Overview

Multi‑Factor Authentication (MFA) adds an extra layer of security to clinic accounts by requiring both a password and a one‑time verification code (OTP). This article explains how to configure MFA at the clinic level and for individual user profiles.


Prerequisites

  • Admin access is required to configure MFA settings.

  • Ensure you have a valid mobile number to receive SMS OTP codes.



Activating Multi-Factor Authentication (MFA)

  1. Navigate to Settings > Clinic Settings > Multi‑Factor Authentication. This is the master setting; it will overwrite any individual user account settings.

  2. Make the required changes.

  3. Click Save Settings.


Setting Up MFA for User Profiles

  1. Log in with admin permissions.

  2. Go to User Management.

  3. Locate the SMS OTP (Multi‑Factor Authentication) column.

  4. Click the Pen icon under the Actions column.

  5. You will see options to create a new password and enable SMS OTP.

  6. Enter the mobile number to receive OTP SMS and click Save.

  7. A confirmation message will appear at the top‑right corner.

  8. Click Send Verification Code.

  9. A confirmation message (“Verification code sent”) will appear at the top‑right corner.

  10. Enter the OTP received via SMS and click Confirm.

  11. Once completed, the phone number will be verified.

  12. Enable SMS OTP for the user profile.

  13. The profile status will update to On.

  14. From now on, when logging in from a different system or network, the user will be prompted to validate via OTP. Note: OTP validation is required every 90 days.