Applying Multi-Factor Authentication for specific users via User Management


Background

Bentley offers free to use MFA utilizing Ping ID services. Until now Bentley offered MFA to be enforced on specific domains only. From now on Admins and co-admin are able to apply MFA on a specific user within User Management.

InformationImportant: The feature described below is not yet generally available but can be enabled on a per-organization basis. If interested in using this feature, please file an IMS Multi-Factor Authentication (MFA) request.

Enabling MFA for organization

Before Administrator can apply MFA to a specific user, 2FA for account must be enabled in User Management.
•    Go to User Management -> Domains (1)
•    Select 'Account' (2)
•    Click 'Enable 2FA' (3)

 
Once 2FA for account is enabled:
•    Go to 'Organization users and roles' (1)
•    Search for user to which MFA should apply (2)
•    Click on the slider under 'Two-Factor' column to enable 2FA (3)
  
•    Confirm your choice

  
On your next login, you'll be prompted to enrol in MFA. For more details, please review this KB:
https://bentleysystems.service-now.com/community?id=kb_article_view&sysparm_article=KB0018783