Organization Security Settings let Organization Administrators control key login and access requirements for their OnBoard organization. These settings can help protect user accounts by enforcing mobile app security, requiring two-factor authentication, and enabling single sign-on.
| Explore the General and Security Settings course and others in OnBoard Academy - link: Security Settings |
Accessing Security Settings
To access these settings, select Settings from the left navigation menu, then select the Security tab at the top of the screen.
Enforce App Security
What Does Enforce App Security Do?
Enforce App Security requires users who log in to OnBoard from a mobile app to use an extra security method. This applies to supported mobile apps, such as Android, iOS, and Windows apps.
When this setting is enabled, users must set up and use one of the following security methods:
- A 4-digit personal identification number, also called a PIN
- A biometric login method, such as Touch ID or Face ID, if available on their device
Users must use this extra security method each time they open the OnBoard app on their mobile device.
How Do I Enforce App Security?
To require App Security for mobile app users:
- Go to Settings.
- Select the Security tab.
- Turn on the Enforce App Security toggle.
- Ask users to set up their required mobile security method the next time they log in from a mobile app.
| To learn more about App Security, explore the article: Mobile Login and Security Guide |
How Do I Add Exceptions for App Security?
After you turn on Enforce App Security, the Add Exceptions for App Security button appears.
Use this option to allow specific users to skip the App Security requirement.
What Happens When a User is Added as an App Security Exception?
Users added to the exceptions list are not required to use mobile App Security when they log in from their devices.
Two-Factor Authentication
What is Two-Factor Authentication?
Two-Factor Authentication, also called 2FA, adds a second step to the login process. When 2FA is enabled, users who sign in with their OnBoard ID and password must also enter a security code.
The security code can be sent by:
- SMS text message
This requirement applies to both:
- Website logins
- Mobile app logins
| To receive 2FA via text, users must add their SMS phone number in the Profile settings. See the Profile Settings article for more details. |
How Do I Require Two-Factor Authentication?
To require 2FA for users who sign in with an OnBoard ID and password:
- Go to Settings.
- Select the Security tab.
- Turn on the Require Two-Factor Authentication toggle.
- Users will be asked to enter a security code after entering their OnBoard ID and password.
How Do I Add Exceptions for Two-Factor Authentication?
After you turn on Require Two-Factor Authentication, the Add Exceptions for Two-Factor Authentication button appears.
Use this option to allow specific users to skip OnBoard’s 2FA requirement.
What Happens When a User is Added as a Two-Factor Authentication Exception?
Users added to the exceptions list are not required to complete OnBoard’s Two-Factor Authentication during login.
How Does Two-Factor Authentication Work With Single Sign-On?
Users who sign in with their organization’s Single Sign-On, also called SSO, do not need to complete OnBoard’s Two-Factor Authentication.
If your organization requires both SSO and 2FA, enable two-factor authentication through your Identity Provider, also called an IdP. An IdP is the system your organization uses to manage user sign-ins, such as Microsoft Entra ID, Okta, or another authentication provider.
Single Sign-On (SSO)
What is Single Sign-On?
Single Sign-On, or SSO, lets users access OnBoard with the same login credentials they use for their organization’s other systems.
This can make sign-in easier for users and help organizations manage access through their own identity provider.
Who Can Use Single Sign-On?
Single Sign-On is available with OnBoard’s Ultimate plan or as an add-on to the Premium or Essentials plans.
How Do I Enable Single Sign-On?
To enable SSO for your organization:
- Go to Settings.
- Select the Security tab.
- Turn on the Enable SSO setting.
- Configure SSO based on your organization’s identity provider requirements.
- Confirm that users can sign in with their organization-managed credentials.
What Happens When SSO is Enabled?
When SSO is enabled and enforced, users access the organization in OnBoard with their existing organization-managed credentials instead of their standard OnBoard ID and password.
| To learn more, explore the SSO Help Center Article collection. |
FAQs
Who can manage Organization Security Settings?
- Organization Administrators can manage security settings for the organization.
Where are Organization Security Settings located?
- Organization Security Settings are located in Settings under the Security tab.
What does Enforce App Security do?
- Enforce App Security requires mobile app users to use an extra security method, such as a PIN or biometric login, when signing in to OnBoard from a mobile device.
Can some users be excluded from App Security?
- Yes. After Enforce App Security is enabled, Organization Administrators can add users to the App Security exceptions list.
What does Two-Factor Authentication do?
- Two-Factor Authentication requires users signing in with an OnBoard ID and password to enter a second security code sent by email or SMS text message.
Does Two-Factor Authentication apply to mobile logins?
- Yes. When enabled, OnBoard’s Two-Factor Authentication applies to both website logins and mobile app logins for users signing in with an OnBoard ID and password.
Can some users be excluded from Two-Factor Authentication?
- Yes. After Two-Factor Authentication is enabled, Organization Administrators can add users to the Two-Factor Authentication exceptions list.
Do SSO users need to complete OnBoard Two-Factor Authentication?
- No. Users who sign in with SSO do not complete OnBoard’s Two-Factor Authentication. If 2FA is needed with SSO, configure it through your identity provider.
What does SSO mean?
- SSO stands for Single Sign-On. It lets users sign in to OnBoard with credentials managed by their organization.
What does IdP mean?
- IdP stands for Identity Provider. It is the system an organization uses to manage user sign-ins and authentication.
Which OnBoard plans include SSO?
- SSO is available with OnBoard’s Ultimate plan or as an add-on to the Premium plan.
Comments
0 comments
Please sign in to leave a comment.