Authentication Methods
The Authentication Methods page enables internal users and Vendor Reps to enroll the authentication methods they use to access VPAM. Depending on the System Admin configuration, these methods can be used for multi-factor authentication (MFA) or Risk-Based Authentication (RBA). For MFA, users provide an additional authentication factor during login. For RBA, ITDR evaluates the authentication method when it detects risk.
If the System Admin configures MFA or RBA for accessing the server, the system displays an indicator on the Authentication Methods page.
Use this page to review required authentication methods, complete enrollment, and revoke an authentication method that is already set up.
To open the Authentication Methods page:
-
Open My Account.
-
Select Authentication Methods.
Depending on the customer and system configuration, users can enroll in Face Authentication, Mobile Authentication, or both. These self-enrollment options appear only when a System Admin enables MFA. If MFA is not enabled, the self-enrollment options do not appear.
When RBA requires enrollment, users can click Skip for now to defer enrollment one time for supported authentication methods. The next time users are prompted, they must complete enrollment before they can access again.
Face Authentication
Face Authentication provides a passwordless authentication method for accessing applications and systems protected by VPAM. If your customer requires Face Authentication, you must complete enrollment before you can access protected resources.
A System Admin must enable Face Authentication before it is available to you.
This feature requires the Identity Assurance and Threat Detection (IATD) package. This package includes Facial Biometric Authentication and Identity Threat Detection and Response (ITDR). Contact your Imprivata Customer Success Manager or call +1 800 935 5958 to activate this feature.
If Face Authentication is set to Yes in Authentication Requirements, users are prompted to enroll in Face Authentication the next time they log in.
Enrollment may open an external enrollment page. Follow the prompts until VPAM confirms that enrollment is complete.
To enroll manually:
-
In the VPAM user portal, open My Account > Authentication Methods.
-
Confirm that the Face Authentication description indicates that the method is not set up.
-
Click Start enrollment.
-
Click Continue.
NOTE:If Face Authentication is required as a second factor for each login, you must complete enrollment before you can continue.
-
Select your place of residence from the location drop-down list.
-
Click Continue.
-
Capture a clear face image.
Use a well-lit location, face the camera directly, and keep your face visible in the camera frame.
-
Click Done after the system confirms successful enrollment.
After enrollment, Face Authentication is available as a second-factor authentication method.
If Face Authentication is required to access VPAM, revoking enrollment immediately logs you out of the VPAM user portal. You cannot log in again until you complete enrollment.
You can revoke Face Authentication enrollment from Authentication Methods at any time.
-
Open My Account > Authentication Methods in the VPAM user portal.
-
Confirm that the Face Authentication description indicates the method is set up.
-
Click Revoke enrollment.
Mobile Authentication
Mobile Authentication uses a time-based one-time code generated by a supported authenticator application on your mobile device. Select an authenticator application from the options listed on the enrollment screen.
The authentication code is a 6-digit code that refreshes every 30 seconds. If a code is close to expiring, wait for the next code before you continue.
To enroll in Mobile Authentication:
-
Open My Account > Authentication Methods in the VPAM user portal.
-
Confirm the Mobile Authentication description indicates the method is not set up.
-
Click Start enrollment.
-
Download one of the supported authenticator applications to your mobile device.
-
Open the authenticator application and scan the QR code displayed on the enrollment screen.
-
Enter the authentication code generated by the application.
-
Click Configure Authenticator.
After enrollment, Mobile Authentication is available as a second factor authentication method.
Depending on your organization’s configuration, Mobile Authentication can be:
-
Required. If Mobile Authentication is set to Required, administrators can click Mobile Authentication Options.
This opens a configuration dialog where administrators can exclude specific user groups from the requirement or enforce Mobile Authentication based on user type.
-
Not required.
-
Required only when logging in outside authorized trusted networks.
When VPAM prompts you for Mobile Authentication, open your authenticator application and enter the current 6-digit code.
If the code does not work, confirm that the time on your mobile device is set automatically, and then try the next code. If the issue continues, contact your customer or administrator.
If Mobile Authentication is required to access VPAM, revoking enrollment immediately logs you out of the VPAM user portal. You cannot log in again until you complete enrollment.
You can revoke Mobile Authentication enrollment from Authentication Methods. To confirm the revocation, you must enter a valid authentication code from your authenticator application.
-
Open My Account > Authentication Methods in the VPAM user portal.
-
Confirm the Mobile Authentication description indicates the method is set up.
-
Click Revoke enrollment.
-
Enter a valid authentication code from your authenticator application.
-
Confirm the revocation.
After you revoke enrollment, Mobile Authentication is no longer available for your account.
If you lose your mobile device or cannot access your authenticator application, contact your customer or administrator. An administrator may need to reset your Mobile Authentication enrollment before you can enroll again.