As part of the commitment to delivering best-in-class digital experiences, our client portal, eMoney is modernizing their platform and strengthening the security program in collaboration with Okta, a trusted partner and industry leader in identity management.
To further strengthen protection, eMoney has enabled an enhanced Adaptive Multi-Factor Authentication for all users who login directly, adding an additional layer of security that safeguards confidentiality, integrity, and availability of client information while providing seamless, user-friendly access.
What’s New
- Minor Design Updates: Users signing in with a username and password may notice some subtle changes, including new multi-factor authentication (MFA) requirements and slight design updates. Users who single sign-on (SSO) into eMoney will not experience anything different, as they bypass the login screen.
- Initial 2nd Factor Prompt: Regardless of the Adaptive MFA level, all users who login directly will be prompted to reauthenticate themselves via this updated flow and provide a 2nd factor at login initially. This may look like being prompted to enter in a unique code emailed from Okta after entering in your password. Once signed in, you most likely won’t be prompted again. Following this update, if you or your clients directly sign-into eMoney with login credentials, an initial prompt to enter your phone number will display.
- Phone Number Request: You may be prompted to provide a phone number as a 2nd factor login method.
- Improved Risk Mitigation: If you’re signing in from an unrecognized location, you may be prompted to provide a 2nd factor when logging in. Additional verification is triggered only when something appears unusual.
- Retiring RSA One-time Access Code: Due to low use and our move towards enhanced security standards, we are retiring the ability for users to log in using a one-time access code in the event a text message or phone call verification wasn’t successful.
How Does AMFA Work?
Each time a user logs in, adaptive MFA dynamically evaluates multiple factors to calculate a risk score and determine whether additional authentication via SMS or phone call is necessary. Factors used in this assessment include device type, geographic location, time of access, network and IP reputation, and historical login patterns. Risk levels (low, medium, high) are configured at the firm level and apply uniformly to all users.
Note: If you directly sign into eMoney, you may see a login message over the coming weeks about this.
Protecting clients’ data remains our top priority. For any questions, feel free contact us.
This information was provided by emoney advisor.