Multifactor Authentication (MFA)

Purpose: An additional layer of account security for logging into LegalServer. It allows access to LegalServer only after you enter a username and password and and authentication code you receive by email or via an authentication app.


Cost: None .

Enabling MFA for a site (Site administrators)

LegalServer staff must enable the feature. File a ticket from your site (Help menu > Support Request). To check if it is already enabled on your site, visit the Admin > Site Settings page and look in the Authentication section.

Requiring MFA

Administrators can require Multifactor Authentication per user role on the Admin > Site Settings page.

Authentication Period

Authentication lasts 24 hours.

I Lost My Phone (Re-Enabling MFA)

A site administrator will need to disable MFA for your account. When you next login, you can enable MFA again, or if it is required for your user role, you will be forced to enable MFA again.

Initial User Experience

Hover your cursor over your name in the upper right corner of any page and select “My Preferences”.

On your My Preferences page, Actions menu > Enable MFA.

Depending on what your site administrators have configured, you can receive your MFA code via email or an app.


Configure MFA via email mechanism

If Email is offered, and you select it, follow the prompts.

The code in the email expires after 15 minutes.

Configuring MFA via an app-based mechanism

If offered, and you select MFA via an app, follow the prompts.


You need an authentication app on your phone or device. Install one like you do other apps (or as required by your organization). Options are Google Authenticator (Google Authenticator for iOS / Google Authenticator for Android), Authy, or password vault applications like 1Password, Lastpass, or Bitwarden.

On the next screen, either: 1) scan the LegalServer MFA QR code to set-up an account, or 2) enter the MFA Manual Entry key via the setup key prompt on your device.

The authenticator app will populate a 6 digit code for entry into LegalServer’s Authenticator Code section. Note that these codes expire every 30 seconds.

Disabling MFA


Users

You may be allowed to disable MFA on your My Preferences page via Actions menu > Disable MFA. If MFA is required for your user role by your site administrators, you will not be able to disable it.


Site Administrators

Site administrators can disable MFA, or change a user's MFA Method, by editing those fields on the user record. Those fields are typically not shown, or not editable, on the user profile, but are on an auxiliary form restricted to only Administrators.

Reporting on MFA

There are two fields on the System Users table that tie in with MFA. A boolean about whether MFA is enabled and which MFA mechanism in use. A sample report about all users and whether they have MFA enabled can be found in Example Reports.

Known Issues and Notes

    • Administrators can see which users have MFA enabled but there is not yet a way to enable MFA without the user’s participation