Multi Factor Authentication for Outsystems Back office

Multi Factor Authentication for Outsystems Back office

  • Other use cases
  • Computer & Technology

Solution Overview

Securing your Outsystems environment for IT users that need to login and use Service Studio, Integration Studio, Service Center and LifeTime, authenticating against Azure using a rotating PIN that expires.
View Demo

Key Features

  • Internal company policy dictates that all internet-facing applications must use the company’s authentication provider such as Azure Active Directory (AAD) with Multi-Factor Authentication (MFA) 

  • OutSystems applications can support this relatively easily with available forge components. However, when it comes to the OutSystems platform itself, it is not so straight forward. There are authenticator plug-ins on the forge that can facilitate AAD+MFA for LifeTime and Service Centre, but not for Service- and Integration Studio -which are desktop applications with a single authentication cycle. 

  • The problem we solved was how to enable all the OutSystems Platform components to work with AAD+MFA using standard API’s. 

  • The JustSolve team has designed a solution which satisfies this requirement by using a bespoke third-party application as a middleman to connect a custom OutSystems authentication plug-in to AAD indirectly via a generated One Time Password (OTP). 

  • The solution itself is divided into two parts, namely the OutSystems Authenticator Plug-in and the JS Authenticator Web Application. 

  • The plug-in will be deployed to each client’s platform and configured with their own information. 

  • The web application will be hosted by JustSolve and will deliver the primary service of dealing with AAD+MFA integration and servicing login requests from client platforms. 

Key Benefits

Adds additional security:

  • The solution adds additional security to the Outsystems Platform so that the platform complies with the company’s standards, the same as with end-user applications. 

  • If a developers AD account gets disabled they will automatically lose access to Service Studio, Integration Studio, Service Center and LifeTime. 

  • OTP sessions expire after a set amount of time, making sessions more secure. 

  • OTP can be sent via UI, email or SMS. 

Other Solutions from JustSolve (Pty) Ltd

Centricity
Centricity
Experience The Digital Workforce platform of the future, today. One platform to create your solutions and processes all in one place with this no code solution builder. Track, execute, manage and report from any mobile device or web browser.
See Solution Details
myCPD
myCPD
Train and assess your staff with verified educational content from industry leaders, innovators, and subject matter experts, so that you’re better prepared to get ahead and excel in your profession. Set your training goals and report on them.
See Solution Details
RubixCube
RubixCube
RubixCube is a solution that fast tracks the ability to determine whether new or existing ventures or ideas are viable. It enables subject matter experts to break the process of building a new business into easily understandable building blocks.
See Solution Details