Multifactor Authentication (MFA)
Purpose: An additional layer of account security for logging into LegalServer. It allows access to LegalServer only after you enter a username and password and and authentication code you receive by email or via an authentication app.
Enabling MFA for a Site (Site administrators)
LegalServer staff must enable the feature. File a ticket from your site (Help menu > Support Request). To check if it is already enabled on your site, visit the Admin > Site Settings page and look in the Authentication section.
Administrators can require Multifactor Authentication per user role on the Admin > Site Settings page.
Authentication lasts 24 hours from when you last successfully logged in.
Authentication is specific to a device:
Different computers are, unsurprisingly, considered different devices.
Different browsers are also considered different devices. If, for example, you login and authenticate with Firefox, then login with Chrome, you will be prompted to authenticate again (unless you had authenticated with Chrome within that last 24 hours).
A private/incognito window in the same browser is considered a different device.
I Lost My Phone (Re-Enabling MFA)
A site administrator will need to disable MFA for your account. When you next login, you can enable MFA again, or if it is required for your user role, you will be forced to enable MFA again.
Initial User Experience
Hover your cursor over your name in the upper right corner of any page and select “My Preferences”.
On your My Preferences page, Actions menu > Enable MFA.
Depending on what your site administrators have configured, you can receive your MFA code via email or an app.
Configure MFA via email mechanism
If Email is offered, and you select it, follow the prompts.
The code in the email expires after 15 minutes.
Configuring MFA via an app-based mechanism
If offered, and you select MFA via an app, follow the prompts.
You need an authentication app on your phone or device. Install one like you do other apps (or as required by your organization). Options are Google Authenticator (Google Authenticator for iOS / Google Authenticator for Android), Authy, or password vault applications like 1Password, Lastpass, or Bitwarden.
On the next screen, either: 1) scan the LegalServer MFA QR code to set-up an account, or 2) enter the MFA Manual Entry key via the setup key prompt on your device.
The authenticator app will populate a 6 digit code for entry into LegalServer’s Authenticator Code section. The codes expire every 30 seconds.
You may be allowed to disable MFA on your My Preferences page via Actions menu > Disable MFA. If MFA is required for your user role by your site administrators, you will not be able to disable it.
Site administrators can disable MFA, or change a user's MFA Method, by editing those fields on the user record. Those fields are typically not shown, or not editable, on the user profile, but are on an auxiliary form restricted to only Administrators.
Reporting on MFA
There are two fields on the System Users table that tie in with MFA. A boolean about whether MFA is enabled and which MFA mechanism in use. A sample report about all users and whether they have MFA enabled can be found in Example Reports.
Emails sent to users using that method appear in the /mail/queue sent list. Add that to the end of your site's URL, for example, foo.legalserver.org/mail/queue. Filter the List Sent Mail list for Subject "verification code".
Notes and Known Issues
Administrators can see which users have MFA enabled but there is not yet a way to enable MFA without the user’s participation.
Users assigned to the Pro Bono Restricted Access role cannot currently use MFA.