Skip to main content

Multi-factor authentication

Multi-factor authentication (MFA) asks for a second piece of evidence in addition to a password, so a password on its own isn't enough to sign in. Accounts that sign in with an iGrafx username and password can add a second factor: an authenticator app or a passkey.

Overview

Accounts that sign in with an iGrafx username and password authenticate against the iGrafx IdentityiGrafx Identity The iGrafx identity and access management service that brokers authentication between customer identity providers and Process360 Live components. Solution — the regional service your platform forwards sign-in to, at id.igrafxcloud.com outside EMEA and id.igrafxcloud.eu within it. The second factor belongs to that account, so it's registered in the Identity Solution's account console rather than in Process DesignProcess Design The discipline of explicitly modeling business processes to document, analyze, and optimize them. In Process360 Live, process design is the authoring side that complements mining's data-driven view..

Users register their own methods, which needs no administrator action. The account console lists both methods under Two-Factor Authentication, and each one shows whether it's set up yet.

Which accounts this applies to

  • Accounts with an iGrafx username and password — the second factor is registered in the account console, by the user.
  • Accounts federated to your own identity provider through SSOSSO An authentication scheme that lets users sign in once with an identity provider and access Process360 Live without re-entering credentials. — your identity provider authenticates the user, so any second factor is configured there rather than in iGrafx. See Setting up single sign-on.
  • Platforms on the classic iGrafx login — there's no account console, so users have nowhere to register a second factor. Which path to follow tells you which login a platform uses.

Second-factor methods

  • Authenticator Application — the Identity Solution uses the time-based one-time password (TOTP) standard and presents a QR code during setup, so a standards-compliant authenticator app can generate the codes. The user reads a code from the app at each sign-in.
  • Passkey — a credential held on the user's own device or password manager and unlocked with its screen lock, fingerprint, or face recognition. There's no code to read from a phone and nothing to retype.

A user can register more than one method. Sign-in then prompts for one of them and offers Try Another Way, which lists the rest so the user can pick another.