Skip to main content

Multi-Factor Authentication - User Portal

SomeThe parkingUser providers supportPortal Multi-Factor Authentication (MFA). Tofeature enableadds MFA,an essential layer of security to user accounts by requiring a One-Time Password (OTP) during the login process. Its primary purpose is to protect sensitive user data and startensure usingthat one-timeonly passwords,authorized followindividuals thesecan steps:access the parking portal. This article is intended for OPS-COM administrators to help them understand the user MFA workflow and support their clients.

Setup and Configuration

This feature requires the organization to have MFA support enabled on their system. Once available, the configuration is primarily handled on the User Side, where individual users opt-in and manage their own security settings.

QuickAdmin Steps:Side:

Ensure
that
your
system's email templates are properly configured, as the OTP emails will utilize the standard system email formatting designated for your account.

Using this Feature

Administrators can use the following instructions to guide users through enabling MFA on their accounts and logging in with One-Time Passwords.

Enabling Multi Factor Authentication

  1. LoginLog thenin to the User Portal and click on your name.name Inin the dropdowntop clickcorner Security.of the screen.

  2. Click Change Multifactor Authentication Settings.
  3. Choose Disable MFA or Enable One-Time Passwords.
  4. Click SendSecurity One-Timefrom Passwordthe Todrop-down Email and go into your email and copy your one time password.menu.

  5. Enter your one-time password as well as your current password then click Submit.

TheScroll one-time password is only valid for 15 minutes. Ifto the password has expired, a new one will be generated.

Step-by-Step Instructions:
  1. Login then click on your name. In the dropdown click Security.
  2. Find the Multi-Factor Authentication section. This section shows the current MFA status and includes a button to manage the settings.
  3. Clickclick the Change Multifactor Authentication Settings buttonbutton.

    at the bottom of the page to open the Multi-Factor Authentication settings.
  4. Either: Disable MFA, orChoose Enable One-Time Passwords. from the available settings.

  5. Click on the Send One-Time Password To Email then enter: Your current password, and the one-time password (OTP).button.

  6. To receive an OTP, click the button to send itNavigate to your registered email address. The OTP will be sent to you by emailinbox and iscopy validthe forgenerated 15 minutes.OTP.

  7. SelectReturn to the portal and enter the OTP alongside your OTPcurrent optionaccount frompassword in the picklistprovided belowfields.

  8. Click the current password field. Press Submit button to confirm your changes and updateactivate yourMFA.

    MFA
  9. settings.
These

One-Time Passwords are youronly choices:

valid
    for
  • OTP15 Expiry:minutes. AnyIf unusedthe OTPsuser's willpassword beexpires invalidatedbefore ifthey enter it, they must generate a new one. Generating a new OTP automatically invalidates any previously unused passwords.

    Logging In with MFA Enabled

    Once MFA is generated,successfully evenenabled, the standard login workflow will change to include the OTP validation step.

    1. Enter your username and password on the main portal login page.

    2. Check your registered email address for the automatically generated OTP.

    3. Enter the OTP into the prompt on the screen.

    4. Click the Submit button to complete the login process and access the site.

    When MFA is active, the system restricts access to the portal. Users will be forcibly redirected to the OTP entry screen if they haven'tattempt expiredto yet.

  • navigate
  • OTPto Emailany Format:other Theinternal pages (such as their profile or vehicle management) before submitting a valid One-Time Password.

    Understanding OTP emailSession willSettings

    follow

    When guiding users through their MFA settings, administrators should be aware of how the templatesystem sethandles foractive yourOTP account.

  • sessions:

    • Session Storage: Once youa enteruser enters an OTP, itthe validation is stored in yourtheir browser's local session data. If youthey clear yourtheir browser's local storage,storage you'llor needcache, they will be forced to enter a new OTP.OTP upon their next login.

    • Different Devices: OTPsOTP dosession data does not persist across different browsers or devices.hardware. If youa loguser logs in from anothera new computer, a secondary mobile device, you'llor a different web browser, they will be prompted to enter a new OTP.


    Best Practices and Considerations

    • LoginEducate byusers enteringon yourOTP usernameexpiration: andAlways passwordremind asusers normal.that One-Time Passwords strictly expire after 15 minutes. If a user complains about invalid codes, ensure they are not attempting to use an expired OTP or one that was invalidated when they clicked the send button multiple times.

    • AfterAssist loggingwith in,device you'llswitching: beInform promptedusers that they will need access to entertheir email whenever they switch devices. Because OTPs are tied to local session storage, attempting to log in on a one-timenew password.phone or public computer will always trigger a new OTP request.

    • You will be redirected to the OTP screen when accessing any page other than:

      • /login – Login page
      • /logout – Logout page
      • /one_time_password – OTP entry screen
      • /account/send_email – Send OTP email
      • /account/multiauth – Multi-auth settings page
    • Enter your OTP, submit it, and you'll be able to access the rest of the site.