[2FA/TFA] Two factor authentication for Service Center and LifeTime
3533
Views
33
Comments
On our RadarOn our Radar
Service Center

Considering the fact that the cloud version does not support internal network for IP white listing, I think adding an extra layer of security to secure service center  with Two factor authentication should be a standard in the Outsystems platform.

Changed the category to
Service Center

good idea, would like this implemented! 

Good idea! 2FA should be the bare minimum for admin tools that are exposed on the internet.

Merged this idea with 'Two factor authentication for Lifetime' (created on 2015-12-08 00:52:18 by Steve Jordan)
I'd really like to see Outsystems introduce a two factor authentication option to Lifetime. Security these days is a massive issue.

Merged from 'Two factor authentication for Lifetime' (idea created on 2015-12-08 00:52:18 by Steve Jordan), on 2018-04-11 17:19:33 by José Ramalho
Changed the status to
On our RadarOn our radar

Hi Robin,


Thank you so much for your idea. I’m marking this as “on our radar” since we think this is a good idea.


This isn’t currently on our short-term backlog but we’ll keep an eye here if this idea continues to grow and get comments from all of you.  

Regards

I agree with the others so far, 2FA or IP address whitelisting is a must for Service Center & Lifetime in the cloud. I would prefer 2FA as it's more flexible. My only option at the moment is to look at some kind of web application firewall to achieve this.

IP address restriction has been easy to achieve in our applications, it would be nice to protect the admin tools as well.


It's just occurred to me that this should also be extended to logins for Service Studio and Integration Studio as well.


Chris.

Considering the fact that the cloud version does not support internal network for IP white listing

At the time of writing this idea Outsystems did not support restricting access to an Internal Network for their cloud solution. This feature is since early this quarter available.


Robin.

Where is this feature available Robin?

Chris.

2018-05-09 09-20-09
Paulo Costa

Hi Chris,

The feature is indeed available for Enterprise users. You'll need to open a Support Case and request to set it.


Cheers,

Paulo

Hi, 

We are looking for the same for on premise deployment. Any design patterns and customizations in service center and lifetime that the team can share with us? 


Jonathan 

@outsystems Any updates on the roadmap regarding implementing MFA on the platform ?

Also for Azure Deployment, two factor for ServiceCenter, LifeCenter and Development tools to secure Admin/developer access to platform it's a must in today's security requirements, like ISO27001.

Merged this idea with 'Service Center OR Lifetime 2 Factor Authentication' (created on 20 Jan 2020 09:20:38 by Rohan Hanumante)

HI, 

Is there is a 2FA (2 Factor Authentication) for the Service Center and Lifetime?

So, That we have the at maximum security at those application.

Like Something, When anyone trying to login in SC/LT by Username and credential by submitting the submit button it popped up to enter the code that has been sent to the email address i.e username. By entering that code/OTP it should get access then...


Thanks.....  



This comment was:
- originally posted on idea 'Service Center OR Lifetime 2 Factor Authentication' (created on 20 Jan 2020 by Rohan Hanumante)
- merged to idea '[2FA/TFA] Two factor authentication for Service Center and LifeTime' on 20 Jan 2020 13:19:24 by João Bento
Merged this idea with 'Two Authentication Factor' (created on 13 Feb 2020 13:15:30 by Tiago Gomes)

A feature to autenticate via Two Authentication Factor (MFA) to Service Studio, Service Center and Life time would be great! Like that we could manage and secure our credentials! Created this idea on behalf of this post.



This comment was:
- originally posted on idea 'Two Authentication Factor' (created on 13 Feb 2020 by Tiago Gomes)
- merged to idea '[2FA/TFA] Two factor authentication for Service Center and LifeTime' on 18 Feb 2020 14:10:41 by Justin James

This idea is amazing, please implement.



This comment was:
- originally posted on idea 'Two Authentication Factor' (created on 13 Feb 2020 by Tiago Gomes)
- merged to idea '[2FA/TFA] Two factor authentication for Service Center and LifeTime' on 18 Feb 2020 14:10:41 by Justin James

Hi,

I am also looking forward that Outsystems will implement this idea.

I have posted the same https://www.outsystems.com/forums/discussion/56467/service-center-2fa/


thanks...



This comment was:
- originally posted on idea 'Two Authentication Factor' (created on 13 Feb 2020 by Tiago Gomes)
- merged to idea '[2FA/TFA] Two factor authentication for Service Center and LifeTime' on 18 Feb 2020 14:10:41 by Justin James

Amazing idea! A must-have.



This comment was:
- originally posted on idea 'Two Authentication Factor' (created on 13 Feb 2020 by Tiago Gomes)
- merged to idea '[2FA/TFA] Two factor authentication for Service Center and LifeTime' on 18 Feb 2020 14:10:41 by Justin James

+1, security is never enough!



This comment was:
- originally posted on idea 'Two Authentication Factor' (created on 13 Feb 2020 by Tiago Gomes)
- merged to idea '[2FA/TFA] Two factor authentication for Service Center and LifeTime' on 18 Feb 2020 14:10:41 by Justin James

+1, Nice idea to increase the security. 



This comment was:
- originally posted on idea 'Two Authentication Factor' (created on 13 Feb 2020 by Tiago Gomes)
- merged to idea '[2FA/TFA] Two factor authentication for Service Center and LifeTime' on 18 Feb 2020 14:10:41 by Justin James

+1 we must have it !

Definitely a must-have going forward.

This should be a mandatory addition in todays age of accounts being hacked through weak passwords and social engineering. I'd also like the ability to set password criteria - such as complexity and length of any passwords + frequency of resets. Because we hold a lot of very sensitive client data (and we know of projects done with outsystems for the Australian Government), this should be at the top of the list for implementation.  Surely it's not super difficult to implement?

+1 Great idea!
Definitely a must have for an added layer of protection to Lifetime and ServiceCenter.

Please implement this OutSystems.

Thank you

This is a compliance requirement in financial services.

Please be available as soon as possible.


100% agree this is a must for Litetime and needs to be added ASAP!!!!

Unfortunately, we've been waiting for 5 1/2 years now :-(  

Yes this is a must. Since there is no native support for SAML in lifetime, atleast this would be a mitigation for having local usernames/passwords.

This is indeed a must-have, and one of our current client's biggest concerns.

Just to add another two cents to this - the UK's Cyber Essentials Plus certifications has now expanded to include cloud platforms such as OutSystems.  So all government and public bodies have been asking for the CE+ certification from service providers.  And we don't always manage to get an Enterprise license, or use a common external identity provider.  Some kind of standalone 2FA solution on all options would be needed with the CE+ updates. 

Links:

https://www.ncsc.gov.uk/cyberessentials/overview

https://iasme.co.uk/cyber-blog/the-january-changes-to-the-cyber-essentials-scheme-reflect-the-changing-cyber-threats-in-todays-digital-environment/ 

Hello OutSystems,

This is the must function to include and been this topic around 2015.

when this will be included part of the platform?

Thanks

Anil.

Hi OutSystems, update on this please.

Thank you.