ZTrust Authenticator

The ZTrust Authenticator is a secure mobile application designed to offer different single factor as well as two-factor authentication (2FA) options.

1. Introduction

The ZTrust Authenticator is a secure mobile application designed to offer different single factor as well as two-factor authentication (2FA) options, including Time-Based One-Time Passwords (TOTP), QR code scanning, Push notifications, and NFC-based authentication. These features provide additional layers of security for your accounts beyond passwords. These features provide different types of methods for user authentication.

2. System Requirements

  • Operating System: Android 10 or later and iOS 13 or later

  • Internet Access: Required for account setup, push notifications, and syncing

  • Storage: 200 MB minimum

  • Permissions:

    • Camera: For QR code scanning

    • NFC: For NFC-based authentication (NFC-enabled device)

    • Internet: For push notification (Allow Notification permission)

3. Installation

  • Now install the application and start the initial setup.

4. Getting started

ZTrust Authenticator allows users to securely add their accounts using the following methods:

  • ZTrust SSO Login

  • Self-Service Portal

Each method uses a simple QR code scan and secure confirmation process to onboard your device.

4.1. Enforce the user to set up an authenticator while logging in or registering.

Prerequisites

  • Initial setup required; enable the required action in ZTrust SSO to trigger device registration and onboarding. Steps as follows:

    • Log in to the ZTrust Admin Console and select the realm where you want to enable Device Registration.

    • Then, on left side under the configuration section, select Authentication tab in bar.

    • There you will see three tabs, like Flows, Required actions and Policies. Select Required ons tab.

    • Here, you will see three headings: Action, Enabled, and Set as Default Action

      • Action: Represents the types of required actions available in ZTrust.

      • Enabled: Indicates whether the action is active and ready to use. Once enabled, the admin can assign it to specific users. However, for device registration, it should be enabled for all users at the time of registration.

      • Set as Default Action: When turned on, the selected required action becomes mandatory for the realm. This means that whenever users register, they must complete this action in addition to filling out the registration form.

    • Now, enable the Authenticator Application Setup by turning on both Enabled and Set as Default Action.

    • Now that it is enabled as a default required action, any user who registers through the ZTrust registration page will also be prompted to complete the device registration setup.

Last updated