This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

MFA Portal

Overview

SingleID’s MFA service provides users with a variety of additional second-factor authentication services through system integration, while maintaining the authentication system used by applications to enhance security. Additionally, SingleID provides an MFA Portal that lets you pre‑register and manage your preferred authentication methods for authentication, allowing convenient configuration.

The MFA Portal manual provides a feature that allows users to self-register secondary multi-factor authentication.

For detailed information, refer to the items below.

SingleID language settings

  • User portal screen > top language selection, choose the language you want from ‘Korean’ or ‘English’.
  • It will be changed to the language you selected.
Reference
On the first login, it is presented in the language configured in the user’s browser. If the language is other than Korean or English, it will be set to English.

SingleID connection environment and support

CategorySupportRecommendation
PCWindows : Windows Desktop 10 and 11 (x86 and x64 CPU Only)
  • Web Browser: Microsoft Edge, Latest public version
Windows : Windows Desktop 10 and 11 (x86 and x64 CPU Only)
  • Web Browser: Microsoft Edge 88.x or later, Chrome 87.x or later
Moblie(Android)Android : 8 and later versions
  • Web Browser: Samsung Internet Latest public version
Android : 8 and later versions
  • Models released in 2018 and beyond among Samsung Galaxy Mobile Products
  • Galaxy S9 ↑
  • Web Browser: Samsung Internet 9.0 ↑
Moblie(iOS)iOS : 16 ,17
  • Web Browser: Safari , Latest public version
iOS : 16 ,17
  • iPhone Xs ↑, Models released in 2018 and beyond among Apple iPhone Products
  • Web Browser: Safari 14.1 ↑
Table. SingleID connection environment support scope and recommended specifications

1 - Log in using an authentication method

Log in using an authentication method

What is an authentication method?

Authentication method, commonly called Authenticator, refers to an authentication tool.

SingleID provides the following 11 authentication methods for user authentication.

  • Password: Enter password on the SingleID login screen
  • Email OTP: Send the OTP via email and enter the OTP on the SingleID login screen
  • SMS OTP: Send OTP via SMS and enter the OTP on the SingleID login screen
  • Knox Messenger OTP: Send OTP via Knox Messenger and enter OTP on the SingleID login screen
  • Knox Identity: Knox Portal user ID password authentication integration
  • SingleID Authenticator Bio: Install the dedicated SingleID mobile app and link authentication using biometric authentication (fingerprint, facial recognition)
  • SingleID Authenticator PIN: Install the SingleID‑dedicated mobile app and link authentication with a PIN.
  • SingleID Authenticator mOTP: Install the SingleID‑exclusive mobile app and integrate authentication with mOTP (Mobile OTP).
  • SingleID Authenticator TOTP: Install the SingleID‑dedicated mobile app and integrate authentication with TOTP(Time base OTP).
  • Passkey: Login and authentication using biometrics (fingerprint, facial), mobile, or PIN code without a password, based on Windows Hello.
  • Admin Authentication: If the admin permits direct authentication, request authentication on the admin’s behalf
Reference
SingleID Authenticator If this is your first time using the SingleID Authenticator mobile app, please refer to SingleID Authenticator.

Setting the preferred authentication method

The user logs into the User Portal provided by SingleID and sets their preferred primary and secondary authentication methods.

If the user sets their preferred method, the screen for selecting a verification method is skipped during login and authentication, allowing immediate authentication using the primary and secondary methods.

If you want to set your preferred authentication method, follow the steps below.

  1. User Portal > Personal Profile > Authentication settings, click.
  2. Click the star (☆) for each of your preferred 1st authentication method, 2nd authentication method.

After the configuration is complete, the next login will use this method, offering convenient access.

Information
Even if users set their preferred authentication methods for primary and secondary authentication, administrators can restrict them to specific authentication methods through login policy settings.

Register authentication tool

All authentication methods can be configured by the user. Registering an authentication method by a user is called enrollment. When a user account is created for the first time, the email OTP is automatically enrolled using the email information from the user data. Other authentication methods can be used by having the user enroll directly as needed.

I will explain the two authentication enrollment methods.

  • Register in Authentication Settings: User Portal > Profile > Authentication settings, click the + Add New button at the bottom to register.
  • Register on the Identity Verification Method Selection Screen: During login, for first-factor authentication and second-factor authentication, on the Identity Verification Method Selection screen, select the authentication method marked with a gray check mark (V) and register it.
Reference
Refer to Register authentication tool for enrollment.

First login

Consent for collection/use of personal information

Consent for the collection and use of personal information is required when logging in with SingleID for the first time or during a certain period. According to the consent procedure, select the required, optional items to agree. Required items must be selected to log in.

Password authentication

Password is the most fundamental authentication method as SingleID’s default authentication tool.

Enter password

To log in using a user ID, follow the steps below.

  1. Login screen > Account ID input field, enter the ID, and click the Next button.
  2. Password field, enter your password, and click the Next button to log in.
Reference
If you click the eye-shaped icon in the password input field, you can view the password you entered.
Information

If you enter the password incorrectly

If the entered password is incorrect, you will see an error message and can try again. The number of allowed retries is limited to the count set by the administrator in the password policy.

When the password is entered incorrectly repeatedly and becomes locked

If the password is entered incorrectly and the device becomes locked, you can unlock it using two methods.

  • Automatic unlock after 1~5 minutes: When automatic unlock is enabled, the account remains locked for 1~5 minutes. * Login will be available after that time.
  • Unlock with password reset: When the administrator configures the password policy to use password reset, a password reset is required. * You can log in after resetting your password. Find ID you can view the detailed information there.

Email OTP authentication

Authenticate

To authenticate with email OTP, an OTP will be sent to the email address registered by the user.

To authenticate with an email OTP, follow the steps below.

  1. In Identity verification selection method, click Email.
  2. An OTP code will be sent to the registered email. 2. Enter the OTP within the time set by the administrator (usually 3~5 minutes).
  3. After you enter, click the Confirm button, and the authentication will be completed.
Reference
  1. Resend Code: If the input validity period has expired, click the resend code button. 1. Resend the OTP code via email.
  2. Would you like to authenticate using a different method?: If the current authentication cannot be used, switch to a different authentication method.
  3. If you changed your email, please register.: You can register (Enrollment) a different email and authenticate it according to admin settings. You can view the details for registration at Register Email Authentication Tool.
guide

If the code is entered incorrectly

If the user enters the OTP code incorrectly, they can re-enter it up to the number of times specified by the administrator.

When locked due to exceeding the user input limit

If the OTP code is entered incorrectly more times than the administrator’s allowed limit, the screen will be locked from input for the duration set by the administrator. You can input after waiting for the specified duration. Refresh and try again after the input timeout.

SMS OTP authentication

Authenticate

To authenticate with SMS OTP, an SMS OTP is sent to the mobile device registered by the user.

To authenticate with an email OTP, follow the steps below.

  1. In the Verification method selection, click Email.
  2. An OTP code will be sent to the registered mobile phone. 2. Enter the OTP within the time set by the administrator (usually 3~5 minutes).
  3. After entering, click the Confirm button, and the authentication will be completed.
Reference
  1. Resend Code: If the input validity period has expired, click the resend code button. 1. Resend the OTP code to the mobile phone.
  2. Would you like to authenticate using a different method?: If the current authentication cannot be used, switch to a different authentication method.
  3. If you have changed your mobile phone, please register.: Click the link to go to the enrollment screen for the new mobile. You can see the detailed information for registration at Register SMS authentication tool.
Information

If the code is entered incorrectly

If the user enters the OTP code incorrectly, they can re-enter it up to the number of times specified by the administrator.

When locked due to exceeding the user input limit

If the OTP code is entered incorrectly more times than the administrator’s allowed limit, the screen will be locked for the duration set by the administrator. You can input after waiting for the specified duration. Refresh and try again after the input timeout.

Knox Messenger OTP authentication

Authenticate

If you want to authenticate with Knox Messaenger OTP, the OTP will be sent to the Knox Messanger you are using.

To authenticate Knox Messenger OTP, follow the steps below.

  1. In Identity verification selection method, click Knox Messenger.
  2. The OTP code is sent via the Knox Messenger you are using. 2. Enter the OTP within the time set by the administrator (usually 3~5 minutes).
  3. After entering, click the Confirm button, and the authentication will be completed.
Reference
  1. Resend Code: If the input validity period has expired, click the resend code button. 1. Resend the OTP code to the mobile phone.
  2. Would you like to authenticate using a different method?: If the current authentication cannot be used, switch to a different authentication method.
  3. Would you like to use a different Knox ID?: Clicking the link will take you to the screen for enrolling a new Knox ID. You can find detailed information about registration at Register Knox Messenger authentication tool.
information

If the code is entered incorrectly

If the user enters the OTP code incorrectly, they can re-enter it up to the number of times specified by the administrator.

When locked due to exceeding the user input limit

If the OTP code is entered incorrectly more times than the administrator’s allowed limit, the screen will be locked from input for the duration set by the administrator. You can input after waiting for the specified duration. Refresh and try again after the input timeout.

Knox Identity Password Authentication

Authenticate

To authenticate with Knox Identity, you must enter your Knox Identity password.

To authenticate with Knox Identity, follow the steps below.

  1. In Verification selection method, click Knox Identity.
  2. Enter the password for your Knox account.
  3. After entering, click the Confirm button, and the authentication will be completed.
Reference
Would you like to authenticate using a different method?: If the current authentication cannot be used, switch to a different authentication method.
information

If the password is entered incorrectly

If the user enters the password incorrectly, they can re-enter it up to the number of attempts specified by the administrator.

When locked due to exceeding the user input limit

If the password is entered incorrectly more times than the administrator’s allowed limit, input on the screen will be restricted for the duration set by the administrator. You can input after waiting for the specified time. Refresh and try again after the input timeout.

SingleID Authenticator authentication

The SingleID service provides a mobile authentication app called SingleID Authenticator and offers authentication in various ways.

Authentication method

Authentication methodExplanation
SingleID Authenticator BioSend a push using the installed SingleID Authenticator mobile app on the device to request biometric authentication.
SingleID Authenticator PINSend a push using the installed SingleID Authenticator mobile app on the device to request authentication with a PIN code.
SingleID Authenticator TOTPSend a push notification to the installed ID Authenticator mobile app on the device to request authentication via TOTP.
SingleID Authenticator mOTPSend a push using the installed SingleID Authenticator mobile app on the device to request authentication with mOTP.
Table. SingleID Authenticator authentication method
Reference

Passkey authentication

The SingleID service provides simple authentication and multi-factor authentication using a Windows-based Passkey.

Authentication method

  1. Convenient authentication: Provides easy login without ID/Password by using Sign in with Passkey at the bottom of the login page.
  2. Multi-factor authentication: Offers convenient login without requiring ID/password during secondary authentication.

Authentication Types

  • Mobile Passkey: Scan the QR code to log in using Android and iOS mobile
  • Security key: Log in using the Windows security key
  • PIN: Login using the Windows PIN code
Reference

Passkey supported environment Operating system (laptop or desktop)

  • Windows 11, macOS Ventura, ChromeOS 109 or later
  • Mobile phone: iOS 16 or Android 9 and above
  • Hardware security key: a hardware security key that supports the FIDO2 protocol

Browse version

  • Chrome 109 or later
  • Safari 16 or later
  • Edge 109

Device Settings

  • Enable Bluetooth
  • Set screen lock password
  • Register PIN code
  • Allow fingerprint or facial recognition
Reference
Passkey requires that Windows Hello be set up in advance. For detailed information, see the reference link.

Administrator authentication

Authenticate

In the SingleID service, the administrator provides authentication by delegating identity verification on behalf of the user.

To perform administrator authentication, follow the steps below.

  1. In the Identity verification selection method, if you cannot perform identity verification at the bottom of the screen, you can request verification from the administrator. 1. Click here. Click it.
  2. Click the Request button.
  3. You will be taken to the admin selection screen. 3. Select the administrator who requested authentication delegation and click the Request button.
  4. Authentication delegation is requested to the selected administrator.
  5. When the administrator approves the authentication delegation, it is completed automatically.
Information
On the administrator selection screen, if the administrator is not assigned or has not registered a SingleID authenticator, a ‘Administrator Not Assigned’ screen appears.
information
If you cannot complete identity verification, you can request verification from the administrator. Click here** if the phrase is missing The administrator has disabled the admin authentication delegation feature by policy. Please contact the administrator.

2 - Register authentication tool

Register authentication tool (Enrollment)

The principle is that users should register and use all authentication tools themselves. Registering an authentication tool by a user is called enrollment. When a user is initially created, only the Email OTP is automatically registered using the user’s email information. The remaining information can be directly registered and used by the user as needed.

There are three ways to register.

  1. Login screen > ID/Password entry > Select authentication method Register on the screen
    • On the authentication method selection screen, click the authentication tool marked as ‘Registration Required’ (gray check mark) to register.
  2. Click the User Portal (after login) > Profile > Authentication Settings +Add New button to register.
  3. Register through the registration message link at the bottom of every authentication screen.
    • The screen below is an example of an SMS verification screen. * You can register by clicking the ‘If you have changed your mobile phone, please register.’ message at the bottom.
    • All authentication codes can be changed via the message at the bottom (Message format: ~ please register.)
Diagram
Figure. Authentication screen example

Register Email Verification Tool

Email registration consists of the following three steps.

  1. Verification Step: This is the identity verification step before registering the email authentication tool.
  2. Registration step: This step registers a new email and checks whether the number is valid.
  3. Completion Stage: This is the final step to confirm that the registration was completed successfully.

Verification step

This is the step of verifying your identity before using the authentication tool. To view the identity verification process, please refer to 로그인하기.

Caution
In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.

Registration phase

This is the step where the user registers the desired email address and checks its validity.

The user should follow the steps below.

  1. If you complete identity verification in the confirmation step, you will automatically proceed to the registration step.
  2. Enter the email address you want to register.
  3. Click the Send verification code button.
  4. Check the OTP code sent to the email address you entered, and enter the OTP code on the screen.
  5. If the verification code is entered correctly, you will proceed to the completion stage.

Completion stage

The registration completion screen will appear, and you can perform first- and second-factor authentication with the email verification tool on your next login.

Register SMS authentication tool

SMS registration consists of the following three steps.

  1. Verification Step: This is the identity verification step before registering the SMS authentication tool.
  2. Registration step: This step registers a new mobile phone number and checks whether the number is valid.
  3. Completion Stage: This is the final step to confirm that the registration was completed successfully.

Verification step

This is the identity verification step before using the authentication tool. To view the identity verification process, please refer to Log in.

In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.

Registration Phase

This step registers the mobile phone number the user wants to add and checks its validity.

The user should follow the steps below.

  1. If you complete identity verification in the confirmation step, you will automatically proceed to the registration step.
  2. Select the country code and enter the mobile phone number you want to register.
  3. Send verification code button, click it.
  4. Check the OTP code sent to the mobile phone number you entered, and enter the OTP code on the screen.
  5. If the verification code is entered correctly, you will proceed to the completion stage.

Completion Phase

Registration Complete screen will appear, and on the next login you can perform first and second factor authentication with the SMS authentication tool.

Register Knox Messenger authentication tool

Knox Messenger registration consists of the following three steps.

  1. Verification step: This is the identity verification step before registering the Knox Messenger authentication tool.
  2. Registration Step: Enter the Knox ID to register. 2. This is the step that checks whether the Knox ID to be registered is valid.
  3. Completion Stage: This is the final step to confirm that the registration was completed successfully.

Check step

This is the step of identity verification before using the authentication tool. To view the identity verification process, please refer to 로그인하기.

In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.

Registration stage

This step registers the mobile phone number the user wants to add and checks its validity.

The user should follow the steps below.

  1. If you complete identity verification in the confirmation step, you will automatically proceed to the registration step.
  2. Please enter the Knox ID to register.
  3. Click the Send verification code button.
  4. Verify the OTP code sent to the Knox Messenger of the entered Knox ID, then enter the OTP code on the screen.
  5. If the verification code is entered correctly, you will proceed to the completion stage.

Completion Phase

Registration Complete screen will appear, and on the next login you can perform first and second factor authentication using the Knox Messenger authentication tool.

Register Passkey authentication tool

The SingleID Authenticator is an authentication tool provided for the SingleID service.

Passkey enrollment consists of the following three steps.

  1. Verification step: This is the identity verification step before registering the Passkey authentication tool.
  2. Registration Stage: This is the Passkey registration stage.
  3. Completion Stage: This is the final step to confirm that the registration was completed successfully.

Verification step

This is the step where you verify your identity before registering the authentication tool. To view the identity verification process, refer to 로그인 및 인증하기.

Information
In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.

Registration stage

This step verifies the mobile phone or PC environment where you want to register a Passkey.

Complete the registration process in the four steps below.

  1. Activation: This is a guide to the Passkey-supported environment.
  2. Confirm: Complete identity verification using an authentication method.
  3. Registration: Passkey registration step. 3. When you click the Generate on this device button, a passkey is generated and registered on the PC. 3. Create on another device button click registers with a mobile phone or hardware security key.
  4. Complete: This step confirms that Registration Complete. 4. Click the Continue button.
Reference

Passkey Support Environment 1.Operating system (laptop or desktop)

  • Windows 11, macOS Ventura, ChromeOS 109 or later
  • Mobile phone: iOS 16 or Android 9 and above
  • Hardware security key: a hardware security key that supports the FIDO2 protocol

Browse version

  • Chrome 109 or later
  • Safari 16 or later
  • Edge 109

Device Settings

  • Enable Bluetooth
  • Set screen lock password
  • Register PIN code
  • Allow fingerprint or facial recognition

Completion Phase

After the Passkey registration is completed, the Registration Complete screen appears. You can perform first- and second-factor authentication with the Windows Hello authentication tool on the next login.

Reference

PC Passkey requires that Windows Hello be configured in advance. Check the reference link for detailed information.

When registering a passkey on mobile, it can be set in an environment where QR code scanning is possible.

SingleID Authenticator Register authentication tool

The SingleID Authenticator is an authentication tool provided for the SingleID service.

SingleID Authenticator enrollment consists of the following four steps.

  1. Verification step: This is the identity verification step before registering the SingleID Authenticator authentication tool.
  2. Installation Step: This is the user’s SingleID installation guide step.
  3. Registration Stage: This step registers a new mobile app and registers the service.
  4. Completion Stage: This is the final step to confirm that the registration was completed successfully.

Verification step

This is the step of verifying your identity before using the authentication tool. To view the identity verification process, please refer to 로그인하기.

Information
In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.

Installation Steps

There are three main ways to install the SingleID mobile app.

  • How to install SingleID Authenticator by scanning a QR code on the user’s mobile device or searching for SinlgeID on Google Play (for Android) or the App Store (for iOS).
  • How to install by entering your mobile phone number and receiving the download link via SMS
  • How to install using a manual download link After installing the SingleID Authenticator app and clicking the Next button, you will proceed to the registration step.
Information
For security reasons, sending the download link via SMS to your mobile phone number is limited to a single transmission. If you send more than three times within one minute, an error message stating “SMS messages cannot be sent multiple times for security reasons.” will be sent. Please try again after a short while.

Registration stage

Install the SingleID Authenticator mobile app on the mobile phone you want to register, then launch SingleID Authenticator.

Complete the registration process in the three steps below.

  1. Service Registration: In the SingleID Authenticator app, click the ‘+’ at the top.
  2. Enter QR or authentication number: Scan the QR code or enter the authentication code to register.
  3. Service registration complete: Click the Confirm button to complete the registration.

Completion Phase

After registration is completed in SingleID Authenticator, the Registration Complete screen appears. You can perform first- and second-factor authentication with the Windows Hello authentication tool on the next login.

Registration Phase

Install the SingleID Authenticator mobile app on the mobile phone you want to register, then launch SingleID Authenticator.

Complete the registration process in the three steps below.

  1. Service Registration: In the SingleID Authenticator app, click the ‘+’ at the top.
  2. Enter QR or authentication number: Scan the QR code or enter the authentication code to register.
  3. Service registration complete: Click the Confirm button to complete the registration.

Completion Phase

After registration with SingleID Authenticator is completed, the Registration Complete screen appears. You can perform first- and second-factor authentication with the Windows Hello authentication tool on the next login.

TOTP Authenticator Register authentication tool

TOTP Authenticator registers third‑party TOTP to support various authentication tools.

TOTP Authenticator enrollment consists of the following four steps.

  1. Verification step: This is the identity verification step before registering the SingleID Authenticator authentication tool.
  2. Installation Step: This is the user’s SingleID installation guide step.
  3. Registration Stage: This step registers a new mobile app and registers the service.
  4. Completion Stage: This is the final step to confirm that the registration was completed successfully.

Check step

This step verifies your identity before using the authentication tool. To view the identity verification process, refer to Login and Authentication.

Information
In the verification stage, the authentication method to be used can only be performed with the authentication tool configured by the administrator.

Installation Steps

There are two main ways to install TOTP Authenticator.

  • Mobile app
  • Web browser extension

Click the Next button to go to the registration step.

Service Registration and Verification Phase

This step registers and verifies the 3rd Party TOTP Authenticator you want to add.

Complete the registration process in the two steps below.

  1. Service Registration: Scan the QR code of the TOTP Authenticator you want to register, or enter the manual code. 1. The code registration is completed in the TOTP mobile app or extension.
  2. Service verification: Run the TOTP mobile app or extension, and enter the OTP.
Guide

TOTP Authenticator support SingleID supports a variety of standardized 3rd‑party TOTP authentication apps. Non-standard TOTP is not supported. The authenticated mobile and extension programs are listed below. We recommend the mobile app or extension below.

  • Mobile app
    • Google Authenticator, Microsoft Authenticator
  • Web browser extension
    • TOTP extension searchable in the Chrome Web Store and Microsoft Edge Add-ons
Information
To register a new TOTP Authenticator, on the TOTP Authenticator OTP entry screen. Click the “If you want to change your TOTP Authenticator, register here” at the bottom to register a new TOTP Authenticator.
Information
Check device information When the user clicks on device information such as password, SMS, email, SingleID authenticator, Nox messenger, passkey, etc., detailed information can be viewed in a popup. Device Information popup displays ’type’, ‘OS version’, ‘browser’, ‘IP’, etc.

3 - Configure Privacy Settings

Configure Privacy Settings

This is a menu for user settings.

To set your privacy preferences, follow these steps.

  1. Click the Personal Profile > Personal Information setting at the top right of the screen.
  2. You can view the photo, name, email, phone number, language, and time zone.
  3. Image: Image > Image Click Change to upload the icon image you want to display.
  4. Language: Choose your desired language in Korean or English.
  5. Language/Time Zone: Please select the time zone you are currently in. Click the City Search button to open the city search popup. Search for the desired city in English and select it.
  6. Click the Save button at the bottom of the screen to save.
Reference
If you click the Delete button at the lower left of the privacy screen, you can delete the current user account. If you delete your account, it will be permanently removed, so please only proceed with withdrawal if you truly wish to delete it.

Configure Authentication

You can register a user’s authentication tool and set the preferred authentication tool.

To configure authentication, follow these steps.

  1. Click the Personal Profile > Authentication setting at the top right of the screen.
  2. +Add New button: click to add using the authentication tool of your choice.
  3. Click the Delete button to remove the authentication tool you do not wish to use.
  4. Star (☆) Click the icon to set your preferred authentication method.
Reference
For instructions on how users register or delete authentication tools, please refer to Register Authentication Tools.

Change Password

In the authentication settings, click Change Password to complete an identity verification process and update your password.

Check login history

You can view the user’s login history and environment.

To view a user’s login history/environment, follow these steps.

  1. Click Personal Profile > Login History/Environment at the top right of the screen.
  2. In the Login History tab, you can view information such as login date and time, location, country, city, IP address, OS type, browser type, detection status, and result.
  3. In the Login Environment tab, you can view the details of any registered login environments, and if an environment is no longer used, you can delete it via the ‘Delete’ button.
guide
Check the country ISO codes at the link below. Refer to the method at ISO 3166 - Wikipedia, the free encyclopedia.
guide
When using the SingleID ADM (Anomaly Detection Management) feature The detection items will display Normal or Detected. This entry represents a login record where abnormal authentication activity was detected.

Log out

Click the photo icon located at the top right of the screen and then click ‘Logout’.

When you click the Logout button, all applications visited through SingleID are logged out simultaneously, and if integrated logout is configured via the PC SSO Agent, logout also proceeds in the associated browsers.