💡 At a Glance
Add an extra security layer to your Coram organization with multi-factor authentication (MFA), and require a one-time passcode from an authenticator app in addition to your email and password. Admins can enable MFA for all users and reset MFA settings. This guide covers enabling and signing in with MFA, and resetting MFA settings for individual users.
⚡ Key Tasks
Enable MFA
As an admin in the Coram web app, navigate to Settings > Security iand switch on Multi-Factor Authentication. This automatically enables MFA for all users.
Log In for the First Time with MFA
After MFA is enabled, install an authenticator app on your secure mobile device, then log in as usual with your credentials to see a QR code. Scan this code with the authenticator app, then enter the generated one-time passcode to complete the login.
Subsequent Logins with MFA
For future logins, enter your password and then, when prompted, enter the passcode from your authenticator app on the MFA page.
Reset MFA for a User
If a user loses access to their authenticator device, admins can reset that user's MFA by going to Settings > Users, selecting the user, and clicking Reset MFA.
For detailed information, keep reading below.
Overview
Multi-Factor Authentication (MFA) adds an extra layer of security to your organization in Coram. In addition to an email and password, all users must use an authenticator app to generate a unique, one-time passcode at login. MFA ensures that even if a password is compromised, unauthorized users cannot access your account without the unique code from your authenticator app. This added security is vital in protecting sensitive data and maintaining compliance with industry standards.
Admin users can enable or disable MFA for all users within the organization, ensuring consistent security practices across the board. By following this guide, you secure your Coram account with MFA, protecting your organization's data while ensuring a smooth user experience during login.
Enabling MFA
Note: Only users with Admin permissions can enable and disable MFA.
Access the Coram web app and sign in to your account.
In the top-right corner, click the dropdown arrow ( ▼ ) and select Settings.
A screenshot that shows the location of the Account Settings dropdown arrow.
In the Settings sub-menu, click Security.
Set the Multi-Factor Authentication (MFA) toggle switch to enabled.
Settings save automatically, and MFA is enabled for all users in your organization.
Logging in for the First Time After MFA Enablement
Before You Begin:
Ensure you have a secure mobile device that only you can access.
Install an authenticator app on your mobile device.
To log in for the first time after MFA enablement:
Log in as usual with your single sign-on (SSO) or email and password.
The MFA QR code appears.
A screenshot that shows the first-time MFA login page.
Open the authenticator app on your mobile device, and use the app’s QR scanner to scan the on-screen QR code.
Coram MFA is added to your authenticator app, and a one-time passcode is generated.
To log in, type the one-time passcode into the Coram web app, then press Enter.
Subsequent Logins for All Users
Log in as usual with your SSO or email and password.
When the MFA page appears, open your authenticator app.
A screenshot that shows the regular MFA login page.
Retrieve the Coram MFA one-time passcode and enter it into the Coram web app.
To log in, type the one-time passcode into the Coram web app, then press Enter.
Resetting MFA for a User
Note: Only users with Admin permissions can reset MFA settings.
Access the Coram web app and log in to your account.
In the top-right corner of the page, click the dropdown arrow ( ▼ ) and select Settings.
In the Settings sub-menu, click Users.
Find and click the email of the user whose MFA you want to reset.
The Edit Details window appears.
To reset their multi-factor authentication settings, for Reset MFA, click Reset, then click Confirm.
A screenshot of the Edit Details page that shows the the MFA Reset button.
Note: If you are a Regular, Limited, or Live-Only user, and you lose access to the mobile device where your authenticator app is installed, contact an admin user to reset your MFA settings.
Best Practices and Tips
Use a personal mobile device for MFA to maintain security.
Regularly update your authenticator app and review connected devices.
Admins should enable MFA organization-wide to enforce consistent security standards.
Ensure only authorized personnel have access to the device used for MFA.