How can we help? How can we help?

Understand Multi-Factor Authentication

MRI Box and Dice MRI Box and Dice

Summary

Learn how MFA and Okta improve security and streamline authentication across MRI CRMs, including setup steps and troubleshooting tips.

This article covers:


About MFA and Okta

Multi-Factor Authentication (MFA) adds an extra layer of security to your accounts. Okta acts as an Identity Provider (IdP) to centralise authentication and enable Single Sign-On (SSO) across MRI platforms.


Why MFA

MFA requires two or more verification factors, making it harder for attackers to access your account even if your password is compromised.

  • Enhanced Security - MFA provides an additional barrier beyond just using a username and password to access an account. It requires users to provide at least two pieces of evidence to verify their identity, such as something they know (password), or something they have (mobile device)

  • Protection Against Password Attacks - Many security breaches occur due to weak or compromised passwords. Attackers can use techniques like phishing, brute force attacks, or password reuse to gain access to user accounts. MFA adds an extra layer of protection by requiring a second factor, which makes it much more difficult for attackers to gain access, even if they have obtained a user's password

  • Safeguarding Against Stolen Credentials - MFA helps protect against stolen or leaked passwords. If a user's password is compromised in a data breach or through other means, MFA acts as an additional safeguard.


Why Okta

Okta provides centralised identity management and SSO for MRI products, offering:

  • Modern, secure authentication
  • Unified access across multiple CRMs
  • Integration with other MRI platforms
Note: If your company uses Microsoft SSO, Okta is still required for MRI products that do not support Microsoft SSO.

Manage MFA and Okta

To set up or update MFA and Okta:

  • Click  Edit Profile
  • Scroll to Extra Verification
  • Enable additional methods (e.g., Okta Verify, Google Authenticator, SMS)

When logging in to your B+D Okta, you will now be presented with multiple options on how you wish to receive the authentication.

  • Select your preferred authentication
  • Tick Do not challenge me on this device again
Tip: Selecting “Do not challenge me on this device again” will mark the device as trusted.

Supported MFA Methods

You cannot opt out of MFA, but you can change your authenticator.

Supported MFA methods:

  • Okta Verify
  • Google Authenticator
  • SMS Authentication
  • Voice Call Authentication
  • Email Authentication
  • Security Key or Biometric
  • Duo Security
  • On-Prem MFA

Common warning message

If you see a warning about mismatched usernames or emails:

You need to update your name in Box + Dice to match the other CRM (e.g., Property Tree or Vault).


What's next?

Set up multifactor authentication through Okta and Manage your MFA login settings