Start of changeChanging multi-factor authentication policy (MFA)End of change

Start of changeThis policy specifies if an additional sign-on factor (MFA) is enabled for the sign-on process for service tools. If this is enabled the sign-on screen will display the "Additional factor" field. The individual user profile attributes can later be configured to require an additional factor for the user profile sign-on process. You can change the additional sign-on factor enabled using system service tools (SST), dedicated service tools (DST), or the Change SST Security Attributes (CHGSSTSECA) command. End of change

Start of change
Notes:

This security policy is independent of the "TOTP enabled" user profile attribute and configuring it "no" (disabled) will not clear or change the service tools user profile TOTP authentication attributes. User profiles can create a TOTP key and have the TOTP enabled attribute on/enabled regardless of this policy being "no" (disabled).

When this policy is configured "no" (disabled), the service tools user profiles will only authenticate with a user ID and password during the sign-on process and the TOTP additional factor is not required.

To change the Additional sign-on factor policy using SST:
  1. Access SST.
  2. Select option 8 (Work with Service Tools Server Security and Devices).
  3. Select option 5 (Work with service tools security options).
  4. Change the (Additional sign-on factor enabled) field and press Enter.
To change the Additional sign-on factor policy using DST:
  1. Access DST.
  2. Select option 5 (Work with DST environment).
  3. Select option 4 (Service tools security data).
  4. Select option 7 (Work with service tools security options).
  5. Change the (Additional sign-on factor enabled) field and press Enter.
To change the Additional sign-on factor policy using the CHGSSTSECA command:
  1. Specify the Additional sign-on factor (ADLSGNFAC) parameter on the Change SST Security Attributes (CHGSSTSECA) command.
  2. The Display SST Security Attributes (DSPSSTSECA) command can be used to display the current value of the Additional sign-on factor and other security attributes.
End of change