Stratforge One

Security

The Security area is where you set the sign-in protections that apply to everyone in your organization. From a single screen you control multi-factor authentication, choose which verification methods members can use, and connect the identity providers that power single sign-on.

You'll find it under Security in the console. The section opens directly on its Authentication view at /security/authentication, which gathers three groups of settings:

  • Multi-factor authentication (MFA) - whether an extra verification step is required at sign-in.
  • Authentication Methods - the second-factor methods members are allowed to use.
  • Identity providers - the SAML and LDAP connections behind single sign-on.

Security settings apply to your whole organization. Changes take effect for members the next time they sign in.

Multi-factor authentication

MFA adds a second verification step on top of a member's normal sign-in, so a password alone isn't enough to get in.

The Force MFA for all users toggle controls enforcement. When you turn it on, every member is required to complete multi-factor authentication the next time they log in. When it's off, members can sign in without a second factor.

To change it, flip the Force MFA for all users switch. You'll see a confirmation that MFA is now mandatory (or that it has been disabled) for all users.

If you enable Force MFA and no authentication method is turned on yet, the Authenticator App (TOTP) method is enabled automatically so members always have a way to satisfy the requirement.

Authentication methods

Under Authentication Methods you decide which second factors members are allowed to enroll and use for MFA. Each method has its own switch:

  • Authenticator App (TOTP) - members use an app such as Google Authenticator or Microsoft Authenticator to generate a one-time passcode at each sign-in.
  • Email OTP - members receive a one-time passcode by email each time they log in.

Toggle a method on to make it available to members, or off to withdraw it. Enabling or disabling a method takes effect immediately and is confirmed with a short message.

While Force MFA is on, you can't turn off the last remaining method. If only one method is enabled, its switch is locked and a reminder appears: enable another method before disabling this one. This keeps members from being locked out of a required step.

Identity providers

The Identity providers list shows the single sign-on connections set up for your organization. Each row shows the provider's name, its type (SAML or LDAP), when it was last modified, and whether it's Active or Inactive.

From here you can add a new provider or manage an existing one. Setting up, testing, and the effect on member sign-in are covered in detail in Authentication & SSO.

How the pieces fit together

  • Force MFA decides whether a second factor is required.
  • Authentication Methods decide which second factors members can use to satisfy it.
  • Identity providers decide how members can sign in through your own SSO, instead of (or alongside) a Stratforge password.

Members themselves are managed in the Directory, and organization-wide defaults live under Organization.