Zoho Invoice

Multi Factor Authentication (MFA) for Customer Portal

Multi-Factor Authentication (MFA) is a security process that requires users to provide two or more verification factors to gain access to an account, system, or application. This adds an extra layer of protection beyond just a username and password. This reduces the risk of unauthorized access, even if one factor, like a password, is compromised.

Zoho Invoice allows you to enable Multi-Factor Authentication (MFA) for the Customer Portal to enhance account security and protect them from unauthorized access. Your customers can configure MFA by scanning a QR code using an authenticator app, such as OneAuth or Google Authenticator. After configuration, they can use the Time-based One-Time Password (TOTP) received in their autheticator app and log in to their portal.

Enable MFA in Customer Portal Preferences

To enable MFA in the Customer Portal Preferences page:

MFA will be enabled for customer portal.

How Customers Can Configure MFA

Prerequisite: Download an authenticator app (such as OneAuth or Google Authenticator) from the Google Play Store or the App Store.

Once you enable MFA for the customer portals, your customers can use an authenticator app (such as OneAuth, Google Authenticator) to configure it themselves.

To configure MFA, customers should:

Insight: They can also manually enter the authentication code received in their authenticator app.

Now, your customers can log in to their portal using the TOTP received in their authenticator app.

Reset MFA for Customers

If a customer loses access to their authenticator app and does not have backup codes, you can reset MFA for them. Here’s how:

MFA will be reset for the respective customer, and they will have to configure it again to log in to their portal.

Disable MFA in Customer Portal Preferences

To disable MFA in the Customer Portal Preferences page:

MFA will be disabled in the Customer Portal Preferences page for customer portals.

Note: If a customer has already configured MFA, they must use TOTP to log into their portal, even after MFA is disabled. To disable MFA for these customers, you can consider resetting their portal.

Was this document helpful?
Yes
No
Thank you for your feedback!