Viewable by the world
Group Access to IT Frequently Asked Questions (FAQ)
Can VIEW the space: itfaq-editors ,  anonymous ,  itfaq-MFA-EDITORS ,  itfaq-itss ,  all-lbnl-users ,  mpsg-staff ,  itfaq-editors-lite ,  mpsg-mpsg-helpdesk ,  google-collab-documentation-management , 
Can EDIT the space: itfaq-editors-lite ,  itfaq-editors ,  mpsg-staff ,  google-collab-documentation-management ,  mpsg-mpsg-helpdesk , 
Can ADMINISTER the space:

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Multi-Factor Authentication (MFA) requires you provide more than one factor to authenticate.  Most commonly, MFA requires typing a password (first factor) and entering a one-time code (second factor) generated by a device, such as Google Authenticator on you phoneWith  With MFA, an attacker will not be able to impersonate you, even if they know your password, whether from hacking a database, or by phishing attack. Access will be denied because they will not have the physical token in their possession.

Integration of One-Time Passwords with User Credentials

For access to most Lab resources other than privileged server access, Berkeley Lab has implemented an MFA strategy requiring the use of your Berkeley Lab Identity credentials in conjunction with a one-time password (OTP). An OTP can be generated either by a software or hardware solution. Berkeley Lab IT has enabled the ability to use either.  Software OTPs are generated using Google Authenticator, whereas hardware OTPs are generated from an authentication device known as a YubiKey. Berkeley Lab IT is the organization that issues the hardware authentication device.

MFA at Berkeley Lab

Berkeley Lab uses MFA for access to:

access your account simply by knowing your password.  The attacker must also have the device capable of generating a code, a much more difficult tasks.  

How to use MFA at Berkeley Lab?

Most people already use MFA at Berkeley Lab and/or to secure their personal accounts. 

When using MFA at Berkeley Lab, after entering your username and password you will be prompted for a one-time code, as follows:

Image Added     Image Added


If you are a member of an Operations division, MFA was required to login Berkeley Lab enterprise applications (Gmail, LETS, FMS, etc.) in May 2018

If you are a member of a Scientific division, you can opt-in to use MFA for Berkeley Lab enterprise applications beginning September 2018.

MFA Frequently Asked Questions (FAQ) 

  1. How do I opt-in to MFA?
  2. How can I manage my Google Authenticator MFA tokens?
  3. How do I manage my Yubikey MFA tokens? (Operations Only)
  4. I lost my MFA token and can't login?

Other MFA resources Berkeley Lab

How do I get started using MFA?

  • If you are a member of the Science staff, an affiliate, a student/post-doc, or otherwise not an Operations staff member, you should get started in MFA by following this link.
  • If you are a member of the Operations staff, follow this link.


If you have questions regarding MFA enrollment, please submit a help ticket.



Pop away