From eScan Wiki
Revision as of 13:51, 18 March 2020
||· eScan · MailScan · Technologies||· Technical Info · Security Awareness · User Guides|
eScan Version 14 (and above) Online Help
<para> <body> I Bhushan Chavan hereby declare that I will not give any documents to Amar Itagi </para> </body>
eScan Two-Factor Authentication (2FA)
Your default system authentication (login/password) is Single-Factor Authentication which is considered insecure as it may put your organization’s data at high risk of compromise. The Two-Factor Authentication, also more commonly known as 2FA, adds an extra layer of protection to your basic system logon. The 2FA feature requires personnel to enter an additional passcode after entering the system login password. So, even if an unauthorized person knows your system credentials, the 2FA feature secures a system against unauthorized logons.
With the 2FA feature enabled, the system will be protected with basic system login and eScan 2FA. After entering the system credentials, eScan Authentication screen will appear. The personnel will have to enter the 2FA passcode to access the system. A maximum of three attempts are allowed to enter the correct passcode. If the 2FA login fails, the personnel will have to wait for 30 seconds to log in again.
To enable the Two-Factor Authentication feature, follow the steps given below:
- In the eScan web console, go to Managed Computers.
- Click Policy Templates > New Template.
You can enable the 2FA feature for existing Policy Templates by selecting a Policy Template and clicking Properties. Then, follow the steps given below:
- Select Administrator Password check box and then click Edit.
- Click Two-Factor Authentication tab.
- Select the check box Enable Two-Factor Authentication. The Two-Factor Authentication feature gets enabled.
The 2FA feature can be used for following all login scenarios:
RDP stands for Remote Desktop Protocol. Whenever someone takes remote connection of a client’s system, the personnel will have to enter system login credentials and 2FA passcode to access the system.
After a system is booted in Safe Mode, the personnel will have to enter system login credentials and 2FA passcode to access the system.
Whenever a system is powered on or restarted, the personnel will have to enter system login credentials and 2FA passcode to access the system.
Whenever a system is unlocked, the personnel will have to enter login credentials and 2FA passcode to access the system.
If the policy is applied to a group, the 2FA passcode will be same for all group members. The 2FA passcode can also be set for specific computer(s).
You can use following all password types to log in:
Use eScan Administrator Password
You can use the existing eScan Administrator password for 2FA login. This password can be set in eScan Password tab besides the Two-Factor Authentication tab.
Use Other Password
You can set a new password which can be combination of uppercase, lowercase, numbers, and special characters.
Use Online Two-Factor Authentication
To use this feature, follow the steps given below:
- Install the Authenticator app from Play Store for Android devices or App Store for iOS devices.
- Open the Authenticator app and tap Scan a barcode.
- Select the check box Use Online Two-Factor Authentication.
- Go to Managed Computers and below the top right corner, click QR code for 2FA. A QR code appears.
- Scan the onscreen QR code via the Authenticator app. A Time-based One-Time Password (TOTP) appears on smart device.
- Forward this TOTP to personnel for login.
After selecting the appropriate Login Scenarios and Password Types, click OK. The Policy Template gets saved/updated.