Multi-factor authentication (MFA)
Requiring your cemetery's users to use MFA
What is MFA?
Multi-factor authentication (MFA), also referred to as two-factor authentication (2FA), is a type of security measure in which a user is granted access to a website only after successfully presenting two or more distinct types of evidence (or factors) to an authentication mechanism. Using two factors to identify users greatly decreases the likeliness of an unauthorized login. In addition to asking users to login using their email and password (the first factor), CIMS asks users for a code from an authenticator app (the second factor) if MFA is enabled.
MFA in CIMS
MFA in CIMS is optional. Your organization may want to implement MFA as an additional security measure, controlling who can access your cemetery’s data. MFA can be enabled either on an individual (account) level or on the cemetery level (requiring all users of a particular cemetery to use MFA). CIMS allows users the ability for their devices to be “remembered” for 30 days at a time, decreasing the frequency MFA is needed to login. A mobile device is necessary both to set up the MFA app and to login to CIMS once MFA is enabled.
Enabling MFA
To enable MFA for your account, follow these steps:
- Login to CIMS as normal.
- Click on the user menu (usually your name) in the top navigation bar. From the dropdown menu that appears, click “User Settings”.
- A popup will open. Click “Two-Factor Auth”.
- Download an authentication app if needed to your mobile device. Links are provided on the two-factor auth setup page if needed, or your organization may have a preference.
- Use the application to scan the QR code. A CIMS account will be set up in your authenticator app and provide 6-digit verification codes. Please note that codes are only valid for a limited time, usually 30 seconds. If you see the code is red, or time is limited, just wait until the counter is reset and use the new 6-digit code that appears.
- Enter in the verification code from your authenticator app onto the CIMS two-factor authentication setup page.
- Click the “Enable 2FA” button.
After you have completed these initial setup steps, do the following:
- Copy or download the 8 one-time use codes that can be used to login should your authentication app not be available. Save these codes in a safe place.
- These one-time codes will NOT appear again! This is the only time you will be able to see, copy, or download them.
- If you need new codes or run out of one-time codes, you can regenerate new ones in the Two-factor Auth page. Doing so erases your unused previously generated codes.
Click “Return to CIMS” to return to CIMS. On your next login, you will be asked to enter a verification code after entering your username and password. Use the same authenticator app you used during the setup to find your verification code for CIMS.
Trusting devices to decrease MFA frequency
If your device is secure, meaning it's your personal or organization's own device and you think the risk of another person trying to login to CIMS using it is low, you can choose to trust the device. You will then not be asked for MFA for 30 days.
To trust a device, login to CIMS using your name and password. On the next screen, asking for your MFA authentication code, click the check box labeled “Trust this device”, then click "Verify".
Requiring your cemetery's users to use MFA
Your organization may want to require all of its users to use MFA when logging in. You will need to have an administrative account in CIMS to do the following:
- Click on your cemetery’s name in the upper-left corner of CIMS and click “Cemetery settings” from the dropdown.
- The cemetery settings popup will open. In the first tab, “Basic”, click the “Require MFA for login” check box, then “Update cemetery settings”.
- All accounts that do not have MFA setup will be automatically redirected to the two-factor auth setup page on their next login.
Troubleshooting
If a user loses their CIMS authentication account/app/device and their one-time use login codes, please contact our team and a tech support specialist will be able to assist by resetting their MFA setup.
If you lose access to your authenticator app, you have two options: If your cemetery has multiple licenses and another is an account administrator, they can turn off your MFA. You can also contact CIMS tech support for help.