ShareFile

Mandatory enforcement of Two-factor authentication

About Two-Step Verification

Two-Step Verification uses your phone to provide an extra layer of security for your username. After you log in, you are asked to enter a verification code that is sent to your phone via text message (SMS) or voice call.

Two-Step Verification is supported on iOS and Android mobile devices.

Enforcing Two-Step Verification

By enabling this feature, you make the Two-Step Verification option available to all users on the account. ShareFile recommends use of Two-Step Verification as an additional layer of security to reduce the likelihood of any unauthorized access.

FAQ for standalone RightSignature users

  1. What if one or more users do not have access to a phone for verification?

    The only way to access RightSignature after enforcing Two Factor Authentication is using the phone number.

  2. What if any user doesn’t have their phone registered for Two-Step Verification?

    If you are not a master admin, contact your account Admin. The admin can reset your Two-Step Verification from Account > Users section. You can enter their current phone number and start using two-factor authentication.

  3. What is the expiration time frame for the text / SMS or voice based passcode?

    The text / SMS or voice based passcode will expire in 2 minutes.

Enabling Two-Step Verification

Two-Step Verification settings are managed at Account > Settings> Account Settings> Two Step Verification.

You are prompted to enter your country as well as the phone number you would like RightSignature to send an SMS or voice message to upon your account activation. You do not need to enter your country code, You can choose to receive either a text (SMS) message or a voice call to your provided phone number.

Pressing Send will send a code via the selected method to the provided number. Enter the code on the next screen in order to complete the setup of two-step verification. You are given the option to trust the device you are currently using. Use this if you do not want to be prompted for another verification code when using this computer and browser in the future.

Can I force my users to use Two-Step Verification?

For new users, the activation process will require that the user enter a phone number that is enabled for text message (SMS) or voice.

For existing users, the user is prompted to enter the phone number that is enabled for text message (SMS) or voice on the next login from the Web App, mobile app for iOS and Android.

Disabling Two-Step Verification

Contact your RightSignature account’s master admin. If you are a master admin user you can disable this feature for all users on your RightSignature account at Account > Settings > Account Settings > Two-Step Verification. Please note that the opt-out waiver should be filled before disabling. Refer to the note section for the opt-out waiver.

Login with Two-Step Verification

After you have set up your Two-Step Verification, you will be prompted for your verification code after logging in to RightSignature on a computer you have not opted to trust. You must enter the code you have received most recently in order to proceed to your RightSignature account. If you do not receive the code, you can select I didn’t receive a code for more options. If you are still unable to get in to your RightSignature account, please contact your RightSignature administrator.

You will see an additional option for the verification code.

Reset User Phone Numbers

Master admins requiring their phone number to be reset will need to contact support.

If a non-master admin has to change their primary phone number used for two-step verification, the account master admin may initiate the reset. To do so, navigate to Account > Users and click on the user’s name that requires the reset. This will direct you to that employee’s profile page where the master admin can click Reset two-step verification under Actions.

A confirmation message will be displayed and after clicking Reset, the user will be emailed a hyperlink that expires in 15 minutes.

After the user clicks the hyperlink in the email, they will be directed to the login page to enter their credentials. Once authenticated, they will be able to enter their new phone number and complete the two-step verification setup.

Mandatory enforcement of Two-factor authentication