MOBOTIX Cloud - Two-factor authentication

Two-factor authentication (2FA)
sometimes referred to as two-step verification or two-factor authentication, is a security method in which users provide two different authentication factors to verify themselves.

Two-factor authentication adds an extra layer of security to the authentication process by making it more difficult for attackers to gain access to a person’s devices or online accounts, because even if the victim’s password has been hacked, a password alone is not enough to pass the authentication check.

With two-factor authentication, access to a MOBOTIX CLOUD account is only possible with a trusted device. When a user wants to log in to a new device for the first time, they must provide two pieces of information: a password and a four-digit security code. The security code must be obtained via a trusted telephone number or email address.

After logging in, the MOBOTIX CLOUD user will no longer be asked for the security code on the authenticated device unless the user logs out completely, deletes the device or has to change the password for security reasons. MOBOTIX AG recommends using two-factor authentication for each account to ensure your security.

To activate this function, open “My profile” in the top right-hand corner of the MOBOTIX CLOUD web interface:

Screenshot 2023-10-17 at 08.36.25

image

If no phone number has been added, you will need to use your email to receive your security code.

image

If your telephone number is linked to your account, it can also be used to receive the security code.

If you use the e-mail, you will receive an e-mail as in the following example:

image

When a new user is added to a MOBOTIX CLOUD account, an email is sent to the potential new user to verify their address. To create their account, the potential new user must click on the “Set password” link in the email. Once they have entered and submitted their new password, the new user is logged in without an additional security code. In this case, the link in the email is used instead of the security code. Two-factor authentication will continue as usual the next time the user logs in.

If a user does not enter the correct security code after four attempts, their account is automatically deactivated and an email notification is sent to the user’s email address.

image

Note: If you add your device to the trusted devices, it will be displayed in the Trusted devices section of the web user interface under “My profile”:

Screenshot 2023-10-17 at 07.54.44

Adding a phone number

Note: MOBOTIX CLOUD does not allow two changes at once. Users cannot activate two-factor authentication and add a phone number at the same time. We recommend that you add your phone number first.

Under “My profile” (as seen above), enter the country code and the phone number as SMS phone. Don’t forget to save your changes.

To verify your phone number, enter your password and send it. A security code will then be sent to your phone as an SMS.