InstaSafe Authenticator - Adding a QR Profile

InstaSafe Authenticator - Adding a QR Profile

This article provides a step-by-step guide on adding a user profile on the InstaSafe Authenticator app by QR code.

An organization may choose to increase their security posture with InstaSafe Secure Access’s (ISA) built-in Two Factor Authentication (TFA) that will prompt users for an OTP delivered to the registered email address and mobile number. 

Further, ISA supports various authenticator apps to provide Time-based OTPs (TOTP) for Two-Factor Authentication. This would effectively eliminate the dependency on mobile networks for SMS OTPs and avoid deadlock scenarios where users can access corporate email for email OTPs only after the ISA User Agent is connected.

InstaSafe Authenticator supports TOTP-based authentication. The Authenticator supports iOS and Android devices. The Authenticator supports adding a user profile by entering the username and password or by scanning the QR code of the user from the user’s profile page on the ISA web portal. 

Opening the QR code on the ISA web portal 

  1. Open a web browser and open the ISA web console login page. 

  2. Enter the username and password of the user.

  1. Click Sign In.

  1. When the user is prompted to select a method to receive the OTP, select OTP via SMS or OTP via Email.

  1. Enter the OTP obtained in your email or via SMS.

  1. Select Verify OTP

  1. Once logged in, click the user profile on the top right side of the screen.

  1. Select QR Code. The QR code option is listed only if Two-Factor Authentication is enabled for the user.

  1. The QR code is displayed. 

  1. On your mobile device, open the InstaSafe Authenticator app. For more information on installing and configuring InstaSafe Authenticator, refer to the KB article, Installing and configuring the ISA Authenticator app

  2. Select Login with mPin or use biometric authentication. 

  1. Enter the pin.

  1. Select Verify.

  1. At the bottom right, select the plus (+) icon.

  1. Select Add Profile.

  1. Select QR Code

  1. Allow camera access.

  1. Scan the QR code displayed on the web portal. 

  1. Once the QR code is verified, the user is added to the app. The TOTP for the user is displayed. 

A new TOTP pin is generated every 30 seconds. Use the pin for secondary authentication when accessing the ISA web console or connecting the ISA User Agent.

  1. Back on the QR code window of the ISA web portal, enter the TOTP in the field under the QR code.
  1. Click Submit.

  1. Once the OTP is verified, a message that the OTP is verified successfully is displayed at the bottom-left of the screen.

  1. The QR code is now attached to the authenticator app and is not available for scanning by other authenticator apps. However, manually adding the user to an authenticator app using the username and password is still possible. To verify, click the QR code option again.

To re-enable the QR code, contact the administrator of the ISA web portal.

Testing
  1. Open a web browser and go to the ISA web console login page. Enter the username and password of the user and sign in.

  1. When the user is prompted to select a method to receive the OTP, select TOTP on Authenticator

Do not select Approve Push Notification on Authenticator, it’s supported only on InstaSafe Authenticator.

  1. On the InstaSafe Authenticator, copy the OTP generated.

  1. On the OTP prompt window, enter the OTP generated on the InstaSafe Authenticator app.

  1. Select Verify OTP.

  1. The user is successfully logged into the ISA web console.


Re-enable QR code

When a QR code is attached to the authenticator app of a user, it becomes disabled and inaccessible for scanning by other authenticator apps. While this safeguards the user's QR code from unauthorized access, it can pose a challenge if the user's mobile device is lost or breaks down. In such situations, the user may need to install the authenticator app on a new device but won't be able to scan the disabled QR code. In these cases, the ISA web portal administrator can re-enable and generate a new QR code. The following section provides instructions on re-enabling the QR code.

  1. Login to the ISA web portal using administrator credentials.
  1. Navigate to the USERS & GROUPS > Users page.
  1. Click the name of the user you want to re-enable QR code for.
  1. On the user’s window, click Re-enable QR.
  1. On the pop-window to confirm, click Yes, Enable QR!


Testing
  1. Enter the username and password of the user.

  1. Click Sign In.

  1. When the user is prompted to select a method to receive the OTP, select OTP via SMS or OTP via Email.

  1. Enter the OTP obtained in your email or via SMS.

  1. Select Verify OTP.

  1. Once logged in, click the user profile on the top right side of the screen.

  1. Select QR Code.

  1. The new QR code is displayed.

Conclusion

InstaSafe Authenticator enhances secondary authentication by way of Time-based One-Time Password (TOTP).