Configuring multifactor authentication
Protect your IBM® Storage Defender® user account from security vulnerabilities by configuring multifactor authentication.
About this task
Multifactor authentication (MFA) provides an extra layer of account protection by requiring all users to verify their identity by using more than one authentication method. When you log in to IBM Storage Defender for the first time, you must configure MFA by setting up at least one additional verification method in addition to your IBMid. Every time you log in to IBM Storage Defender, you are required to authenticate by using two different verification methods.
- The MFA prompt frequency cannot be modified or scheduled.
- All user accounts are required to log in by using MFA for every session.
- When your user authentication token expires (every 60 minutes), you will be prompted to reauthenticate.
- After you access the MFA settings page, you might be prompted to reauthenticate.
- Your IBM Storage Defender user account is associated with your IBMid, but profile settings for your IBMid user account and your IBM Storage Defender user account are maintained and controlled separately. In your IBMid profile, you can optionally configure additional MFA verification methods that are specific for your IBMid user account, but those IBMid MFA verification methods are not used to authenticate your IBM Storage Defender user account.
- MFA verification methods for your IBMid and for your IBM Storage Defender user account are controlled separately.
- (Optional) To configure MFA for your IBMid, go to your IBMid profile and click the Profile tab.
- (Required) To configure MFA for IBM Storage Defender, follow the procedure on this page.
- If MFA is configured for both your IBMid account and your IBM Storage Defender account, MFA requirements for both accounts are enforced separately and you might be prompted to authenticate by using MFA for both accounts every time you are prompted to reauthenticate.
- MFA verification methods for your IBMid and for your IBM Storage Defender user account are controlled separately.
In releases later than 2.1.5, users who sign in with an IBMid must complete a one-time Multi-Factor Authentication (MFA) reconfiguration during their first login. The system guides users through the MFA setup process during sign-in. With this update, MFA is managed exclusively through IBMid, which removes duplicate prompts and simplifies the sign-in experience. Users who authenticate through other methods are not affected.
Procedure
- Go to https://storage-defender.ibm.com.
- On the Welcome page, click Log in.
- On the IBM Security Verify page, sign in by using your IBMid and an alternative verification method that you already configured. Two-step verification is required.
-
On the Data Resiliency Service home page, click the User Profile
icon from the menu bar and select Profile from drop-down list. The Profile page is displayed.
-
To configure your MFA verification methods, click the MFA settings tile. The IBM Security Verify page opens in a new browser window.