{"id":1630,"date":"2019-12-03T14:43:11","date_gmt":"2019-12-03T14:43:11","guid":{"rendered":"https:\/\/www.harepoint.com\/Blog\/?p=1630"},"modified":"2020-07-13T15:19:36","modified_gmt":"2020-07-13T15:19:36","slug":"two-factor-authentication","status":"publish","type":"post","link":"https:\/\/www.harepoint.com\/Blog\/two-factor-authentication\/","title":{"rendered":"Two-Factor Authentication in SharePoint: Basic information"},"content":{"rendered":"\n<p>You all at some point have seen a prompt recommending activation of <b>Two-factor authentication (2FA)<\/b> in various email services, messengers or e-shops. Most of the people ignore that prompt, but after seeing it time after time on different websites, apps or services they start to wonder: <i>\u201cDo I really need it? How does it work? How will it help me? Will it make my account safer? Is it easy to use? Are there downsides of using 2FA?\u201d<\/i>. Let\u2019s try to figure it out.<\/p>\n<h2>\u201cDo I really need it?\u201d<\/h2>\n<p>According to the Revised Directive on Payment Services (PSD2) of the European Parliament, starting September 2019 you cannot perform any financial activity without 2FA. That means that some of the choices will be made for you. It also means that even the European Parliament thinks that 2FA is more secure than your classic login\/password duo.<\/p>\n<h2>\u201cHow does it work?\u201d<\/h2>\n<p>2FA adds another layer of authentication to your classic login\/password. It\u2019s been around for quite some time now. Long-time ago, when mobile phones had buttons and the first definition of PDA abbreviation in search engines was \u201cpersonal digital assistant\u201d, banks used to give their corporate users sheets of paper or cards with request\/response codes printed on them. Later, they\u2019ve replaced them with a little device that looked like a calculator that would generate response codes. Now the second authenticators are usually SMS or Push messages that services send to your smartphone. The other popular 2FA method is using a special apps that generate response codes such as \u201cgoogle-authenticator\u201d. For even higher security level, special USB key sticks with your digital signature hardcoded are used, preventing the service from activation without proper dongle presented in your computer\u2019s USB port. There are also less convenient ways for 2FA such as sending an e-mail with the access code to your registered mailbox or a phone call, but, fortunately, those methods are usually used when the system suspects a security breach.<\/p>\n<h2>\u201cHow will it help me? Will it make my account safer?\u201d<\/h2>\n<p>The short answer is \u201cYes\u201d, it will definitely make it much harder for third parties to access your private data, even if they somehow (trojans, key grabbers, a simple look over your shoulder) got access to your login\/password.<\/p>\n<h2>\u201cIs it easy to use? Are there downsides of using 2FA?\u201d<\/h2>\n<p>It is very easy to use. You don\u2019t need any special knowledge or training to activate and start using 2FA. Downsides? &#8211; Yes. It can get very annoying. Picture the situation: you\u2019re sitting at your desk in your bedroom working on your home PC while your smartphone is charging in the kitchen. At some point you need to send an Email. You start your favorite browser and open Gmail. You enter your Login\/Password (I hope you don\u2019t have them remembered in your web browser) and get a standard Google 2FA prompt asking you to press YES on your smartphone screen. I believe you\u2019re a stone-cold, very relaxed and calm person with nerves of steel. You don\u2019t yell at your screen, don\u2019t break anything around you. You calmly get up, go to the kitchen and press YES on your smartphone screen just to come back and see that you didn\u2019t do it in time and you have to go back, enter your login\/password again to get a new message asking you to press YES. Hope you\u2019ve brought your smartphone with you this time.<\/p>\n<p>Anyway, 2FA is a good thing, but you\u2019re the only one responsible for your privacy. Lock your phone, don\u2019t use simple passwords, don\u2019t write your passwords on a post-it and stick it on your screen, don\u2019t tell your passwords or PIN codes to anyone over the phone. Don\u2019t send your access information by email, messengers or SMS. Be careful and 2FA will make your data safer. To realize 2FA in SharePoint environment, we offer reliable and secure <a href=\"\/Products\/SharePoint-Multi-Factor-Authentication\/Default.aspx\">HarePoint Multi-Factor Authentication<\/a> solution.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>You all at some point have seen a prompt recommending activation of Two-factor authentication (2FA) in various e-mail services, messengers or e-shops. Most of the people ignore that prompt, but after seeing it time after time on different websites, apps or services they start to wonder: \u201cDo I really need it? How does it work? How will it help me? Will it make my account safer? Is it easy to use? Are there downsides of using 2FA?\u201d. Let\u2019s try to figure it out.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[35],"tags":[32,33,34],"_links":{"self":[{"href":"https:\/\/www.harepoint.com\/Blog\/wp-json\/wp\/v2\/posts\/1630"}],"collection":[{"href":"https:\/\/www.harepoint.com\/Blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.harepoint.com\/Blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.harepoint.com\/Blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.harepoint.com\/Blog\/wp-json\/wp\/v2\/comments?post=1630"}],"version-history":[{"count":11,"href":"https:\/\/www.harepoint.com\/Blog\/wp-json\/wp\/v2\/posts\/1630\/revisions"}],"predecessor-version":[{"id":1643,"href":"https:\/\/www.harepoint.com\/Blog\/wp-json\/wp\/v2\/posts\/1630\/revisions\/1643"}],"wp:attachment":[{"href":"https:\/\/www.harepoint.com\/Blog\/wp-json\/wp\/v2\/media?parent=1630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.harepoint.com\/Blog\/wp-json\/wp\/v2\/categories?post=1630"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.harepoint.com\/Blog\/wp-json\/wp\/v2\/tags?post=1630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}