March 12, 2019 By Ben Lopez
Martin Smolny
Michelle Kaufman
2 min read

Multifactor authentication for IBM Cloud users

We are excited to deliver a highly requested feature to our IBM Cloud account owners that supports multifactor authentication (MFA) for federated IDs. A user with a federated ID can log in by using their corporate or enterprise single sign-on (SSO) ID. The enhanced MFA functionality now allows account owners or users with the administrator role on the billing account management service to enable MFA for all users in the account, whether they have a federated or non-federated ID.

For those unfamiliar with MFA, it is also known as two-factor authentication. It adds an extra layer of security to the login process by requiring a user to provide a time-based, one-time passcode (TOTP) that is set up using an authenticator app in addition to their standard ID and password. To put it simply, MFA support strengthens security by preventing unauthorized account access and protecting your data.

What you need to know about enabling MFA

While this is exciting news, there are a few things all account owners and billing service administrators should know prior to enabling MFA for their users for the first time:

  • When MFA is enabled, users need an authenticator app. We will walk users through how to get the authenticator app on a smartphone device via our UI when they log in. 
  • Any user without an authenticator app won’t be able to log in because after MFA is turned on, every user is required to provide their passcode the next time they log in.
  • If you require MFA for your account and you have users in your account that do not have an IBMid, you must enable one of the other MFA options for that user from their User details page in the IBM Cloud console. For more information, see Types of MFA.
  • If you are using CLI, you must use API keys or SSO after MFA is enabled for the account.

Before you turn on MFA, we recommend alerting all IBM Cloud users of the upcoming change and providing instructions for configuring the authenticator smartphone app. These two practices will help prepare your users for the change and prevent any login delays when you enable MFA. See below for a step-by-step walkthrough:

Spread the news

We are ready when you are. Spread the news to your users and head to the IAM Settings page to take the next step towards stronger security and better flexibility with MFA. For more information on the step-by-step process, check out the documentation. Feel free to use the feedback button located on every page in IBM Cloud to provide feedback. Good or bad, we are listening. Lastly, we welcome you to join us on your hybrid and multicloud journey, and we look forward to constantly improving your experience with IBM Cloud.

Was this article helpful?
YesNo

More from Cloud

New 4th Gen Intel Xeon profiles and dynamic network bandwidth shake up the IBM Cloud Bare Metal Servers for VPC portfolio

3 min read - We’re pleased to announce that 4th Gen Intel® Xeon® processors on IBM Cloud Bare Metal Servers for VPC are available on IBM Cloud. Our customers can now provision Intel’s newest microarchitecture inside their own virtual private cloud and gain access to a host of performance enhancements, including more core-to-memory ratios (21 new server profiles/) and dynamic network bandwidth exclusive to IBM Cloud VPC. For anyone keeping track, that’s 3x as many provisioning options than our current 2nd Gen Intel Xeon…

IBM and AWS: Driving the next-gen SAP transformation  

5 min read - SAP is the epicenter of business operations for companies around the world. In fact, 77% of the world’s transactional revenue touches an SAP system, and 92% of the Forbes Global 2000 companies use SAP, according to Frost & Sullivan.   Global challenges related to profitability, supply chains and sustainability are creating economic uncertainty for many companies. Modernizing SAP systems and embracing cloud environments like AWS can provide these companies with a real-time view of their business operations, fueling growth and increasing…

Experience unmatched data resilience with IBM Storage Defender and IBM Storage FlashSystem

3 min read - IBM Storage Defender is a purpose-built end-to-end data resilience solution designed to help businesses rapidly restart essential operations in the event of a cyberattack or other unforeseen events. It simplifies and orchestrates business recovery processes by providing a comprehensive view of data resilience and recoverability across primary and  auxiliary storage in a single interface. IBM Storage Defender deploys AI-powered sensors to quickly detect threats and anomalies. Signals from all available sensors are aggregated by IBM Storage Defender, whether they come…

IBM Newsletters

Get our newsletters and topic updates that deliver the latest thought leadership and insights on emerging trends.
Subscribe now More newsletters