Multi-Factor Authentication

Add a time-based one-time password (TOTP) second factor to local sign-ins.

MFATOTPSecurityAdmin

Rapid BI Catalog supports time-based one-time password (TOTP) multi-factor authentication for an extra layer of security at sign-in. You enroll with any standard authenticator app.

MFA applies to local logins
MFA secures local username/password sign-ins. SSO sign-ins defer multi-factor to your Identity Provider, so configure MFA for SSO users at the IdP. See SSO Configuration.

How MFA Works

Once enrolled, a user enters their username and password as usual, then a 6-digit code from their authenticator app to complete sign-in. Each user manages their own enrollment; administrators can set an organisation-wide requirement and reset a user's MFA if they lose their device.

Enrolling in MFA

  1. Open your profile and choose to set up MFA.
  2. Scan the displayed QR code with your authenticator app (or enter the setup key manually).
  3. Enter the current 6-digit code from the app to verify and activate MFA.

To turn MFA off again, use the Disable MFA option — unless an administrator has made MFA mandatory (see below).

Requiring MFA for All Users

An administrator can enable MFA required for all users. When this is on, any local user who has not yet enrolled is prompted to set up MFA at their next login before they can continue, and users cannot disable it.

Require MFA for all users
Administrators can require MFA for all local users from the security settings.

MFA and SSO-Only Deployments

Disabled when SSO is the only login method
The MFA required control governs local logins only. When SSO is the only enabled sign-in method (local password login is disabled), the control is disabled — multi-factor is then owned by your Identity Provider.

Resetting a User's MFA

If a user loses access to their authenticator device, an administrator can reset their MFAfrom User Management. The user is then prompted to enroll again on their next sign-in (immediately, if MFA is required).

Next Steps