Blog Post

Release Notes
1 MIN READ

Introducing Multi-Factor Authentication for Marketing

SofiaP's avatar
SofiaP
Khoros Alumni (Retired)
5 years ago

As part of our ongoing series of security enhancements, Khoros Marketing will soon require any non-SSO user to use Multi-Factor Authentication to login to the platform. This requirement is currently not live, but will be in the next few business days.

Clear instructions for users, alongside a series of FAQs and troubleshooting tips, have been provided here

Once MFA is enabled, users will need to follow the new authentication process to login each time their previous session expires. Sessions typically expire when the user has explicitly logged out, or because they have been timed out of the platform after a period of inactivity.

We are concurrently exploring further MFA options, to help better blend usability, speed, and security, and platform administrators have been sent an email with advice for communicating with all users.

If you have questions about MFA which are not covered by the article or subsequent email communications, please contact khorosmarketingplatform@khoros.com

Updated 5 months ago
Version 3.0
  • DanCr's avatar
    DanCr
    Khoros Alumni (Retired)

    MArduengo I'm sure you're definitely not alone in using multiple windows.

    The behavior you outlined is exactly what's now expected.

    You will have to click login in a new window, but as your existing session is still active, you won't have to retype the authentication data multiple times.

    Note that once your session expires in any of your open windows, you will be logged out of all other windows. This will likely mean you have to log back in with your authentication info in one window at least, before refreshing or re-opening the others.

    Thanks for the catch and I'll make sure we add this information into our existing login documentation to help anybody else with the same question.

  • DanCr's avatar
    DanCr
    Khoros Alumni (Retired)

    AmandaPo some of the organizations we work with choose to instrument and utilize the Single Sign On (SSO) capabilities of Marketing, in order to control and secure compliance with the authentication standards and internal policies of their company.

    In this case, a 'non-SSO user' is simply a user whose company is not using this capability, and who therefore logs in through the regular native process. If your company hasn't set up SSO for use with Marketing, you can consider yourself a 'non-SSO user'.

    Hope that helps!

  • SofiaP  will the determination of whether or not MFA is implemented be at the discretion of a global administrator or will this be mandatory and non-configurable for any non-sso users?

  • Thanks for the information and the security upgrade. How will this affect having Khoros open in multiple browser windows? I do this fairly often--and now opening in a new window requires me to click login (although I do not have to retype data for login).