Multi-Factor Authentication - User Portal
SomeThe parkingUser providers supportPortal Multi-Factor Authentication (MFA). Tofeature enableadds MFA,an essential layer of security to user accounts by requiring a One-Time Password (OTP) during the login process. Its primary purpose is to protect sensitive user data and startensure usingthat one-timeonly passwords,authorized followindividuals thesecan steps:access the parking portal. This article is intended for OPS-COM administrators to help them understand the user MFA workflow and support their clients.
Setup and Configuration
This feature requires the organization to have MFA support enabled on their system. Once available, the configuration is primarily handled on the User Side, where individual users opt-in and manage their own security settings.
QuickAdmin Steps:Side:
Using this Feature
Administrators can use the following instructions to guide users through enabling MFA on their accounts and logging in with One-Time Passwords.
Enabling Multi Factor Authentication
-
LoginLogthenin to the User Portal and clickonyourname.nameInin thedropdowntopclickcornerSecurity.of the screen. ClickChange Multifactor Authentication Settings.ChooseDisable MFAor Enable One-Time Passwords.-
Click
SendSecurityOne-TimefromPasswordtheTodrop-downEmailand go into your email and copy your one time password.menu. Enter your one-time password as well as your current password then clickSubmit.
TheScroll one-time password is only valid for 15 minutes. Ifto the password has expired, a new one will be generated.
Step-by-Step Instructions:
Loginthen click on your name. In the dropdown clickSecurity.Find theMulti-Factor Authenticationsection. Thissectionshows the current MFA statusandincludes a button to manage the settings.Clickclick the Change Multifactor Authentication Settingsbuttonbutton.at the bottom of the page to open theMulti-Factor Authenticationsettings.-
Either:Disable MFA, orChoose Enable One-Time Passwords.from the available settings. -
Click
onthe Send One-Time Password To Emailthen enter: Your current password, and the one-time password (OTP).button. -
To receive an OTP, click the button to send itNavigate to your registered emailaddress. The OTP will be sent to you by emailinbox andiscopyvalidtheforgenerated15 minutes.OTP. -
SelectReturn to the portal and enter the OTP alongside yourOTPcurrentoptionaccountfrompassword in thepicklistprovidedbelowfields. -
Click the
current password field. PressSubmit button to confirm your changes andupdateactivateyourMFA.MFA
One-Time Passwords are youronly choices:
- for
OTP15Expiry:minutes.AnyIfunusedtheOTPsuser'swillpasswordbeexpiresinvalidatedbeforeifthey enter it, they must generate a new one. Generating a new OTP automatically invalidates any previously unused passwords.Logging In with MFA Enabled
Once MFA is
generated,successfullyevenenabled, the standard login workflow will change to include the OTP validation step.-
Enter your username and password on the main portal login page.
-
Check your registered email address for the automatically generated OTP.
-
Enter the OTP into the prompt on the screen.
-
Click the Submit button to complete the login process and access the site.
When MFA is active, the system restricts access to the portal. Users will be forcibly redirected to the OTP entry screen if they
haven'tattemptexpiredtoyet.navigate -
OTPtoEmailanyFormat:otherTheinternal pages (such as their profile or vehicle management) before submitting a valid One-Time Password.Understanding OTP
emailSessionwillSettingsfollowWhen guiding users through their MFA settings, administrators should be aware of how the
templatesystemsethandlesforactiveyourOTPaccount.sessions:
-
Session Storage: Once
youaenteruser enters an OTP,itthe validation is stored inyourtheir browser's local session data. Ifyouthey clearyourtheir browser's localstorage,storageyou'llorneedcache, they will be forced to enter a newOTP.OTP upon their next login. -
Different Devices:
OTPsOTPdosession data does not persist across different browsers ordevices.hardware. Ifyoualoguser logs in fromanothera new computer, a secondary mobile device,you'llor a different web browser, they will be prompted to enter a new OTP. -
LoginEducatebyusersenteringonyourOTPusernameexpiration:andAlwayspasswordremindasusersnormal.that One-Time Passwords strictly expire after 15 minutes. If a user complains about invalid codes, ensure they are not attempting to use an expired OTP or one that was invalidated when they clicked the send button multiple times. -
AfterAssistloggingwithin,deviceyou'llswitching:beInformpromptedusers that they will need access toentertheir email whenever they switch devices. Because OTPs are tied to local session storage, attempting to log in on aone-timenewpassword.phone or public computer will always trigger a new OTP request. You will be redirected to the OTP screen when accessing any page other than:/login– Login page/logout– Logout page/one_time_password– OTP entry screen/account/send_email– Send OTP email/account/multiauth– Multi-auth settings page
Enter your OTP, submit it, and you'll be able to access the rest of the site.