2FA - Microsoft Authenticator App as well as text codes
With the implementation of 2FA and codes sent via text for access, are we able to suggest as an option the Microsoft Authenticator App as well?
We're pleased to advise that you can now setup multiple authentication methods for accessing Property Tree such as Google Authenticator, Okta Verify, and Biometrics (Face recognition/fingerprint access) alongside SMS. We strongly recommend having more than one form of authentication configured, and you can choose which one to use when logging in or making account changes in Property Tree. Thank you for your patience as we rolled out the new login process. Check out the Multifactor Authentication Options to learn more about the MFA options available or Change Multifactor Authentication to learn how to update your factors.
-
Eleni Louglos commented
Agree on the email verification - text verification isn't helpful when working from overseas for a period of time.
-
Jerry Ji commented
Please link my account to my devices so i will no need the code everytime.
-
Heidi Kilborn commented
Agree another option should be available for 2FA, whether it is through an app or email as cannot access PT when mobile service is down (which unfortunately does still happen).
-
Helen Rolfe commented
this would be much easier then having to wait for a text message to come through as could just use the app
-
Hoi Man Wong commented
Cancel phone verification and introduce email verification instead. Sometimes when we are in oversea we will not able to receive message by SMS but we can access to our email.
-
Voltaire Taguinod commented
PT 2FA needs to have (note: "must have", not "nice to have") at least two options for receiving OTP codes, not just one.
E.g. if my phone has been stolen and compromised, my next course of action would be to reset my password. However, since PT only provides 2FA via SMS, I am unable to change my password (since my phone was stolen). On the other hand, the bad actor can now reset my password since he has access to my phone.
Any software company worth their salt implement MFA by giving other options to receive OTP.
PT needs to be modified as below.
I am unable to access my SMS, send me the code another way:
1. via email
2. via Authenticator App (either Google or Microsoft) -
Sandra Tan commented
Our remote team members have been facing issues receiving the 2FA code. They were unable to login for hours. It is really such a hassle and inefficient.
-
Andrea Topouzakis commented
When generating the one time code it would be great if it had the option for this code to be sent to either a mobile or an email
-
Rene Poulos commented
Hi I was concerned about being overseas and not being able to access the SMS but it has not been an issue.
We are with TELSTRA and SMS messages come through at no charge with roaming off. -
Sue Owen commented
Strongly suggest the 2Fa be amended to include either an Authenticator via goodle or Microsoft and an email authentication option.
The recent vodafone outage has shown up a serious flaw in the process that needs to be fixed asap.
As a sole trader with no one else in the office, I have but one phone and an ipad both on the same network. Having 2fa rely solely on a phone number is a serious issue that needs recitfying as a mater of urgency.
Whilst I was not locked not for long, I have to ask what happens on a weekend when there is no support?.
Support had the audacity to suggest it was a 'vodafone' issue. Actually NO it is a Property Tree issue as there are no alternatives for people with only one phone number!! that is a serious business continuity issue for me and a serious defect in the introduction of a new 'feature' in Property Tree !!!! -
APG Accts commented
Other software providers provide dual 2FA such that codes are sent immediately to both options, normally being email and mobile which operate on different platforms. Alternatively, provide a choice to choose the format for receiving the one-time code, i.e. either by email or by mobile. Best yet, allow the user the option to turn off the 2FA. Just relying on one method of presenting the 2FA does not provide a failsafe approach, and like today, I was unable to log in for 1 hour. you are not going to compensate me for lost time.
-
Matthew Leigh commented
TOTP is absolutely vital here, especially with the recent history of data breaches. SMS is too easily spoofed. There are many examples of how to do this for your developers to use, depending on what framework PropertyTree is built on.
-
Teresa Anderson commented
Totally agree with this comment as well.
2FA absolutely needs an email or app authorisation option such as Authy. Overseas team members are present in most agencies with scale and aren't walking around the streets of manila with a company mobile phone. -
Daniel Brennan commented
2FA absolutely needs an email or app authorisation option such as Authy. Overseas team members are present in most agencies with scale and aren't walking around the streets of manila with a company mobile phone.
-
Karen Kelly commented
I'd just like to suggest that the sign in text messages have a second option of email as there are multiple issues such as what happens if you forget your phone, office staff don't have a phone or when the senior property manager is away and someone else is manning my phone I then can't access PT.
-
Kerrie Lee commented
Link Routine Inspections to the Property Management Profile or to the Property - so we can more easily audit routine inspections via our Portfolio.
-
Tegan Darcy commented
I agree, as a company with offshore team members we have the issue. It's surprising this was not considered but PT before the decision to make 2FA mandatory.
-
Derek Lee commented
2FA by SMS is outdated. A quick google search shows how impractical, unreliable and insecure it is. Making it the only option for login is not an update, it is a downgrade to last decade's technology!
-
Derek Lee commented
2FA by SMS is outdated. A quick google search shows how impractical, unreliable and insecure it is. Making it the only option for login is not an update, it is a downgrade to last decade's technology!
-
Alison Mansell commented
Either email or an app such as Duo Mobile to allow for push notifications, without it being a small office and owner I can effectivly no longer go on holidays, as there is no one to take my place and i work remotely while away, alot of the time without phone service