Introduction
GEMS Administrators can enable Multi-Factor Authentication (MFA) with SMS or email for their GEMS database if they are not using single sign-on (SSO).
With MFA enabled, users will receive a one-time passcode after entering their username and password on the GEMS login page. The passcode is sent via SMS or email. Only after entering that passcode will the user's login be complete.
Please note: Users in certain countries may not be able to receive passcodes from GEMS via SMS. Contact CES Support at [email protected] to confirm current coverage.
Review MFA settings
When enabling MFA, Administrators must configure several settings. Review the screenshot and the corresponding numbers below to learn more about each setting.
1. Enable SMS MFA and Enable E-mail MFA - Choose how users receive the one-time passcode: SMS or email. If both are enabled, users can select their preferred method at login.
2. Users prompted to enter own phone number (if none present) - If SMS MFA is enabled and a user does not have an MFA Mobile Number on their User Details page, GEMS prompts them to enter a number the first time they log in with MFA.
3. Days between MFA prompt - How long GEMS remembers a successful MFA verification before prompting the user again.
Enable MFA
MFA is enabled by GEMS Administrators in the System Management area of GEMS.
In this scenario, we would like to enable MFA that lets users select whether they receive the passcode through SMS or email. We don't know if all users have a phone number in their MFA Mobile Number field, so we want GEMS to prompt for a phone number in those situations. Finally, we would like GEMS to not ask users to enter an MFA passcode again for 14 days after they last entered one.
1. From the Hub Toolbar, click Admin, then select GEMS Settings> System Management.
2. In the left Menu, select Options> Password and Multi-Factor Authentication.
3. Select EDIT.
4. Locate the Multi-Factor Authentication (MFA) section and tick the first three checkboxes as needed. In this scenario, we will tick Enable SMS MFA, Enable E-mail MFA, and Users prompted to enter own phone number (if none present).
5. In the Days between MFA prompt field, enter your desired number of days. In this scenario, we'll enter 14.
6. Click SAVE.








