Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Introduction

TDS platform is utilising utilizing SSO solution based on Keycloak. That is usually standalone and users can use basic authentication procedure using username and password or multi factor authentication (MFA) with time based OTP token.

Enabling MFA

For specific user

MFA can be optionally enabled by user via user profile on portal or via OTP token reset from TDS SSO login page.

For area/project

Following steps will enable Multi Factor authentication on area/project level. Members of area/project will be required to set up TDS MFA solution can be also enabled on area/project level ONLY by members with relevant owner role. Just to go to your portal area/project, open the detail menu item and enable "Multi Factor Authentication management" feature. This will automatically check whether all area/project members have TDS OTP tokens already created. People with already configured TDS OTP tokens do not need to do anything. If some users are still missing TDS OTP token, they will be forced to setup TDS OTP tokens during next sign-in using TDS password or AzureAD/ADFS integration unless they already use MFA in TDS. TDS OTP token is then required every time when signing in using TDS password.

  • Go to Area/Project configuration
  • Enable Multi Factor Authentication management feature

Customers using Some customers have AzureAD/ADFS integration as described in this link Single sign on - SSO#AzureADorADFSauthentication. Such customers only need to configure OTP token if they do not have it, but then they are NOT bothered with . They are not required to use TDS OTP token use for sign in as they already utilise utilize MFA capable SSO integration. In case when TDS password is attempted to be used, OTP is required.

OTP token reset or enable

...