about phone based one-time password - … · web viewone time password credentials are often used...

16
Phone One-Time Password Level 2 (without Proofing) User Guide October 2017 1 Copyright ©2017 Exostar LLC. All rights reserved

Upload: others

Post on 30-Aug-2020

6 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

Phone One-Time PasswordLevel 2 (without Proofing)

User GuideOctober 2017

1Copyright ©2017 Exostar LLC. All rights reserved

Page 2: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

ContentsAbout Phone Based One-Time Password...................................................................3OTP Acquisition and Activation Process Overview.....................................................3Step 1: Determine Your Need for an OPT Credential.................................................3Step 2: Purchase Your OTP Credential......................................................................4Step 3: Register the Credential.................................................................................9Step 4: Activate Your Phone....................................................................................11Log into MAG with Phone OTP.................................................................................13

2Copyright ©2017 Exostar LLC. All rights reserved

Page 3: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

About Phone Based One-Time Password Exostar features One-Time Password (OTP) credentialing technology which provides users with a physical credential which allows them to access an application using 2-factor authentication (2FA). Using an OTP credential along with your username/password (2-factor authentication) mitigates security risks by providing a stronger assurance level and better identity protections than conventional username/password technologies that are vulnerable to theft.

There are two types of OTP credentials available which can be used to access applications behind Exostar’s Managed Access Gateway (MAG):

One-Time Password Hardware Token (OTP Hardware) Phone Based One-Time Password (Phone OTP)

This guide provides information on the Phone Based One-Time Password credential. Phone Based One-Time Password (Phone OTP) allows you to register your mobile telephone or LAN line telephone in order to receive a one-time password credential (numeric code) via text or voice. The Phone Based OTP credential is used in combination with your MAG user ID and password, and is required each time you log in to Exostar’s Managed Access Gateway (MAG) to access applications that require the credential. Using this 2-factor authentication (Phone OTP + username and password) reduces the risk of unauthorized access to your account, and provides added security.

For more information about Phone OTP, including OTP FAQs, go to www.myexostar.com.

OTP Acquisition and Activation Process Overview There are several steps in the process of acquiring and activating your Phone Based OTP credential. Each step is covered in detail in this guide.

Step 1: Determine your need for an OTP Credential• You are attempting to access an application that requires two-factor authentication, and• You do not already have an equivalent security credential

Step 2: Purchase the OTP License Key• Purchase the credential via the MAG Portal• You can complete a purchase using a credit card or invoice

Step 3: Register the License Key• Go to the MAG portal, then Manage OTP tab to register your license key (received in

email)• You must enter your name and country

Step 4: Activate Your Phone

3Copyright ©2017 Exostar LLC. All rights reserved

Page 4: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

Step 1: Determine Your Need for an OPT CredentialOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if you are attempting to access an application that requires 2FA, you need a security credential. If you already have a security credential, you may not need Phone-Based OTP if the following applies:

If you already have an acceptable 2FA credential used to access another application, you can use that to meet the requirements to access multiple applications. You do not need to proceed with purchasing and installing additional credentials.

If you have another account with a credential used with another application, you can leverage that by connecting your accounts. Visit myexostar.com to learn more about account connections.

If you are unsure of the credential requirement for an application you are accessing, please contact Exostar Tier I Support .

Step 2: Purchase Your OTP Credential Before completing an OTP credential purchase, please ensure you have access to the application that requires the OTP credential. If you are an existing MAG account holder, you can purchase your OTP credential from within the MAG portal. If you do not have a MAG account, and are certain you require an OTP credential, please visit the Exostar Webstore. You need to log into your Exos t ar Ma n ag e d A cc ess Ga t eway (MAG) ac c o u nt with your username and password.

To purchase a Phone Based OTP credential:1. Go to https://portal.exostar.com and log in to your Exostar Managed Access Gateway

(MAG) account.

4Copyright ©2017 Exostar LLC. All rights reserved

Page 5: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

2. Go to the My Account tab and select the Manage OTP link.

2. Prior to purchasing and activating the credential, you can test your phone to verify your mobile telephone or LAN-line telephone is able to receive messages.

Click Test Phone.

Enter your phone number and select Send Test Message.

Note: Shared phone numbers or devices are NOT permitted.

5Copyright ©2017 Exostar LLC. All rights reserved

Page 6: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

3. Once you have successfully tested your phone, proceed to purchase the credential. Select Purchase Phone OTP.

4. The Exostar E-Commerce Portal page is displayed. From the dropdown list, select the partner whose application requires use of the Phone Based OTP credential.

5. Locate the desired product and click Add to Cart.

6Copyright ©2017 Exostar LLC. All rights reserved

Page 7: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

6. The item is placed in your shopping cart. Review your cart contents, and click Proceed to Checkout.

7. On the Payment Information page, you have the option to pay by credit card or invoice. Enter your payment information. Click Continue.

Note: If you select the invoice option, Exostar must receive and process your payment before you receive the license key to complete the activation of your credential. Additionally, if you have a Reference or PO Number for your invoice, you must submit it to [email protected].

7Copyright ©2017 Exostar LLC. All rights reserved

Page 8: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

8. Review your order and the disclaimer. Before submitting your order, check the box next to I have read and acknowledged the following Disclaimer. Click Submit Order.

9. An order confirmation page is displayed. Please note the Sales Order Confirmation Number included in the confirmation..

Upon completion of the purchase, you will receive an email notification. If you paid with a credit card, you will receive a second email with the activation information for your license key. The license key activation initiates the process for you activating your telephone.

IMPORTANT: Once you activate the license key, you cannot use it again.

8Copyright ©2017 Exostar LLC. All rights reserved

Page 9: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

Step 3: Register the Credential Once you receive your licensing key, proceed through the steps below to register your OTP Phone credential.

1. Log into your Exostar Managed Access Gateway (MAG) account with your username and password.

3. Select the My Account tab and then the Manage OTP sub-tab.

4. Before entering your license key, click the What is required of me link to review the information.

Select ‘I understand what is required of me’ when you are ready to proceed.

5. Enter the license key you received via email in the License Key field and click Register.

9Copyright ©2017 Exostar LLC. All rights reserved

Page 10: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

6. Confirm your legal first and last name, and select your country. After completing these actions, click Next.

10Copyright ©2017 Exostar LLC. All rights reserved

Page 11: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

Step 4: Activate Your Phone You now need to register your mobile telephone or land-line telephone. Please note once you register your initial telephone, you can register additional phones.

1. Working in the MAG portal, select the delivery method you want to receive the OTP code on, and complete the required fields.

2. Once you complete all fields, click Send Code.

Note: The code may take a few minutes to receive. Please note once you receive the code, the code expires after two minutes. You can resend the code by selecting Resend Code.

3. Enter the verification code you received through your registered delivery method. Click Submit.

11Copyright ©2017 Exostar LLC. All rights reserved

Page 12: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

4. A message confirming successful registration is displayed. You have the ability to add an additional phone.

To complete the activation, click Complete.

5. You will receive a message confirming you have successfully registered your phone. You have the ability to add an additional phone.

Log into MAG with Phone OTP You must activate the Phone OTP credential before you can use it. To log in using your Phone OTP credential:

1. Go to www.portal.exostar.com and enter your username and password. Click Login.

12Copyright ©2017 Exostar LLC. All rights reserved

Page 13: About Phone Based One-Time Password - … · Web viewOne Time Password credentials are often used to access applications that require two-factor authentication (2FA). Therefore, if

2. Select the phone you want to receive the OTP code. Click Send to have the code sent to your phone.

3. You will receive the OTP code on your telephone. Enter the code in the OTP Code field. Click Submit.

Note: Once you receive the code, the code expires after two minutes. You can resend the code by selecting Resend Code.

You are now logged in with your Phone OTP credential. You can confirm you have successfully logged in with Phone OTP by verifying the credential strength in the upper, right hand corner. It should say Phone OTP.

13Copyright ©2017 Exostar LLC. All rights reserved