What is Multi Factor Authentication?
Multi Factor Authentication (MFA) is an authentication strategy where a user must provide more than one type of identifying evidence (factor) in order to gain access to a resource. ATMs used to access bank accounts are a good example: you must insert your ATM card (something you have) and enter your PIN number (something you know) before you can access your account. In computing, MFA most frequently involves having a password (something you know) and a physical key or token (something you have).
Why use MFA?
Multi-factor authentication provides continued protection, even if a password has been compromised. With MFA, an attacker will not be able to impersonate you, even if they know your password, whether from hacking a database, or by phishing attack. Access will be denied because they will not have the physical token in their possession.
Integration of One-Time Passwords with User Credentials
For access to most Lab resources other than privileged server access, Berkeley Lab has implemented an MFA strategy requiring the use of your Berkeley Lab Identity credentials in conjunction with a one-time password (OTP). An OTP can be generated either by a software or hardware solution. Berkeley Lab IT has enabled the ability to use either. Software OTPs are generated using Google Authenticator, whereas hardware OTPs are generated from an authentication device known as a YubiKey. Berkeley Lab IT is the organization that issues the hardware authentication device.
MFA at Berkeley Lab
Berkeley Lab uses MFA for access to:
- Multi Factor Authentication for FMS
- Multi Factor Authentication for HRIS - MFA for HR personnel logging into Berkeley Lab HR databases and accessing Personally Identifiable Information (PII) data
- Multi Factor Authentication for Windows (StrongID) - MFA for Operations personnel logging into Windows Active Directory computers (sometimes known as StrongID)
- Multi Factor Authentication for Single Sign-On (SSO) - MFA for Single Sign-On providing Lab personnel access to Berkeley Lab resources like email, calendar, LETS, etc.
- Login for Oracle Lab Resources - MFA for FMS and some similar Oracle Peoplesoft-based tools
- Lawrencium HPC Cluster - MFA for HPCS Clusters
- Privileged Server Access - MFA for access to critical servers and services via gateways (sometimes known as L4 Gateways, or L4 StrongID)
How do I get started using MFA?
- If you are a member of the Science staff, an affiliate, a student/post-doc, or otherwise not an Operations staff member, you should get started in MFA by following this link.
- If you are a member of the Operations staff, follow this link.
If you have questions regarding MFA enrollment, please submit a help ticket.