Multi-Factor Verification for Employers
This feature will be made available in the June 2022 release.
Overview
When Multi-Factor Verification (MFV) is enabled, during registration, Employers will be taken to a verification step to verify if they are the intended recipient of the email.
Multi-Factor Verification
When a new Employer is registered, they will receive a registration email as usual. When they click the Activate Account link in the email, then:
- if MFV is not enabled, they will be taken to the Create Password screen as usual.
- if MFV is enabled, but they do not have a mobile number populated, or have an invalid mobile number, then they will be taken to the Create Password screen.
- if MFV is enabled, and they have a valid mobile number populated, then they will be taken to the Enter verification code screen in Aptem console, even if they only have access to Classic.
When the user reaches this screen, a six-digit code is sent to the registered mobile number.
The SMS delivery is tracked – allowing the user to know if the message was successfully delivered or not.
The user can use the Resend Code option and request a new verification code after 30 seconds of the previous request. Note that the new verification code will be the same as the previous code if it has been under 15 minutes since the previous code was sent. If it has been over 15 minutes, then the new verification code will differ from the old one.
The user must enter the verification code they received in their mobile. Once they enter the code, they must click Verify and Register.
If the verification code is incorrect, an error message is displayed. If the user enters the incorrect code five times, they will see an error and be asked to wait 60 seconds before trying again.
If the verification code is correct, the user is taken to the change password screen.
Those Employers who only have access to Aptem classic will be logged in/redirected to the classic interface after they complete the verification and set their password using the console interface.
In cases where MFV is not enabled, the employer will be directly taken to the create password registration step when they click the Activate account link in the registration email.