Multi Factor Authentication (MFA)
The security options to login into Nimbus are set at client and user levels. There is also the ability to select the method of MFA - either email or App.
Client Security Settings
MFA can be configured at a client level, setting of which will then cascade down to all users below. Users are able to adjust their own personal MFA settings, but they cannot make the restriction less strict than what is configured at a client level.
How to configure
The option can be found by clicking on the client, selecting edit on the manage page and scrolling down to the section titled 'Security Settings'. Select the relevant option from the drop down.
MFA client options
No MFA Required |
MFA will never be required for users. We do not recommend this setting due to the security risk and to protect access to customer data. |
MFA only new sessions (Default) |
This is the default setting for all new clients and users. This setting remembers both IP and browser session for 90 days. An MFA will be required if both the IP and the browser session has changed OR it has been longer than 90 days. |
Managers require MFA every login |
Any user configured as a manager under the client will be presented with an MFA on every login attempt. |
Everyone requires MFA every login |
All users under the client will be presented with an MFA on every login attempt. |
Note: Users are able to change their individual MFA settings (see below), however they are not able to reduce the security on their own account to a weaker security setting than the client level. They can only increase the security or leave the same.
For example, if the client setting is MFA only new sessions (Default), users will not be able to select No MFA required, but will be able to chose to require MFA every login.
User Security Settings
MFA can be configured at a user level. The user inherits the MFA settings from the client level, but can be edited to a more strict level of security if desired. The security level cannot be lowered, please contact your Nimbus administrator if you would like to get security lowered.
How to configure
Click on the drop down next to your name and select "My Details".
Find the section titled 'Security - Multi Factor Authentication' and select the relevant option from the drop down.
MFA User options
- No MFA Required
- MFA will never be required
- We do not recommend this setting due to the security risk and to protect access to customer data.
- MFA only new sessions (Default)
- This is the default setting for all new clients and users
- This setting remembers both IP and browser session for 90 days.
- An MFA will be required if both the IP and the browser session has changed OR it has been longer than 90 days.
- Every Login
- MFA will be presented on every login attempt
- MFA will be presented on every login attempt
MFA Method
There are two methods for Multi Factor Authentication in Nimbus:
Authenticator App (Recommended) |
Set up and use an authenticator app that generates a code for the MFA.
|
Sends a code to your email address, also includes a link that will automatically apply the code and log in. |
How to choose MFA Method
- Set up of user: On set up of the user, they will be presented with a screen to input information, where the MFA method can be chosen
- Edit user details. Click on the drop down next to your name and select "My Details".
On either of the above methods you will be presented with a section called 'Security - Multi Factor Authentication'
Under the MFA Method, select either Email or Authenticator App.
How to configure MFA Method
If email is chosen, no further action is required and a code will be sent to the registered email address with the account.
Important Note: ensure that noreply@nimbusdigital.com is added to your contacts as a safe sender to ensure that emails are always received. Due to issues with various mail servers receiving emails, we recommend using the authenticator app as your MFA method of choice.
Authenticator App
- Click on the button marked 'Click to setup'.
- The user will be presented with a screen including a QR code.
- Use your Authenticator App of choice to scan the QR code as instructed in the app. Follow links below on how to setup popular apps.
- Google Authenticator
- Microsoft Authenticator
- If required and the QR code fails, you can use the button to reveal a code that can be input into the app instead.
- Input the code that the 6 digit code the app provides and click 'Complete setup'.
- You will now be able to login to Nimbus using your authenticator app.
How to reset
If you need to reset your authenticator because of a new device or a new app:
- Select MFA method to email.
- Save Changes.
- Select MFA method as Authenticator App.
- You will now see the option 'Click to setup'.
- Follow instructions as above.
Note: if you have lost your authenticator app and cannot login to Nimbus, please contact support to reset your account to email. You maybe asked some questions to confirm your identity.