SingleID’s MFA service provides users with a variety of additional second-factor authentication services through system integration, while maintaining the authentication system used by applications to enhance security.
Additionally, SingleID provides an MFA Portal that lets you pre‑register and manage your preferred authentication methods for authentication, allowing convenient configuration.
The MFA Portal manual provides a feature that allows users to self-register secondary multi-factor authentication.
For detailed information, refer to the items below.
User portal screen > top language selection, choose the language you want from ‘Korean’ or ‘English’.
It will be changed to the language you selected.
Reference
On the first login, it is presented in the language configured in the user’s browser. If the language is other than Korean or English, it will be set to English.
SingleID connection environment and support
Category
Support
Recommendation
PC
Windows : Windows Desktop 10 and 11 (x86 and x64 CPU Only)
Web Browser: Microsoft Edge, Latest public version
Windows : Windows Desktop 10 and 11 (x86 and x64 CPU Only)
Web Browser: Microsoft Edge 88.x or later, Chrome 87.x or later
Moblie(Android)
Android : 8 and later versions
Web Browser: Samsung Internet Latest public version
Android : 8 and later versions
Models released in 2018 and beyond among Samsung Galaxy Mobile Products
Galaxy S9 ↑
Web Browser: Samsung Internet 9.0 ↑
Moblie(iOS)
iOS : 16 ,17
Web Browser: Safari , Latest public version
iOS : 16 ,17
iPhone Xs ↑, Models released in 2018 and beyond among Apple iPhone Products
Web Browser: Safari 14.1 ↑
Table. SingleID connection environment support scope and recommended specifications
1 - Log in using an authentication method
Log in using an authentication method
What is an authentication method?
Authentication method, commonly called Authenticator, refers to an authentication tool.
SingleID provides the following 11 authentication methods for user authentication.
Password: Enter password on the SingleID login screen
Email OTP: Send the OTP via email and enter the OTP on the SingleID login screen
SMS OTP: Send OTP via SMS and enter the OTP on the SingleID login screen
Knox Messenger OTP: Send OTP via Knox Messenger and enter OTP on the SingleID login screen
Knox Identity: Knox Portal user ID password authentication integration
SingleID Authenticator Bio: Install the dedicated SingleID mobile app and link authentication using biometric authentication (fingerprint, facial recognition)
SingleID Authenticator PIN: Install the SingleID‑dedicated mobile app and link authentication with a PIN.
SingleID Authenticator mOTP: Install the SingleID‑exclusive mobile app and integrate authentication with mOTP (Mobile OTP).
SingleID Authenticator TOTP: Install the SingleID‑dedicated mobile app and integrate authentication with TOTP(Time base OTP).
Passkey: Login and authentication using biometrics (fingerprint, facial), mobile, or PIN code without a password, based on Windows Hello.
Admin Authentication: If the admin permits direct authentication, request authentication on the admin’s behalf
Reference
SingleID Authenticator If this is your first time using the SingleID Authenticator mobile app, please refer to SingleID Authenticator.
Setting the preferred authentication method
The user logs into the User Portal provided by SingleID and sets their preferred primary and secondary authentication methods.
If the user sets their preferred method, the screen for selecting a verification method is skipped during login and authentication, allowing immediate authentication using the primary and secondary methods.
If you want to set your preferred authentication method, follow the steps below.
User Portal > Personal Profile > Authentication settings, click.
Click the star (☆) for each of your preferred 1st authentication method, 2nd authentication method.
After the configuration is complete, the next login will use this method, offering convenient access.
Information
Even if users set their preferred authentication methods for primary and secondary authentication, administrators can restrict them to specific authentication methods through login policy settings.
Register authentication tool
All authentication methods can be configured by the user. Registering an authentication method by a user is called enrollment. When a user account is created for the first time, the email OTP is automatically enrolled using the email information from the user data. Other authentication methods can be used by having the user enroll directly as needed.
I will explain the two authentication enrollment methods.
Register in Authentication Settings: User Portal > Profile > Authentication settings, click the + Add New button at the bottom to register.
Register on the Identity Verification Method Selection Screen: During login, for first-factor authentication and second-factor authentication, on the Identity Verification Method Selection screen, select the authentication method marked with a gray check mark (V) and register it.
Consent for collection/use of personal information
Consent for the collection and use of personal information is required when logging in with SingleID for the first time or during a certain period. According to the consent procedure, select the required, optional items to agree. Required items must be selected to log in.
Password authentication
Password is the most fundamental authentication method as SingleID’s default authentication tool.
Enter password
To log in using a user ID, follow the steps below.
Login screen > Account ID input field, enter the ID, and click the Next button.
Password field, enter your password, and click the Next button to log in.
Reference
If you click the eye-shaped icon in the password input field, you can view the password you entered.
Information
If you enter the password incorrectly
If the entered password is incorrect, you will see an error message and can try again.
The number of allowed retries is limited to the count set by the administrator in the password policy.
When the password is entered incorrectly repeatedly and becomes locked
If the password is entered incorrectly and the device becomes locked, you can unlock it using two methods.
Automatic unlock after 1~5 minutes: When automatic unlock is enabled, the account remains locked for 1~5 minutes. * Login will be available after that time.
Unlock with password reset: When the administrator configures the password policy to use password reset, a password reset is required. * You can log in after resetting your password.
Find ID you can view the detailed information there.
Email OTP authentication
Authenticate
To authenticate with email OTP, an OTP will be sent to the email address registered by the user.
To authenticate with an email OTP, follow the steps below.
In Identity verification selection method, click Email.
An OTP code will be sent to the registered email. 2. Enter the OTP within the time set by the administrator (usually 3~5 minutes).
After you enter, click the Confirm button, and the authentication will be completed.
Reference
Resend Code: If the input validity period has expired, click the resend code button. 1. Resend the OTP code via email.
Would you like to authenticate using a different method?: If the current authentication cannot be used, switch to a different authentication method.
If you changed your email, please register.: You can register (Enrollment) a different email and authenticate it according to admin settings.
You can view the details for registration at Register Email Authentication Tool.
guide
If the code is entered incorrectly
If the user enters the OTP code incorrectly, they can re-enter it up to the number of times specified by the administrator.
When locked due to exceeding the user input limit
If the OTP code is entered incorrectly more times than the administrator’s allowed limit, the screen will be locked from input for the duration set by the administrator. You can input after waiting for the specified duration. Refresh and try again after the input timeout.
SMS OTP authentication
Authenticate
To authenticate with SMS OTP, an SMS OTP is sent to the mobile device registered by the user.
To authenticate with an email OTP, follow the steps below.
In the Verification method selection, click Email.
An OTP code will be sent to the registered mobile phone. 2. Enter the OTP within the time set by the administrator (usually 3~5 minutes).
After entering, click the Confirm button, and the authentication will be completed.
Reference
Resend Code: If the input validity period has expired, click the resend code button. 1. Resend the OTP code to the mobile phone.
Would you like to authenticate using a different method?: If the current authentication cannot be used, switch to a different authentication method.
If you have changed your mobile phone, please register.: Click the link to go to the enrollment screen for the new mobile.
You can see the detailed information for registration at Register SMS authentication tool.
Information
If the code is entered incorrectly
If the user enters the OTP code incorrectly, they can re-enter it up to the number of times specified by the administrator.
When locked due to exceeding the user input limit
If the OTP code is entered incorrectly more times than the administrator’s allowed limit, the screen will be locked for the duration set by the administrator. You can input after waiting for the specified duration. Refresh and try again after the input timeout.
Knox Messenger OTP authentication
Authenticate
If you want to authenticate with Knox Messaenger OTP, the OTP will be sent to the Knox Messanger you are using.
To authenticate Knox Messenger OTP, follow the steps below.
In Identity verification selection method, click Knox Messenger.
The OTP code is sent via the Knox Messenger you are using. 2. Enter the OTP within the time set by the administrator (usually 3~5 minutes).
After entering, click the Confirm button, and the authentication will be completed.
Reference
Resend Code: If the input validity period has expired, click the resend code button. 1. Resend the OTP code to the mobile phone.
Would you like to authenticate using a different method?: If the current authentication cannot be used, switch to a different authentication method.
Would you like to use a different Knox ID?: Clicking the link will take you to the screen for enrolling a new Knox ID.
You can find detailed information about registration at Register Knox Messenger authentication tool.
information
If the code is entered incorrectly
If the user enters the OTP code incorrectly, they can re-enter it up to the number of times specified by the administrator.
When locked due to exceeding the user input limit
If the OTP code is entered incorrectly more times than the administrator’s allowed limit, the screen will be locked from input for the duration set by the administrator. You can input after waiting for the specified duration. Refresh and try again after the input timeout.
Knox Identity Password Authentication
Authenticate
To authenticate with Knox Identity, you must enter your Knox Identity password.
To authenticate with Knox Identity, follow the steps below.
In Verification selection method, click Knox Identity.
Enter the password for your Knox account.
After entering, click the Confirm button, and the authentication will be completed.
Reference
Would you like to authenticate using a different method?: If the current authentication cannot be used, switch to a different authentication method.
information
If the password is entered incorrectly
If the user enters the password incorrectly, they can re-enter it up to the number of attempts specified by the administrator.
When locked due to exceeding the user input limit
If the password is entered incorrectly more times than the administrator’s allowed limit, input on the screen will be restricted for the duration set by the administrator. You can input after waiting for the specified time. Refresh and try again after the input timeout.
SingleID Authenticator authentication
The SingleID service provides a mobile authentication app called SingleID Authenticator and offers authentication in various ways.
Authentication method
Authentication method
Explanation
SingleID Authenticator Bio
Send a push using the installed SingleID Authenticator mobile app on the device to request biometric authentication.
SingleID Authenticator PIN
Send a push using the installed SingleID Authenticator mobile app on the device to request authentication with a PIN code.
SingleID Authenticator TOTP
Send a push notification to the installed ID Authenticator mobile app on the device to request authentication via TOTP.
SingleID Authenticator mOTP
Send a push using the installed SingleID Authenticator mobile app on the device to request authentication with mOTP.
For installation and configuration of SingleID Authenticator, refer to SingleID Authenticator.
Detailed information on how to register the SingleID Authenticator authentication tool can be found at Register Authentication Tool.
Passkey authentication
The SingleID service provides simple authentication and multi-factor authentication using a Windows-based Passkey.
Authentication method
Convenient authentication: Provides easy login without ID/Password by using Sign in with Passkey at the bottom of the login page.
Multi-factor authentication: Offers convenient login without requiring ID/password during secondary authentication.
Authentication Types
Mobile Passkey: Scan the QR code to log in using Android and iOS mobile
Security key: Log in using the Windows security key
PIN: Login using the Windows PIN code
Reference
Passkey supported environment
Operating system (laptop or desktop)
Windows 11, macOS Ventura, ChromeOS 109 or later
Mobile phone: iOS 16 or Android 9 and above
Hardware security key: a hardware security key that supports the FIDO2 protocol
Browse version
Chrome 109 or later
Safari 16 or later
Edge 109
Device Settings
Enable Bluetooth
Set screen lock password
Register PIN code
Allow fingerprint or facial recognition
Reference
Passkey requires that Windows Hello be set up in advance. For detailed information, see the reference link.
Administrator authentication
Authenticate
In the SingleID service, the administrator provides authentication by delegating identity verification on behalf of the user.
To perform administrator authentication, follow the steps below.
In the Identity verification selection method, if you cannot perform identity verification at the bottom of the screen, you can request verification from the administrator. 1. Click here. Click it.
Click the Request button.
You will be taken to the admin selection screen. 3. Select the administrator who requested authentication delegation and click the Request button.
Authentication delegation is requested to the selected administrator.
When the administrator approves the authentication delegation, it is completed automatically.
Information
On the administrator selection screen, if the administrator is not assigned or has not registered a SingleID authenticator, a ‘Administrator Not Assigned’ screen appears.
information
If you cannot complete identity verification, you can request verification from the administrator. Click here** if the phrase is missing
The administrator has disabled the admin authentication delegation feature by policy. Please contact the administrator.
2 - Register authentication tool
Register authentication tool (Enrollment)
The principle is that users should register and use all authentication tools themselves. Registering an authentication tool by a user is called enrollment.
When a user is initially created, only the Email OTP is automatically registered using the user’s email information. The remaining information can be directly registered and used by the user as needed.
There are three ways to register.
Login screen > ID/Password entry > Select authentication method Register on the screen
On the authentication method selection screen, click the authentication tool marked as ‘Registration Required’ (gray check mark) to register.
Click the User Portal (after login) > Profile > Authentication Settings +Add New button to register.
Register through the registration message link at the bottom of every authentication screen.
The screen below is an example of an SMS verification screen. * You can register by clicking the ‘If you have changed your mobile phone, please register.’ message at the bottom.
All authentication codes can be changed via the message at the bottom (Message format: ~ please register.)
Figure. Authentication screen example
Register Email Verification Tool
Email registration consists of the following three steps.
Verification Step: This is the identity verification step before registering the email authentication tool.
Registration step: This step registers a new email and checks whether the number is valid.
Completion Stage: This is the final step to confirm that the registration was completed successfully.
Verification step
This is the step of verifying your identity before using the authentication tool. To view the identity verification process, please refer to 로그인하기.
Caution
In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.
Registration phase
This is the step where the user registers the desired email address and checks its validity.
The user should follow the steps below.
If you complete identity verification in the confirmation step, you will automatically proceed to the registration step.
Enter the email address you want to register.
Click the Send verification code button.
Check the OTP code sent to the email address you entered, and enter the OTP code on the screen.
If the verification code is entered correctly, you will proceed to the completion stage.
Completion stage
The registration completion screen will appear, and you can perform first- and second-factor authentication with the email verification tool on your next login.
Register SMS authentication tool
SMS registration consists of the following three steps.
Verification Step: This is the identity verification step before registering the SMS authentication tool.
Registration step: This step registers a new mobile phone number and checks whether the number is valid.
Completion Stage: This is the final step to confirm that the registration was completed successfully.
Verification step
This is the identity verification step before using the authentication tool. To view the identity verification process, please refer to Log in.
In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.
Registration Phase
This step registers the mobile phone number the user wants to add and checks its validity.
The user should follow the steps below.
If you complete identity verification in the confirmation step, you will automatically proceed to the registration step.
Select the country code and enter the mobile phone number you want to register.
Send verification code button, click it.
Check the OTP code sent to the mobile phone number you entered, and enter the OTP code on the screen.
If the verification code is entered correctly, you will proceed to the completion stage.
Completion Phase
Registration Complete screen will appear, and on the next login you can perform first and second factor authentication with the SMS authentication tool.
Register Knox Messenger authentication tool
Knox Messenger registration consists of the following three steps.
Verification step: This is the identity verification step before registering the Knox Messenger authentication tool.
Registration Step: Enter the Knox ID to register. 2. This is the step that checks whether the Knox ID to be registered is valid.
Completion Stage: This is the final step to confirm that the registration was completed successfully.
Check step
This is the step of identity verification before using the authentication tool. To view the identity verification process, please refer to 로그인하기.
In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.
Registration stage
This step registers the mobile phone number the user wants to add and checks its validity.
The user should follow the steps below.
If you complete identity verification in the confirmation step, you will automatically proceed to the registration step.
Please enter the Knox ID to register.
Click the Send verification code button.
Verify the OTP code sent to the Knox Messenger of the entered Knox ID, then enter the OTP code on the screen.
If the verification code is entered correctly, you will proceed to the completion stage.
Completion Phase
Registration Complete screen will appear, and on the next login you can perform first and second factor authentication using the Knox Messenger authentication tool.
Register Passkey authentication tool
The SingleID Authenticator is an authentication tool provided for the SingleID service.
Passkey enrollment consists of the following three steps.
Verification step: This is the identity verification step before registering the Passkey authentication tool.
Registration Stage: This is the Passkey registration stage.
Completion Stage: This is the final step to confirm that the registration was completed successfully.
Verification step
This is the step where you verify your identity before registering the authentication tool. To view the identity verification process, refer to 로그인 및 인증하기.
Information
In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.
Registration stage
This step verifies the mobile phone or PC environment where you want to register a Passkey.
Complete the registration process in the four steps below.
Activation: This is a guide to the Passkey-supported environment.
Confirm: Complete identity verification using an authentication method.
Registration: Passkey registration step. 3. When you click the Generate on this device button, a passkey is generated and registered on the PC. 3. Create on another device button click registers with a mobile phone or hardware security key.
Complete: This step confirms that Registration Complete. 4. Click the Continue button.
Reference
Passkey Support Environment
1.Operating system (laptop or desktop)
Windows 11, macOS Ventura, ChromeOS 109 or later
Mobile phone: iOS 16 or Android 9 and above
Hardware security key: a hardware security key that supports the FIDO2 protocol
Browse version
Chrome 109 or later
Safari 16 or later
Edge 109
Device Settings
Enable Bluetooth
Set screen lock password
Register PIN code
Allow fingerprint or facial recognition
Completion Phase
After the Passkey registration is completed, the Registration Complete screen appears. You can perform first- and second-factor authentication with the Windows Hello authentication tool on the next login.
Reference
PC Passkey requires that Windows Hello be configured in advance. Check the reference link for detailed information.
When registering a passkey on mobile, it can be set in an environment where QR code scanning is possible.
The SingleID Authenticator is an authentication tool provided for the SingleID service.
SingleID Authenticator enrollment consists of the following four steps.
Verification step: This is the identity verification step before registering the SingleID Authenticator authentication tool.
Installation Step: This is the user’s SingleID installation guide step.
Registration Stage: This step registers a new mobile app and registers the service.
Completion Stage: This is the final step to confirm that the registration was completed successfully.
Verification step
This is the step of verifying your identity before using the authentication tool. To view the identity verification process, please refer to 로그인하기.
Information
In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.
Installation Steps
There are three main ways to install the SingleID mobile app.
How to install SingleID Authenticator by scanning a QR code on the user’s mobile device or searching for SinlgeID on Google Play (for Android) or the App Store (for iOS).
How to install by entering your mobile phone number and receiving the download link via SMS
How to install using a manual download link
After installing the SingleID Authenticator app and clicking the Next button, you will proceed to the registration step.
Information
For security reasons, sending the download link via SMS to your mobile phone number is limited to a single transmission.
If you send more than three times within one minute, an error message stating “SMS messages cannot be sent multiple times for security reasons.” will be sent.
Please try again after a short while.
Registration stage
Install the SingleID Authenticator mobile app on the mobile phone you want to register, then launch SingleID Authenticator.
Complete the registration process in the three steps below.
Service Registration: In the SingleID Authenticator app, click the ‘+’ at the top.
Enter QR or authentication number: Scan the QR code or enter the authentication code to register.
Service registration complete: Click the Confirm button to complete the registration.
Completion Phase
After registration is completed in SingleID Authenticator, the Registration Complete screen appears. You can perform first- and second-factor authentication with the Windows Hello authentication tool on the next login.
Registration Phase
Install the SingleID Authenticator mobile app on the mobile phone you want to register, then launch SingleID Authenticator.
Complete the registration process in the three steps below.
Service Registration: In the SingleID Authenticator app, click the ‘+’ at the top.
Enter QR or authentication number: Scan the QR code or enter the authentication code to register.
Service registration complete: Click the Confirm button to complete the registration.
Completion Phase
After registration with SingleID Authenticator is completed, the Registration Complete screen appears. You can perform first- and second-factor authentication with the Windows Hello authentication tool on the next login.
TOTP Authenticator Register authentication tool
TOTP Authenticator registers third‑party TOTP to support various authentication tools.
TOTP Authenticator enrollment consists of the following four steps.
Verification step: This is the identity verification step before registering the SingleID Authenticator authentication tool.
Installation Step: This is the user’s SingleID installation guide step.
Registration Stage: This step registers a new mobile app and registers the service.
Completion Stage: This is the final step to confirm that the registration was completed successfully.
Check step
This step verifies your identity before using the authentication tool. To view the identity verification process, refer to Login and Authentication.
Information
In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.
Installation Steps
There are two main ways to install TOTP Authenticator.
Mobile app
Web browser extension
Click the Next button to go to the registration step.
Service Registration and Verification Phase
This step registers and verifies the 3rd Party TOTP Authenticator you want to add.
Complete the registration process in the two steps below.
Service Registration: Scan the QR code of the TOTP Authenticator you want to register, or enter the manual code. 1. The code registration is completed in the TOTP mobile app or extension.
Service verification: Run the TOTP mobile app or extension, and enter the OTP.
Guide
TOTP Authenticator support
SingleID supports a variety of standardized 3rd‑party TOTP authentication apps. Non-standard TOTP is not supported.
The authenticated mobile and extension programs are listed below. We recommend the mobile app or extension below.
Mobile app
Google Authenticator, Microsoft Authenticator
Web browser extension
TOTP extension searchable in the Chrome Web Store and Microsoft Edge Add-ons
Information
To register a new TOTP Authenticator, on the TOTP Authenticator OTP entry screen.
Click the “If you want to change your TOTP Authenticator, register here” at the bottom to register a new TOTP Authenticator.
Information
Check device information
When the user clicks on device information such as password, SMS, email, SingleID authenticator, Nox messenger, passkey, etc., detailed information can be viewed in a popup.
Device Information popup displays ’type’, ‘OS version’, ‘browser’, ‘IP’, etc.
3 - Configure Privacy Settings
Configure Privacy Settings
This is a menu for user settings.
To set your privacy preferences, follow these steps.
Click the Personal Profile > Personal Information setting at the top right of the screen.
You can view the photo, name, email, phone number, language, and time zone.
Image: Image > Image Click Change to upload the icon image you want to display.
Language: Choose your desired language in Korean or English.
Language/Time Zone: Please select the time zone you are currently in. Click the City Search button to open the city search popup. Search for the desired city in English and select it.
Click the Save button at the bottom of the screen to save.
Reference
If you click the Delete button at the lower left of the privacy screen, you can delete the current user account.
If you delete your account, it will be permanently removed, so please only proceed with withdrawal if you truly wish to delete it.
Configure Authentication
You can register a user’s authentication tool and set the preferred authentication tool.
To configure authentication, follow these steps.
Click the Personal Profile > Authentication setting at the top right of the screen.
+Add New button: click to add using the authentication tool of your choice.
Click the Delete button to remove the authentication tool you do not wish to use.
Star (☆) Click the icon to set your preferred authentication method.
Reference
For instructions on how users register or delete authentication tools, please refer to Register Authentication Tools.
Change Password
In the authentication settings, click Change Password to complete an identity verification process and update your password.
Check login history
You can view the user’s login history and environment.
To view a user’s login history/environment, follow these steps.
Click Personal Profile > Login History/Environment at the top right of the screen.
In the Login History tab, you can view information such as login date and time, location, country, city, IP address, OS type, browser type, detection status, and result.
In the Login Environment tab, you can view the details of any registered login environments, and if an environment is no longer used, you can delete it via the ‘Delete’ button.
When using the SingleID ADM (Anomaly Detection Management) feature
The detection items will display Normal or Detected. This entry represents a login record where abnormal authentication activity was detected.
Log out
Click the photo icon located at the top right of the screen and then click ‘Logout’.
When you click the Logout button, all applications visited through SingleID are logged out simultaneously, and if integrated logout is configured via the PC SSO Agent, logout also proceeds in the associated browsers.