Google Authenticator App for ctcLink MFA
The following instructions are excerpted from Okta Help Center, URL- https://help.okta.com/en-us/Content/Topics/Security/mfa/google-authenticator.htm#En
Google Authenticator is an app that provides a Time-based One-time Password (TOTP) as a second factor of authentication to users who sign in to environments where multifactor authentication (MFA) is required.
End-user experience
- Go to the Apple App Store or the Google Play Store and install Google Authenticator on your device.
- In the web browser on your computer: When signing in to Okta or accessing an Okta-protected resource, enter your credentials and then click Next.
- On the Setup security authenticators page, click Set up.
- Select your device type, and then click Next.
- Perform the QR code scanning steps that apply to you:
If your device can scan QR codes:
- Don’t click Next in the browser yet; instead, on your mobile device, launch Google Authenticator.
- In Google Authenticator, tap the + sign.
- Tap Scan a QR code and then point your camera at the QR code displayed in the browser on your computer. Your device camera scans the QR code automatically.
- In the web browser on your computer, click Next.
- In the Enter Code field, enter the setup key shown in Google Authenticator on your mobile device.
- Click Verify.
If your device can’t scan QR codes:
- Don’t click Next in the browser yet.
- In the web browser on your computer, click Can’t scan.
- In the field above the Next button, make a note of the string of numbers and letters.
- On your mobile device, launch Google Authenticator.
- Tap the + sign.
- Tap Enter a setup key.
- In the Account field, enter your Okta username.
- In the Key field, enter the string of numbers and letters that you made a note of earlier.
- Tap Add. The message Secret saved appears.
- In the web browser on your computer, click Next.
- In the Enter Code field, enter the setup key shown in Google Authenticator on your mobile device.
- Click Verify.
Important considerations
-
The time on the end user's device might not be the same as the time on the clock in the Google Authenticator app. The Google Authenticator app allows a time difference on the end-user device of up to two minutes earlier or later than the time in the Google Authenticator app.
-
After five unsuccessful authentication attempts, regardless of the time between the attempts, the user account is locked and the admin must reset it.