How to Choose Whether People Need an Authenticator App
The system administrator decides, for the whole company, whether people signing in to ABM Service over the web need an authenticator app: a second step after the password, in which they type the six-digit code shown by an app on their phone. This is often called two-factor authentication. Open the menu and, under Administration, select Sign-in, then choose Off, Optional or Required under Authenticator app.
How do I turn on authenticator apps for everybody?
Open the menu, select Sign-in under Administration, and choose Required under Authenticator app. It is saved the moment you choose it; there is no Save button.
- Open the menu with Menu (or Navigation menu on the Calls, Customers and Scheduler screens).
- Select Sign-in under Administration.
- Choose Off, Optional or Required under Authenticator app.
- Check the line under the choices. It reads Saving… and then Saved. followed by what the choice means now.
While the Sign-in screen opens it shows Reading how this company signs in…, and if the setting cannot be read, the reason is shown in its place. If the choice could not be saved, the reason appears at the top of the Sign-in screen and the choice goes back to what it was, so the screen always shows the rule that is really in force.
The Sign-in screen's subtitle, How people sign in to your company over the web, is a reminder of what this controls: the web sign-in page. The rule is your company's, kept in its database, so it is the same for everybody whichever browser or computer they use. Another ABM company on the same site has a setting of its own, chosen on that company's own Sign-in screen.
What do Off, Optional and Required mean?
The three choices on the ABM Service Sign-in screen decide who is asked for an authenticator code after their password when signing in over the web:
- Off — Nobody is asked for a code. People sign in with their password alone, and nobody's menu shows an Authenticator entry. This is where every site starts.
- Optional — Anybody may set one up from the menu, and is asked for a code only if they did. An Authenticator entry appears beside Sign out in the menu of everybody signed in over the web, and stays there under Required too. People who set one up are asked for a code each time they sign in; they may also turn theirs off again with a current code.
- Required — Everybody must set one up; a person without one is asked to at their next sign-in. After their password, anybody without an authenticator is taken straight to setting one up and cannot reach ABM Service until it is done. Nobody can turn their own off.
Required applies to you too. The next time you sign in over the web as user 1 without an authenticator, you set one up like everybody else.
The choice is one rule for everybody signing in to your company over the web: there is no way to require an authenticator for some people and not for others. The nearest thing is Optional, where only the people who set one up are asked for a code.
The Authenticator app setting is for ABM users only. Your customers signing in to the Customer portal are never asked for an authenticator code, whichever of the three you choose.
A site that wants to ease people in can choose Optional first, tell everybody to set one up from their menu, and change to Required later. There is no grace period built into Required: it takes effect at each person's next sign-in.
Which authenticator app do people need on their phones?
Any authenticator app works with ABM Service: Google Authenticator, Microsoft Authenticator, 1Password or any other app that shows six-digit codes. ABM Service does not supply one, so people use the one they already have or install one from their phone's app store. The ABM Service page for setting one up says so itself: "Scan the square with an authenticator app — Google Authenticator, Microsoft Authenticator, 1Password, any of them."
People set up their authenticator in a browser, on the ABM Service web sign-in pages: after their password when the Authenticator app setting on the Sign-in screen is Required, or from Authenticator in their own menu under Optional.
- Scan the square on the screen with the authenticator app. A phone that cannot scan it can use the key under Or type this key beside the square instead: type it into the app, or use Copy.
- Check the app: it saves the entry under the company's name and the person's name, and shows a six-digit code that changes every thirty seconds.
- Type that code into The code it shows and select Confirm and sign in, or Turn it on when setting up from the menu.
Nothing is kept until that first code is right, so a scan that did not work costs nothing: they simply try again. Somebody who signs in to two ABM companies over the web sets one up in each, and sees two entries in the app.
Does changing the authenticator setting sign anybody out?
No. Changing the authenticator setting on the Sign-in screen signs nobody out, and after choosing Required the screen says so: Saved. Nobody is signed out; the code is met at the next sign-in. So if somebody is still getting in without a code after you chose Required, either they were already signed in over the web, or they use the ABM Service desktop app, which never asks for a code whatever the setting.
People already signed in over the web carry on working. A web sign-in stays signed in until the person selects Sign out, until the server ABM Service runs on is restarted, or until it has not been used for 30 days. So under the new rule, people meet the code or the setting up the next time they actually sign in, for example after signing out, on a new browser, or after a restart.
There is no button on the Sign-in screen to sign one particular person out, and no setting for how long a web sign-in lasts. If you need everybody to meet the new rule today, ask whoever looks after your ABM Service server to restart it. That ends every web sign-in at once, and everybody signs in again under the new rule.
After choosing Optional the line reads Saved. Anybody may now set one up from their menu. When you are signed in over the web, the Authenticator entry appears in your own menu straight away; the desktop app's menu never shows it. Other people see it the next time they open ABM Service in their browser or reload the page they are on.
What happens to people's authenticators if I switch back to Off?
Switching the Sign-in screen back to Off stops ABM Service asking anybody for a code, but keeps the authenticators people have set up. The screen confirms it: Saved. Nobody will be asked for a code. Anything already set up is kept, not deleted.
While the setting is Off, those authenticators are simply not used, and the Authenticator entry disappears from the menu: from yours straight away, and from other people's when they next open or reload ABM Service. If you later choose Optional or Required again, everybody who had set one up is asked for a code from their phone as before, with nothing to scan again.
To clear one person's authenticator for good, for example because they have lost their phone, use Reset beside their name in the People list on the same Sign-in screen.
Does the authenticator setting apply to the ABM Service desktop app?
No. The authenticator setting applies only to signing in over the web, in a browser. The Sign-in screen says so under Authenticator app: It applies to the web only — the desktop application is unchanged. People who open ABM Service with the desktop app sign in as they always have, whatever you choose.
You can still change the setting from inside the desktop app when you are signed in as user 1: the Sign-in screen is under Administration in the desktop app's menu too. The setting is your company's, so it takes effect for the web sign-in whichever of the two you set it from.
Setting up an authenticator, and managing your own, happens on the web sign-in pages, so people do that in a browser.