Two-Factor Authentication (New Brunswick)
11 min
two factor authentication (new brunswick) intrahealth has enabled two factor authentication to allow rich client use anytime and anywhere, i e , externally two factor authentication uses the combination of something you know, which is your password, and something you have, which is your cell phone or email address user authentication is critical because the ability to use rich client anytime and anywhere means the servers are open to the internet customers can also choose to use two factor authentication for additional internal security, i e , within the clinic requirements profile build of 8 4 66 14 (sms pin code delivery) or 8 4 70 21 (email pin code delivery) and higher sms or email must be enabled in the clinic for two factor authentication functionality complex password enforcement is required when https connections are enabled the complex password requirements are a minimum of 10 characters and a maximum of 25 characters some special characters are allowed but not mandatory ! @ # $ % ^ ( ) { } \[ ] < > ; ‘ “ configuration please note, configuration must be done by the sys admin user as an internal user, i e , in the clinic otherwise, there is the risk of locking yourself and all external users out of the system initially in nb, intrahealth helpdesk is working in concert with a clinic user to configure two factor authentication go to organization/preferences/security (global)and select the security tab in the two factor dropdown field, select sms or email and check the require 2 factor authentication for external log ins checkbox located underneath the two factor survival period, the period during which the authentication of the user and their machine is remembered, is set to 28 days by default if the clinic would like to change the number of days, our recommendation is to reduce the number of days the pin survival preference is set to 5 mins before the pin times out the clinic can customize this setting to allow time for the email with the pin to be delivered, as email delivery can take longer than sms delivery press to save the changes and close the window note there is an extra password setting in the unlock panel of the global security preferences window check the allow truncation to \[ ] chrs checkbox to set the shortening of the password on the profile lock screen to a chosen number of characters, with the default being 3 characters this ensures that workflow for everyone isn’t interrupted by having to type in the full complex password throughout the workday go to organization/people & places, open the desired provider/user’s profile and select the general view enter the provider/user’s cell phone number in the cell phone field or their email address in the e mail field this number or email address is used to receive the pin code as part of the two factor authentication press to save the information and leave the window open select the special view in the desired provider/user’s profile check the user can log in externally checkbox if the two factor method selected was sms, the provider/user’s cell phone number will display in a sms number field with a green checkmark if the two factor method selected was email, the provider/user’s email address will display in an e mail field with a green checkmark if the required information is missing, a warning triangle will display in the sms number or e mail field note to enable two factor authentication for users logging in within the clinic, you will need to check the use two factors on log in checkbox press to save the changes and close the window log out and log back in to configure the next provider or user workflow when you (or any user or provider) log in, an enter pin window opens, with an enter pin field you can check the trust this computer checkbox, so profile remembers the authentication of you and your machine for the number of days set in the two factor survival period field in the security tab of the global security preferences window if a different user logs into profile on the same computer, they will be asked for their pin to validate them as a trusted person, even though they are already using a trusted computer if this checkbox isn’t checked, the enter pin window will appear for you at every login note it is important that public computers are not trusted once you receive your pin by sms on your cell phone (see screenshot below) or by email, enter the pin in the enter pin field, press and you will be logged in if another pin needs to be sent, press a 30 second countdown will be displayed note the pin code sent to you will expire after 3 minutes when this happens, a pin code expiry dialog box appears in profile it states the pin code sent to you has expired and offers to send another pin press to receive another pin or to close the pin code expiry dialog box and go back to the login window a hint text shows that the two factor authentication was cancelled