA enabled user tries to log in to the Active Roles MMC interface, the user is prompted to enter the Starling Two-factor token response. Based on the option selected by the user, the token response is provided through SMS, Phone Call or Push Notifications. After the token is generated the token request options are disabled.
In case the token must be generated again, you need to wait for the minimum notification retry interval for the request options to get enabled. The default value for the notification retry interval period is 30 seconds.
On entering the token response and after successful verification the MMC interface is displayed.
|
NOTE: Push Notification works only if the Starling App is installed on the device with registered mobile number. The link to install the Starling App will be send to your registered mobile number at the time of registering to Starling. |
If the system is kept idle for more than 30 minutes, the 2FA session expires and the MMC console gets disconnected with a session timeout warning.
Disallowing two-factor authentication for Active Roles users
To disable Active Roles users for two-factor authentication, remove the users from the ARS 2FA Users group. Removing the users from the ARS 2FA Users group disables the minimal permissions on the users applied through the Starling - Two Factor Authentication User Access template that authorize the users for two-factor authentication.
Disabling or Enabling Starling 2FA Users from Configuration Centre
Disabling or Enabling Starling 2FA Users from Configuration Center
In case of Starling outage, the Administrator has the privilege to disable Starling users from 2FA in the Web interface by clicking on the Disable Starling 2FA button in Starling 2FA tab in Starling page of Configuration Center.
To re-enable the Starling users to use 2FA again, administrators can click on the Enable Starling 2FA button in Starling 2FA tab in Starling page of Configuration Center.
Managing One Identity Starling Connect
Active Roles provides support to connect to Starling Connect to manage the user provisioning and deprovisioning activities for the registered connectors. Using the Starling Join feature in Active Roles, you can connect to One Identity Starling.
On joining to Starling, the registered connectors for the user are displayed if the Starling Connect subscription exists. If the subscription does not exist, visit the Starling site for Starling Connect subscription. The displayed connectors are available for provisioning or deprovisioning of users or groups through Active Roles.