59
Multifactor Authentication for Business Banking Customer Platform: Certification Webcast for Security Code Laura Sund Martin Digital Insight University Business Banking v. 4.16

Laura Sund Martin Digital Insight University

  • Upload
    astra

  • View
    33

  • Download
    0

Embed Size (px)

DESCRIPTION

Multifactor Authentication for Business Banking Customer Platform: Certification Webcast for Security Code. Laura Sund Martin Digital Insight University. Business Banking v. 4.16. Some Recorded Webcast Pointers. - PowerPoint PPT Presentation

Citation preview

Page 1: Laura Sund Martin       Digital Insight University

Multifactor Authentication for Business Banking Customer Platform:

Certification Webcast for Security Code

Laura Sund Martin

Digital Insight University

Business Banking v. 4.16

Page 2: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 2MFA for BB – Customer Platform – Security Code Certification Webcast

Note that you’ve got controls along the bottom of the webcast window. You can pause the webcast if you need to take a short break, rewind to review, forward, or stop.

This webcast is best viewed with Media Player 10 or higher and the Replay Wrapper installed. If you don’t see a list of the slides on the left side of your screen, you don’t have the Replay Wrapper installed. See next slide for how to install both MP10 and the Replay Wrapper.

If you need to stop the webcast and finish it at a later time, note that the slide names/numbers appear in a window to the left. When you access the webcast later, simply scroll to the name of the next slide from where you left off. It will take a moment to jump to that spot, and then you are on your way!

Some Recorded Webcast Pointers

Page 3: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 3MFA for BB – Customer Platform – Security Code Certification Webcast

Some Recorded Webcast Pointers

If you don’t have the dropdown menu showing the slide deck, stop the recording, return to this screen, and install the Replay Wrapper. You must have Media Player 10 or higher to install the Wrapper.

Page 4: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 4MFA for BB – Customer Platform – Security Code Certification Webcast

Did you know…there are 3-4 ways to change the volume on your computer for a webcast?? If you are having problems hearing my voice, please hit your PAUSE button and check the following:

The Windows Media Player softwareYou have a volume control (typically a slide bar) at the bottom of your Player window.

Your computer softwareIf you’re using Windows, in the lower right corner you should have a sound control icon . Double click on this, and check the following: 1) everything should be set a maximum and 2) none of the “mute” options are checked.

Your computer’s sound cardOn your computer (especially if it’s a laptop), the sound card may have a volume control. Feel or look around your computer to see if there is a volume control.

External speaker controlThis is the most obvious one and you’ve probably already thought of it!

If you have adjusted all those settings, and experience normal audio volumes listening to other sources of pc audio (go to another site, like www.cnn.com to test it out), then please contact Microsoft Customer Support at 866-493-2825 and they can work further with you.

Some Volume Pointers

Page 5: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 5MFA for BB – Customer Platform – Security Code Certification Webcast

Overall Objective:This webcast will train you on how your business users will use multifactor

authentication (MFA) to increase their login security, and how to track MFA activity in the FI Admin Platform.

Specifically we will cover:

What multifactor authentication is How business users enroll and unenroll in MFA How enrolled users log in New features for Company Administrators How FI administrators use FI Admin Platform to create reports on MFA

Session Objectives – Security Code Webcast

Please note that this webcast is for financial institutions offering the Security Code option for MFA!

Page 6: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 6MFA for BB – Customer Platform – Security Code Certification Webcast

We have designed this MFA Security Code training for multiple employees at your financial institution:

If you are a cash management specialist or service rep who needs to talk to your commercial clients about MFA but will NOT be using the FI Admin Platform, you’ll complete through slide 53. The trainer will remind you at that point that you can exit the webcast.

If you are an FI admin who will be using the FI Admin Platform, you’ll complete the entire webcast.

If you are the Project Lead, be sure you view the Enablement Webcast before you view this one!

Completing this Training

Page 7: Laura Sund Martin       Digital Insight University

Product Overview

If you have already viewed the Enablement Webcast, skip

to slide 15 “Using MFA on the Commercial Customer Platform”.

Page 8: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 8MFA for BB – Customer Platform – Security Code Certification Webcast

In the fall of 2005, the Federal Financial Institutions Examination Council (FFIEC), the regulators overseeing banks and credit unions, communicated that passwords alone will no longer be acceptable as the sole means of achieving online security. Multifactor authentication (MFA) was the recommended solution.

MFA requires online users to provide something additional beyond username and password to login.  This enhanced security means that even if a user has their password stolen in a phishing attack or by malicious software, the fraudster cannot access online accounts because they do not possess the additional factors needed, which are harder to steal.  By offering MFA, your FI can give your consumers and businesses peace of mind when using your online products and services.

Why MFA?

So why are we doing this?? To protect your end users’ sensitive information!

Page 9: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 9MFA for BB – Customer Platform – Security Code Certification Webcast

After your FI has enabled MFA:

1. Business Banking user logs into Business Banking.

2. User must retrieve Security Code from their email account, and enter it.

3. User can choose to enroll the computer they are currently using in MFA.

a. If they do – a cookie is installed on their computer, and the next time they log in, they will see nothing different.

b. If they do not – the next time they are logged in, they will be presented with the Security Code screen and sent a new security code.

Basic MFA Steps

Page 10: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 10MFA for BB – Customer Platform – Security Code Certification Webcast

Terms & Definitions Single Armored authentication – The process of authenticating user credentials where the

only credentials authenticated are the User ID and password. MFA – Multifactor Authentication. The process adds an additional credential to be authenticated. Enhanced Login Security – This is the default feature label for the MFA product. Your FI is

allowed to choose a different name if desired.

Enroll a Computer – The process whereby a user chooses to define a particular computer as their additional factor for purposes of authentication. A cookie is installed on the computer.

Un-enroll a Computer – Where a user removes the computer as the additional factor. Enrolled User – Any user who has opted in to the MFA feature. First time enrollment is

accomplished when the user has successfully enrolled their first computer .

Credentials – Data elements that are needed in order to log in. This may include User ID, password, and browser cookie as well as Company Id and Company password.

Factors – Data elements that are required to log in above and beyond User ID. These factors may include password, browser cookie and email Security Code.

Temporary Access – Login where the user is enrolled in MFA and is attempting to log in from a computer that has not been recognized.

Cookie – a small piece of code installed on your computer (specifically in your browser). Invalid Cookie – a cookie that does not match the user credentials or as cookie that has been

expired or marked invalid by the MFA system.

Page 11: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 11MFA for BB – Customer Platform – Security Code Certification Webcast

Terms & Definitions

Security Code – A one-time passcode generated by the system in order to allow an MFA user to initiate a Business Banking session via Temporary Access.

Invalid Security Code – A security code that has: exceeded the timeout value, has been previously used successfully, or has been invalidated by the generation of a new security code.

FI – Financial institution

FI admin – an FI employee who is responsible for managing, overseeing, reporting on, etc. a particular product. There may be 1 or more FI admins per product at an FI.

Front-line staff – FI employees who communicate with commercial clients, e.g. cash management specialists or customer service reps.

Page 12: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 12MFA for BB – Customer Platform – Security Code Certification Webcast

Fraud Prevention: Strong Authentication

• Passwords• PINs• Secrets, etc.

• Computers• Phone / PDA• E-mail passcode

• Fingerprints• Iris scans• Voice prints, etc.

Know Have Are

Page 13: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 13MFA for BB – Customer Platform – Security Code Certification Webcast

Why a browser cookie-based approach?

Strong security with minimal effort by end user Always requires a second factor of authentication (something you have)

Cookie credential or security code Signup straightforward and fast

Non-intrusive No change from today’s login experience when using primary computers No change in browser settings required

Preserves “access anywhere” ability of business banking Temporary access method

Page 14: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 14MFA for BB – Customer Platform – Security Code Certification Webcast

Bus Banking MFA : Using the computer as the 2nd factor

On computer of user’s choice, a unique, secure device ID will be placed in the browser of the user’s PC

Links the computer to the user for login During subsequent logins, Digital Insight will check for

both correct password & matching device ID If user logs in from an enrolled PC, then no change

from current login experience If device ID is not present or mismatched, login is

only allowed if temporary security code sent via email to user is entered

No limit on number of computers a user can enroll

Business Banking Site

Business Banking Site

IDIDIDID

IDIDIDID

IDIDIDID

Laptop PC

Workroom PC

User#2

User#1

Page 15: Laura Sund Martin       Digital Insight University

Using MFA on the Commercial Customer Platform

Page 16: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 16MFA for BB – Customer Platform – Security Code Certification Webcast

Your financial institution has some options in enabling MFA. These are the setup possibilities for your commercial clients that you’ll need to be aware of in supporting them:

Your FI may require MFA for all commercial clients, or for select ones only.

Your FI has selected an MFA effective date (globally or per client).

Before the MFA Effective Date is reached, your commercial client users must confirm their email address (in one of two ways – see later slides).

Once the MFA Effective Date is reached, commercial client users have from 0-15 times to respond “later” (called the “MFA Bypass Count”) before they are required to provide a Security Code and/or add extra security protection to their user validation.

Your FI can choose to allow users to update their own email addresses.

MFA Setup for Commercial Clients

Your financial institution may have chosen to enable MFA for all your commercial clients with the same effective date, or your FI may have chosen different settings for different commercial clients. Talk to your Super User or project lead to find out

which way your FI has chosen to do this.

Page 17: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 17MFA for BB – Customer Platform – Security Code Certification Webcast

We’ll go through 3 training scenarios. All scenarios assume your FI has required MFA for this commercial client:

Scenario 1: In the FI Admin Platform your Super User has set the Effective Date = 2 weeks from today, MFA Bypass Count = 1. Bryce the Business User logs in.

Scenario 2: Bailey the Business User is going on a “working vacation” for two weeks. She will be taking along her home laptop, from which she cannot access her business email account. MFA is enabled for her business, and she has already enrolled her regular work computer.

Scenario 3: Blaine the Business User was out on her honeymoon during the 1-week period your FI allowed before making MFA mandatory for her company. Her company email address changed, but her company administrator did not update it in Business Banking.

Training Scenarios

Page 18: Laura Sund Martin       Digital Insight University

Scenario 1

Page 19: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 19MFA for BB – Customer Platform – Security Code Certification Webcast

Scenario 1: In the FI Admin Platform, your Super User has set the Effective Date = 2 weeks from today, MFA Bypass Count = 1.

1. Bryce the Business User logs in for the first time after you have enabled the MFA for this customer with the effective date 2 weeks away. He is presented with the confirm email address screen.

2. Bryce confirms his email address is correct or updates it if not.

3. Bryce continues to log in all week and the next.

4. Two weeks from today, Bryce logs in again. Now MFA is effective for his business, and Bryce is presented with the MFA enrollment screen. He chooses to defer enrolling in MFA.

5. Bryce logs in again the next day, from his main work computer. Now he must provide the Security Code sent to him via email and add the extra security protection (if he desires).

WHY? Digital Insight recommends that you make the effective date NOT the first date that MFA is rolled out to your FI. This gives your business users time to

confirm or update their email address.

Scenario 1 - Introduction

Page 20: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 20MFA for BB – Customer Platform – Security Code Certification Webcast

1. Bryce the Business User logs in for the first time the day after MFA has been enabled for his business. He is presented with the confirm email address screen.

Scenario 1 – Actions 1 & 2

2. If the address is correct, Bryce clicks on Yes. He will not be presented again with this screen upon future logins.

Page 21: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 21MFA for BB – Customer Platform – Security Code Certification Webcast

If the address is incorrect, Bryce clicks on No, and the screen refreshes to allow him to change his address (if your FI has checked the box to allow users to change their own email address). He will not be presented again with this screen upon future logins after he updates his address.

Scenario 1 – Action 2

Notes:

1. An email notification is sent to the Company Administrator when a user changes their email address.

2. If the user clicks on Cancel, they are taken to their Business Banking session. They will be presented with the Change Email Address screen again when they log in the next time.

Page 22: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 22MFA for BB – Customer Platform – Security Code Certification Webcast

Scenario 1 – Action 2

If the address is incorrect, the user enters it in both boxes, then clicks on Update and gets a confirmation screen.

Note: The user will not be presented with this Change Email Address screen again when logging in. However, they can change their address at any time by going to Administration Login Credentials Change Email Address once they have successfully logged into Business Banking. (If your FI has checked the box to allow users to change their own email address.)

Page 23: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 23MFA for BB – Customer Platform – Security Code Certification Webcast

OR – if you have not checked the box allowing users to update their own email address, Bryce will see a similar screen with different instructions:

Scenario 1 – Action 2

If his address is correct, Bryce clicks on Yes. If it’s incorrect, he clicks on No and then must contact his company administrator to update the address. Bryce will continue to be presented with this screen until he clicks on Yes.

Note: If it is the Company Administrator seeing this screen, they will be told to contact their FI administrator.

Page 24: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 24MFA for BB – Customer Platform – Security Code Certification Webcast

3. Bryce continues to log in all week and the next. Because the MFA Effective Date hasn’t occurred yet, and because Bryce has already updated and/or confirmed his email address, he will not notice anything different for the rest of the time period.

Scenario 1 – Action 3

Page 25: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 25MFA for BB – Customer Platform – Security Code Certification Webcast

4a. Two weeks later, Bryce logs in again. Now MFA is effective for his business, and Bryce is presented with the MFA enrollment screen. He chooses to defer enrolling in MFA by clicking on Enroll Me Later. Remember that your FI has set the Bypass Count to 1, so he can defer one time.

Scenario 1 – Action 4

Page 26: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 26MFA for BB – Customer Platform – Security Code Certification Webcast

4b. After clicking on Enroll Me Later, Bryce sees a screen reminding him about MFA and letting him know he must update his email address if incorrect. Remember that your FI has set the Bypass Count to 1, which he has now used up, so this screen tells him he has zero logins remaining.

Scenario 1 – Action 4

Page 27: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 27MFA for BB – Customer Platform – Security Code Certification Webcast

Scenario 1 – Action 55. Bryce logs in again later in the day, from his main work computer. Now he must provide the Security Code sent to him via email and add the extra security protection (if he wants), because he has used up his one allowed Bypass Count login.

Page 28: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 28MFA for BB – Customer Platform – Security Code Certification Webcast

1. Following the on-screen instructions, Bryce checks his email account for the security code. Note the link to open a new browser window if he accesses email via a Web mail platform.

2. Bryce enters the security code. This is a code of random letters and numbers that is best copied and pasted into this field.

3. Since Bryce is on the computer he regularly uses to access Business Banking, he checks the “Add extra security protection to this computer”, then clicks on Continue.

Scenario 1: Enrolling a Computer

Notes:

1. The user should only enroll a computer if it is a non-public computer that the user will use regularly to access the Commercial Customer Platform.

2. The system sends a notification e-mail (identifying the user but not including the security code) to the Company Administrator.

Page 29: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 29MFA for BB – Customer Platform – Security Code Certification Webcast

4. The computer and browser being used are enrolled in MFA by installing a cookie on the user’s hard drive. If he has Macromedia Flash Player installed, an image is also made of that cookie. A confirmation screen appears.

5. Bryce is taken to Business Banking and continues his session.

Scenario 1: Enrolling a Computer

Notes:

1. Once a user enrolls their first computer, the user is now enrolled in the MFA feature.

2. Once a computer/browser is enrolled, the user will see nothing different at future logins to Business Banking from that computer using that browser.

3. If Bryce the Business User tries to access his Business Banking account from any other computer/browser, he will be presented with the same Enhanced Login Security screen requesting a Security Code.

Page 30: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 30MFA for BB – Customer Platform – Security Code Certification Webcast

Security Code Information

A Business Banking user will be presented with the screen requesting they enter the Security Code in the following situations:

When they attempt to log into Business Banking from an unenrolled computer/browser

If they have cleared their cookies on a previously-enrolled computer. BUT - If a user has Macromedia Flash Player (MMP) installed (most computers do), then an image will be made of that cookie. The result is that if cookies are deleted on that computer, the computer will NOT be unenrolled in MFA.

If the Company Administrator has reset them (see later in the training)

If the Company Administrator has unenrolled all computers for that user (see later in the training)

New informationsince the webcast

was recorded! Note other references to

MMP in thiswebcast.

Page 31: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 31MFA for BB – Customer Platform – Security Code Certification Webcast

Security Code Steps - Summary

1. You attempt to log into Business Banking from an unenrolled computer/browser.

2. System checks to see if you have a valid Security Code in the system. (See Security Code Timeout rules on page 35 to learn why a user might already have a valid Security Code in the system – typically they do not.)

3. If no, the system sends you a security code, and displays the screen telling you to check your email account.**

4. After obtaining the security code, return to this screen, enter the security code, and click Continue.

5. You are taken to your Business Banking session.

**By setting the MFA Effective Date later than the date your FI enables MFA, you are giving users time to ensure their email address is accurate.

Page 32: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 32MFA for BB – Customer Platform – Security Code Certification Webcast

Security Code – Other Scenarios

If the user entered an expired Security Code:

The screen refreshes to display the message in red. The user should request that a new code be issued.

Page 33: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 33MFA for BB – Customer Platform – Security Code Certification Webcast

Security Code – Other Scenarios

If the user has a valid security code but could not retrieve it before it expired:

On this Security Cole screen, they click on Request a New Security Code. The system invalidates the previous code (if it hadn’t actually expired) and sends a new one. The screen refreshes to display the message in red, then the user continues as described previously.

Page 34: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 34MFA for BB – Customer Platform – Security Code Certification Webcast

Security Code – Other Scenarios

If the user enters the wrong Security Code:

An error message displays. This is counted as a bad login attempt for the user (in other words, they can get locked out due to excessive tries). The Activity Report “bad login” log will clarify what caused the bad login (either if the user entered incorrect credentials or if it was an incorrect security code). Assuming the user is not locked out, they can try again. Note that the previous entry remains displayed so the user can see if they entered it incorrectly.

Page 35: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 35MFA for BB – Customer Platform – Security Code Certification Webcast

Security Code

Sample Security Code Email

Page 36: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 36MFA for BB – Customer Platform – Security Code Certification Webcast

Security Code

Passcode Requirements: The passcode is comprised of a series of numbers (default is 6). The passcode is not case sensitive and may display on the screen in either case.

Passcode Timeouts: The passcode has a 30 minute timeout value from the time that it is generated. If the passcode

has not been used within this time period, then the passcode automatically becomes invalid. Only one passcode is valid at any given time. If a user requests a new passcode, than all previously issued passcodes become invalid. Once a user successfully enters a passcode and is able to login, that passcode becomes invalid. If a user requests a passcode and does not use it (perhaps because they are unable to access

their email account) then that passcode will remain good for the duration of the timeout period. If the user attempts to log in again and they require the use of a passcode, and their previous passcode is still valid, the system will not automatically send them another when they reach the Passcode screen. Only if the end user requests a new passcode or if the passcode times out will a new passcode be automatically sent.

Other Information: A business user can set up 5 email addresses for the security access code to be sent to. The

user will select upon challenge which email address they wish to use to receive the passcode.

The first and last bullets are new information since the webcast was recorded.

Page 37: Laura Sund Martin       Digital Insight University

Scenario 2

Page 38: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 38MFA for BB – Customer Platform – Security Code Certification Webcast

Scenario 2: Bailey the Business User is going on a “working vacation” for two weeks. She will be taking along her home laptop, from which she cannot access her business email account. MFA is enabled for her business, and she has already enrolled her regular work computer.

1. Bailey changes her email address in Business Banking to one she can access via a web mail account. OR If your FI will not allow users to change their own address, her Company Administrator does it for her.

2. Bailey logs in for the first time from her laptop and is presented with the Security Code screen. She retrieves the code and enrolls this computer at the same time.

3. Bailey continues to log in for the next two weeks.

4. When she returns home, she is not planning to use that laptop again for work, so she unenrolls that computer.

Scenario 2 - Introduction

Page 39: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 39MFA for BB – Customer Platform – Security Code Certification Webcast

1. Bailey changes her email address in Business Banking to one she can access via a web mail account. OR If your FI will not allow users to change their own address, her Company Administrator does it for her.

If Bailey is allowed to do it herself, she goes to Administration Login Credentials Change Email Address.

Scenario 2 – Action 1

If Bailey is not allowed to do it herself, her company administrator goes to Administration User Maintenance and changes it for her.

Page 40: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 40MFA for BB – Customer Platform – Security Code Certification Webcast

2. Bailey logs in for the first time from her laptop and is presented with the Security Code screen. She retrieves the code. Before she clicks on Continue, she checks the “add extra security protection to this computer” box, since she will be using this computer for the next two weeks and it’s not a public computer.

Scenario 2 – Action 2

This works the same way as when she enrolled her work computer (see Scenario 1).

Page 41: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 41MFA for BB – Customer Platform – Security Code Certification Webcast

3. Bailey continues to log in for the next two weeks. Because she has enrolled this computer, she is taken straight to her Business Banking session after she enters the required login information.

Scenario 2 – Action 3

Page 42: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 42MFA for BB – Customer Platform – Security Code Certification Webcast

4. Back home, Bailey is not planning to use that laptop again for work, so she unenrolls that computer by going to Administration Login Credentials Unenroll Computers. The system removes the cookie from her browser.

Scenario 2 – Action 4

Notes:

1. Bailey is still enrolled in MFA! So if she logs in again from this or any unenrolled computer, she will not be allowed into her Business Banking session until they provide the security code.

2. A user should only select this option if they are not going to be using this computer for Business Banking again.

3. This ‘Unenroll Computers’ feature will only display if the financial institution has enabled MFA for the company and the ‘MFA Effective Date’ defined has expired.

Page 43: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 43MFA for BB – Customer Platform – Security Code Certification Webcast

Users select the second option to unenroll all computers from MFA. The system removes/invalidates the cookie from the user’s browser on this computer, and invalidates the cookies on any other registered computers.

Unenroll from the System

Note: As long as MFA is enabled for this client, a user who unenrolls all computers will be challenged each time they log into Business Banking.

Page 44: Laura Sund Martin       Digital Insight University

Scenario 3

Page 45: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 45MFA for BB – Customer Platform – Security Code Certification Webcast

Scenario 3: Blaine the Business User was out on her honeymoon during the 1-week your FI allowed before making MFA mandatory for her company. Her company email address changed, but her company administrator did not update it in Business Banking.

1. Blaine returns to work and attempts to log into Business Banking.

2. MFA is now mandatory, so Blaine is not presented with the “Confirm Email” screen. Instead, she is presented with the Security Code screen. However, when she checks her (new) email, the security code is not in her inbox.

3. Blaine is stuck – she cannot get into her Business Banking account because her email address as stored in Business Banking is incorrect. She must contact her company administrator and have him change her email address. Blaine can then return to the Security Code screen, click on Request a New Passcode, and try again.

WHY? It’s critical that you educate your Company Administrators about the importance of email addresses. They must make sure that everyone’s

address is correct.

Scenario 3

Page 46: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 46MFA for BB – Customer Platform – Security Code Certification Webcast

Front-Line Staff Pointers for Security Codes

Security code requests may generate a large number of calls to your FI.

Some things for you to keep in mind:

1) It’s common to suggest to users having Business Banking issues that they clear their cache and cookies. BUT – you need to understand that for a user who is enrolled in MFA, doing so will unenroll that computer unless they have the Multimedia Flash Player installed. You should warn them that they will be presented with the Temporary Access screen to enter in a Security Code and/or add the extra security protection once they have cleared their cookies in an attempt to solved the other issue.

2) You can no longer ask an enrolled user for their username and password in order for you to recreate the issue because now you will get challenged. Under no circumstances should you ask the user for their security code so that you can access their site. Solution: If you want to recreate the issue, you can disable the MFA feature for this commercial client in the FI Admin Platform (if the user agrees), as this will remove the additional security validation to allow you to log in and troubleshoot. You can then re-enable the feature. Note: The business users will not be MFA Challenged as long as the user’s cookie is still valid.

Digital Insight University has created Quick Tip sheets for you. Talk to your manager or MFA project lead to obtain these.

Page 47: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 47MFA for BB – Customer Platform – Security Code Certification Webcast

More details about the Bad Login Counter:

A ‘Bad Login’ occurs whenever an invalid credential is presented during the Business Banking login process. When the Bad Login count threshold of 5 is reached, the user is locked out of the system. A company administrator or FI Admin administrator must unlock or reset the user’s account before they can access the system again.

If one of the following invalid login events occurs, the bad login count will increment by one for each instance:

Incorrect company password

Incorrect user password

Security Code expired

Security Code incorrect

Computer is not recognized - No cookie or invalid cookie installed

Bad Login Counter

The business user’s Bad Login count is reset to zero when they successfully log into the Business Banking application.

Page 48: Laura Sund Martin       Digital Insight University

Company Administrator Features for MFA

Page 49: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 49MFA for BB – Customer Platform – Security Code Certification Webcast

Two features related to MFA are available to the company administrator on the User Maintenance screen: (Note: The options are not visible until the Effective Date has been reached.)

Company Administrator Features

Page 50: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 50MFA for BB – Customer Platform – Security Code Certification Webcast

Reset Login Credentials: This feature allows the Company Administrator the ability to reset and invalidate the selected user’s password and computer/cookies (including the Multimedia Flash Player cookie image). The Company Administrator must enter in a ‘Password’ and ‘Confirm’ prior to clicking the reset login credentials button.

If the company administrator resets the user’s login credentials, the user will be required to change their password, and will be presented with the option to add extra security protection to their computer.

Unenroll Computers:. This feature allows the Company Administrator to delete/invalid a sub user’s cookies/computer (including the Multimedia Flash Player cookie image).

Company Administrator Features

Notes:

1. The change password feature will function independently of the Reset Login Credentials and Unenroll Computers features. **In other words, using Administration > Login Credentials > Change User Password will not reset a user’s cookies.**

2. These features really work by invalidating the cookies in the DI cookie-based authentication system; it doesn’t literally go out and remove the cookies from remote computers, although it does invalidate the cookie in the current browser.

3. These same features are available in the FI Admin Platform – in that case, the effect is for the Company Administrator.

Page 51: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 51MFA for BB – Customer Platform – Security Code Certification Webcast

Administration > User Maintenance > Reset Login Credentials This feature allows the Company Administrator the ability to reset a sub user’s

password and invalidate the cookies/computers (including the Multimedia Flash Player cookie images) that the sub user had previously enrolled.

Why? If a computer is lost or stolen, a user does not remember their password, a user is on vacation and the CA doesn’t want them accessing BB, or a user has left the company.

Results: The Sub User has no enrolled computers (if successful; if failed, some or all

computers are still enrolled). The Sub User will be required to change their password and enroll their computer(s) upon their next login attempt.

The Sub User password has been reset and the user will be prompted to change their password.

Reset Login Credentials

Warning Message:

You are about to reset the user password and unenroll all of their computers/cookies. The user will be required to change their password and enroll their computer(s) at the next login attempt. Are you sure you want to reset the user’s password and computer(s)?

Confirmation Message:

The User password have been reset. All enrolled browsers for all computers have been successfully unenrolled from the Enhanced Login Security feature for the user selected.

Page 52: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 52MFA for BB – Customer Platform – Security Code Certification Webcast

Administration > User Maintenance > Unenroll Computers This feature allows the Company Administrator to delete/invalid a sub user’s

cookies/computer (including the Multimedia Flash Player cookie images). Why? similar reasons to the previous slide. Results: The Sub User has no enrolled computers (if successful; if failed, some or

all computers are still enrolled). The Sub User will be required to enroll their computer(s) upon their next login attempt.

Unenroll Computers

Warning Message:

You are about to reset the user’s computers/cookies. The user will be required to enroll their computers at the next login attempt. Are you sure you want to reset the selected user’s computers?

Confirmation Message:

The user’s computer(s) have been reset. All enrolled browsers on all computers have been successfully unenrolled from the Enhanced Login Security feature for the user selected.

Page 53: Laura Sund Martin       Digital Insight University

MFA Reporting & Other FIAP Enhancements

This is the end of the Customer Platform section.

If you will not be using the FI Admin Platform, you may EXIT the webcast now.

Thank you for attending!

Page 54: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 54MFA for BB – Customer Platform – Security Code Certification Webcast

The following Transaction Types (Customer Platform = Administration Activity Reporting, FI Admin Platform = Billing & Reporting Customer Activity Reporting) are affected by MFA.

Non-MFA-Specific Transaction Types that contain MFA information:1. Bad login (see next page)2. Usermaint modified

MFA Transaction Types:1. Unenroll computer2. All computers unenrolled3. New security code sent4. One time security code entered5. Computer enrolled6. Login authenticated7. User challenged8. User computers unenrolled9. Login credentials reset10. Email address confirmed11. Changed email address12. MFA bypass count

MFA Reporting

See the Business Banking 4.8 and 4.9.1 user guides for details

about each type.

Page 55: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 55MFA for BB – Customer Platform – Security Code Certification Webcast

There are four other features in the FI Admin Platform specific to MFA:

1. For the Security Code emails that get sent – the “Reply To” address is configurable by the FI via Communications > Email Workflow Routing feature. (The “From” email address is [email protected] .)

2. The verbiage of the Confidential statement is configurable via Communications > Messages > MFA Confidential for the following email notifications:

• The Auto Generated Email Notification with the Security Code

• The Company Administrator Email Notification

3. Change Email Address screen: The FI can define a default message for this page via Communications > Messages > Change Email Address.

4. Refer back to slides 51-52 for the Reset and Unenroll options.

Other FIAP Enhancements

Some things on thisslide have been reworded

since the webcast was recorded.

Page 56: Laura Sund Martin       Digital Insight University

Wrap Up

Page 57: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 57MFA for BB – Customer Platform – Security Code Certification Webcast

Overall Objective:This webcast trained you on how your business users will use multifactor

authentication (MFA) to increase their login security, and how to track MFA activity in the FI Admin Platform.

Specifically we covered:

What multifactor authentication is How business users enroll and unenroll in MFA How enrolled users log in New features for Company Administrators How FI administrators use FI Admin Platform to create reports on MFA

Session Objectives

Page 58: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 58MFA for BB – Customer Platform – Security Code Certification Webcast

Webcast Survey

Your feedback is valuable to us! Please take a minute to complete the webcast survey at www.customersat3.com/csc/di/wod.asp

(You must access this page by clicking on the hyperlink on the next slide.)

Your trainer’s name: __________________________

We value your comments – please let us know:

if this webcast provided valuable information to you

how the trainer presented the material NOTE: The survey will notautomatically open when Igo to the next screen! You

must click on the hyperlink there.

Page 59: Laura Sund Martin       Digital Insight University

© 2010 Digital Insight, an Intuit company. May not be reproduced in whole or in part without written permission.

p 59MFA for BB – Customer Platform – Security Code Certification Webcast

Slide Title

http://www.customersat3.com/csc/di/wod.asp