Multi-Factor Authentication (MFA)

Note: Starting 15 November 2024, all Rescale users must use MFA to secure their accounts unless their organization is configured to use Single Sign-on (SSO). Organization administrators are free to require MFA for their users before this change takes effect.

Multi-factor Authentication (MFA) is an authentication scheme that requires two independent types of credentials, e.g., a password and a login token generated on an application or received through an online account such as email.

Prerequisites

  • A Rescale account with an MFA device setup
  • Depending on the MFA device setup, access to either the email attached to your Rescale account or a personal computing device (e.g. a smartphone or tablet) with an authentication app installed
  • If you plan on using an authentication app for MFA, Rescale recommends the following:
    • For an iOS device, Google Authenticator from the App Store
    • For an Android device, Google Authenticator from the Google Play Store
    • For a Windows device, Microsoft Authenticator from the Microsoft Store

Managing MFA

You can manage your MFA devices by logging into your Rescale account, navigating to the User Profile Settings page, and clicking on the MFA Device tab. Rescale supports email and authentication apps as MFA devices. You must have at least one MFA device set up to log into Rescale if MFA is enabled for your user.

When MFA is required, Email is selected as the default MFA device for new users or existing users who did not previously have an MFA device. However, you can choose to add an authenticator app if preferred.

You may also generate backup codes to authenticate your login if you lose access to your MFA device(s).

Authenticator Application MFA Device

In addition to email, you may choose to use an authenticator application as your MFA device if you don’t have one set up already. On the MFA Devices page, click on the Add Authenticator button. A QR code will be shown on the screen. 

Launch the authenticator app on your smartphone or tablet to set up a new account and scan the QR code. The app will generate a 6-digit code based on the QR code scanned. Add the code in the Token field and click on Confirm to add the device. Now you are ready to use the authentication app as your MFS device.

google-authenticator-ios

Default MFA Device

If you have multiple MFA devices set up, you can specify your preferred MFA device from the MFA Device page. A Set As Default button will appear against your non-default MFA device as shown in the image below. Please note that the default MFA device setting only determines the device you see first during the login process, however, you may still choose to use a non-default device to authenticate your login.

MFA Backup Codes

MFA backup code is a one-time code that serves as a backup method for accessing your account if you can’t use your primary MFA method. These codes are particularly useful if you lose your phone, your authentication app is deleted, or you can’t receive a verification code for any reason. Backup codes on Rescale are generated in a batch of 10 one-time codes so please make sure you generate a new batch of codes before exhausting the current batch.

You can generate backup codes by clicking on the Generate Backup Codes button on the MFA Device page as shown below.

A drawer will open on the right side of your screen. Click on the Generate button to create and view your backup codes. Save these backup codes securely. Please note that any existing backup codes will be deactivated once you click on the Generate button.

Using MFA to Login

With the MFA device set up, you will need both your password and a login token from your email or authenticator app to log into Rescale. Enter your email and password on the login screen and click on the Log In button. You will be redirected to enter your passcode. 

If you’ve selected Email as your default MFA device, as shown below, a one-time passcode will be sent to your email. Enter the passcode and click on the Submit button to complete your login. Optionally, check the Remember this device box to avoid being prompted for an MFA code on this device for 14 days.

Alternatively, you can click on the Use Alternative Method button to use a different MFA device to log in. Only the devices enabled for your user are displayed on this screen.

If you select the Use Authenticator option, you will be prompted to enter a passcode from your authenticator app. Launch the app on your device and enter the token that is displayed for this user based on the platform domain. In the screenshot below, the token applies only to platform.rescale.com. Finally, click Submit to finish the login.

google-authenticator-ios

Note: Each platform has a different domain name as shown below:

  • For US Platform: platform.rescale.com
  • For EU Platform: eu.rescale.com
  • For JP Platform: platform.rescale.jp
  • For KR Platform: kr.rescale.com

Organization-level MFA Settings

Note: This page will be deprecated on November 15th, 2024, once MFA is required for all Rescale users.

This section is for organization administrators only. As an organization administrator, you can manage MFA settings for all users within the organization. To access the MFA Settings in the company administration site:

Platform RegionOrganization MFA Settings
United StatesUS Security
European UnionEU Security
JapanJP Security
South KoreaKR Security

Three options are available in MFA Settings:

  • Disable MFA authentication: this will disable MFA for all users in the company
  • MFA authentication optional: this will allow users to make MFA optional
  • MFA authentication required for all users: this will require all company users to use multi-factor authentication to log in to the Rescale Platform

Lost Your MFA Device?

With MFA enabled on your Rescale account, you’ll need both your email/password and your MFA device to log into the platform. If you lose access to your MFA device or accidentally delete your authentication app, you can use backup codes to authenticate your login. Please contact Rescale support at [email protected] if you lose access to your MFA device and do not have backup codes.