--- title: "Multi-Factor Authentication" slug: "multifactor-authentication" updated: 2023-11-07T15:23:27Z published: 2023-11-07T15:23:27Z canonical: "wiki.cobblestonesoftware.com/multifactor-authentication" --- > ## Documentation Index > Fetch the complete documentation index at: https://wiki.cobblestonesoftware.com/llms.txt > Use this file to discover all available pages before exploring further. # Multi-Factor Authentication ### **Multi-Factor Authentication (MFA)** **Multi-Factor Authentication (MFA)** The MFA Settings and MFA Questions pages allow for the configuration of Multi-Factor Authentication. MFA requires a user to provide additional authentication information, such as a code sent to their email and/or verification questions, to validate their login. **Note:** Multi-Factor Authentication within Contract Insight is only implemented for those using the standard login method. Users with SSO login would need to contact their authentication service for MFA. 1. Multi-Factor Authentication can be found under the **Config Settings**. **![The Application Configuration Section of the Contract Insight Main Menu. Config Settings is highlighted.](https://cdn.document360.io/e3626857-1fb5-4e27-b278-2d3fc5508be4/Images/Documentation/1(237).png)** 2. Once on the **Config Settings** page, MFA can be found in the menu on the left side of the page. **![The Data Management side menu of the Application Configuration page. MFA Settings and MFA Employee Questions is highlighted.](https://cdn.document360.io/e3626857-1fb5-4e27-b278-2d3fc5508be4/Images/Documentation/2(185).png)** **Multifactor Authentication: Settings** **Multifactor Authentication Enabled** - This sets whether Multifactor Authentication is enabled (True) or disabled (False) **Multifactor Authentication Style** - This setting determines how Multifactor Authentication validates the initial login. The options are: Email Code, SMS Code, SMS or Email, Email or SMS, Challenge Question. **Note:** Sending a code via SMS requires SMS Messaging to be set up. See the [SMS Messaging](https://wiki.cobblestonesoftware.com/docs/configuration-group-sms-messaging) wiki page for information. **Multifactor Code Style** - Defines what type of characters to use when creating the challenge code. The options are: Caps Only, Alpha Only, Numeric Only, Unambiguous. **Multifactor Code Length** - This setting is for how long challenge codes should be. The default is 5 characters. **Employee question pool size** - This is the pool of questions the system chooses from for authorization. **Number of MFA questions** - The number of questions a user must correctly answer before access is permitted. **Email Message** - The email that is sent out containing the verification code. Use ###VERIFICATION_CODE### as a place holder for the verification code. ![Multifactor Authentication Page](https://cdn.document360.io/e3626857-1fb5-4e27-b278-2d3fc5508be4/Images/Documentation/3(138).png) **Multifactor Authentication: Questions** The list of available challenge questions set up by the System Admin are found at the bottom of the **MFA Settings** page. Existing questions can be managed using the icons in the **Options** column. From left to right they are: Edit, Enable/Disable, and Delete. ![Multifactor Authentication Questions List](https://cdn.document360.io/e3626857-1fb5-4e27-b278-2d3fc5508be4/Images/Documentation/34.png) To add a new question, click **Add Question** at the bottom of the questions list. Type your question into the pop-up **Add Question** screen and click **Save** to add the new question to the list. ![Add Questions Pop-Up](https://cdn.document360.io/e3626857-1fb5-4e27-b278-2d3fc5508be4/Images/Documentation/multifactor-authentication-image-zzd5kdwj.png) **Set MFA Employee Questions** 1. Click the **MFA Employee Questions** link in the side menu. 2. In the next window, **select the user** from the drop down list and click **Load Questions**. ![MFA Employee Questions pop-up with user dropdown](https://cdn.document360.io/e3626857-1fb5-4e27-b278-2d3fc5508be4/Images/Documentation/35.png) 3. The list of available questions will populate. Check the box in the **Selected** column to choose the questions for the employee, then enter their answers and click the **Save** button. Note that the minimum number of questions needed is the number in the **Employee question pool size** setting on the **MFA Settings** page. ![The Employee and a list of questions that can be assigned.](https://cdn.document360.io/e3626857-1fb5-4e27-b278-2d3fc5508be4/Images/Documentation/36.png) 4. The next time the user logs in to Contract Insight they will be prompted to validate their login. ![The Validation Message on Contract Insight Login](https://cdn.document360.io/e3626857-1fb5-4e27-b278-2d3fc5508be4/Images/Documentation/multifactor-authentication-image-yoicdlv6.png) 5. Once validated, and if they are set up, the user will be presented with any question(s) needed to authenticate their login. ![The MFA question shown at login](https://cdn.document360.io/e3626857-1fb5-4e27-b278-2d3fc5508be4/Images/Documentation/multifactor-authentication-image-jugruvqq.png)