Multi Factor Authentication
Comissio uses Multi Factor Authentication (MFA) to provide a higher level of security protecting sensitive information.
Comissio uses Multi Factor Authentication (MFA) to provide a higher level of security protecting sensitive information. Agents and Users will have the same process for the authentication process. They will have three options for receiving a security code by email, text message, or phone call. A six-digit code is sent to the User who must enter the code before completing logging in.
Initial authentication page to select authentication method:

- Depending on the selected option, a dropdown will display available email address or phone numbers.
- Email addresses or phone numbers displayed will be partially masked.
- Users will have six attempts to successfully enter a security code and log in or will need to wait thirty minutes before they can attempt again.
- Codes expire after seven minutes.
- If at one or more phone numbers have been identified as ‘Cell,’ when Text is selected, only phone numbers identified as call will display in the dropdown. If no phone numbers are identified as ‘Cell’ then all phone numbers will display as selections for the Text option.
Entry page for Verification Code:

Remember this device for 30 days
A user will only have to perform the MFA log in process every thirty days when the ‘Remember this device for 30 days’ option on the initial MFA selection is checked.

System Setting for authentication
There is a setting to allow limiting the authentication options.
Setting that will allow controlling options for authentication method:

MFA from Forgot Password
When a User uses ‘Forgot Password’ from the initial Comissio log in page, after they enter their Username and email, they will be presented with an MFA process with only voice and text options. This is to add more security in the event a user’s email were compromised.
Reset Password page after selecting ‘Forgot Password:’

Two Step authentication page presented for MFA:
