Manage two-factor authentication for an organization

Administrators manage CrashPlan two-factor authentication (2FA) in two ways: by turning it on or off for an organization, and by resetting it for an individual user.

The CrashPlan 2FA setting applies to users who sign in with a CrashPlan account password, including accounts listed as local users in an organization that uses single sign-on (SSO). Users who sign in with SSO get any multi-factor requirement from their identity provider. The verification methods and the users 2FA applies to are described in How two-factor authentication works in CrashPlan.

New CrashPlan accounts begin with 2FA turned off. We recommend turning it on for every organization whose users sign in with a CrashPlan account password.

Requirements

Managing CrashPlan 2FA requires one of the following roles, depending on the task:

  • To turn 2FA on or off: The Customer Cloud Admin role, or the Multi-Factor Auth Admin role together with a role that can change organization settings, such as Org Admin or Cross Org Admin.
  • To reset 2FA for a user: A role that can manage that user, such as Org Admin.

The permissions each CrashPlan role grants are listed in the User Roles reference.

Before you turn 2FA on or off

Turning CrashPlan 2FA on or off for an organization changes how every user in it signs in, so communicate the change to affected users before you save it. When accounts only have a single organization, the setting applies to every user on the account.

  • Turning 2FA on: Each user sets up 2FA during their next sign-in. Users already signed in to the CrashPlan console stay signed in until they sign out, and the CrashPlan app stays signed in and keeps backing up.
  • Turning 2FA off: Every user's 2FA configuration is removed. If you turn 2FA on again later, every user sets it up again.

Turning 2FA on stops CrashPlan API scripts and integrations that use basic authentication as a user in the organization. Move them to a token authentication method, as described in CrashPlan API authentication methods, before you turn 2FA on.

Turn 2FA on or off for an organization

CrashPlan 2FA is an organization setting on the Security tab of the organization in the CrashPlan console.

  1. Sign in to the CrashPlan console.
  2. Navigate to Administration > Environment > Organizations.
  3. Click the organization.
  4. From the action menu Action menu icon, select Edit.
  5. Select the Security tab and go to the Local two-factor Authentication section.
  6. If Inherit setting from parent is selected, clear it. An organization that inherits the setting takes its parent organization's value.
  7. Select Enabled or Disabled.
  8. Optional: To apply the setting to every child organization, click the lock icon. Locking overwrites the setting in each child organization and prevents child organization administrators from changing it.
  9. Click Save.
Security tab of an organization in the CrashPlan console, showing the Local two-factor Authentication section

Reset 2FA for a user

Resetting a user's CrashPlan 2FA in the console removes their current 2FA configuration, so that CrashPlan asks them to set up 2FA again at their next sign-in. Use it when a user cannot reset their own 2FA from the sign-in page, for example because they cannot receive email at their sign-in address.

  1. Sign in to the CrashPlan console.
  2. Navigate to Administration > Environment > Users.
  3. Click the user's name.
  4. From the action menu on their profile page Action menu icon, select Reset two-factor authentication.

Instruct the user to sign in again and set up 2FA, as described in Set up two-factor authentication. If no administrator who can manage the user is able to sign in, contact our technical support team for assistance.

Was this article helpful?
0 out of 0 found this helpful