---
sourceDocument: Xanadu Customer Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/xanadu/customer-service-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Customer Service Management

ft:clusterId :

    - csm

bundleId :

    - csm

workflow :

    - Customer and Industry


---

# Multi-factor authentication for Customer and Consumer Service Portals

# Multi-factor authentication for Customer and Consumer Service Portals {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Multi-factor authentication, also known as two-step verification, is a security
requirement that asserts a user enter more than one set of credentials.
Enable multi-factor authentication for Customer and Consumer Service Portal users so that
access to the self-service web portals is more secure from potential vulnerabilities. For more
information, see [Multifactor authentication
(MFA)](https://www.servicenow.com/docs/access?context=c_MultifactorAuthentication&version=xanadu&pubname=xanadu-platform-security&ft:locale=en-US).

## Multi-factor authentication properties {#configure-csm-multifactor-auth__section_ar3_brx_g3b}

Use properties to enable role-based multi-factor authentication criteria and configure the behavior. {#configure-csm-multifactor-auth__table_g3p_2rx_g3b__entry__2}

| Property | Description |
|-|-|
| Enable Multi-factor authentication \[glide.authenticate.multifactor\] | Select this check box to allow users and administrators to use this feature. * Type: enabled \| disabled * Default value: enabled * Location: Multi-factor AuthenticationProperties {#configure-csm-multifactor-auth__ul_ggl_jmx_kt} |
| Number of times a user can bypass setting up multi-factor authentication \[glide.authenticate.multifactor.setup.bypass.count\] | Enter a number that represents how many times a user can choose to skip the additional passcode requirement. This gives your users the ability to still log in the instance if they do not have their mobile device with them. If you disable this feature and then re-enable it, the counter starts over again. * Type: string * Default value: 3 * Location: Multi-factor AuthenticationProperties {#configure-csm-multifactor-auth__ul_xtx_1sx_g3b} |
| The time in minutes, the one time code sent to user's email address is valid for \[glide.multifactor.onetime.code.validity\] | Enter a number in minutes that specifies how long the reset code is valid. See [Log on with multi-factor authentication](https://www.servicenow.com/docs/access?context=t_LogOnWithMultifactorAuth&version=xanadu&pubname=xanadu-platform-security&ft:locale=en-US). * Type: string * Default value: 10 * Location: Multi-factor AuthenticationProperties {#configure-csm-multifactor-auth__ul_ny3_jsx_g3b} |
| Additional time in seconds for which the code will be valid to accommodate for the clock skew. Max value is 60 seconds. \[glide.authenticate.multifactor.clock_skew\] | Enter a number in seconds with a maximum of <kbd class="ph userinput">60</kbd>. By default, the instance validates the code entered by the user against the single app-generated code generated at whatever the `current time` is. You can skew the time window with this property and allow one or more codes generated during a time window to be considered valid. The property's value is used in the following calculation: `current time - x/2` and `current time + x/2`, where 'x' is the value of this property. If you use the value of `10`, for example, the instance considers any codes generated by the app between the time range `[the current time - 5 seconds]` and `[current time + 5 seconds]` to be valid. Use this property to prevent log in issues where the user is unable to enter the correct code in the default time allotted. |
[Table 1. Properties for multi-factor authentication]

{#configure-csm-multifactor-auth__table_g3p_2rx_g3b}

## Configure roles for multi-factor authentication {#configure-csm-multifactor-auth__section_wn4_h5x_g3b}

Add the following external roles to the multi-factor roles:

* sn_customerservice.customer
* sn_customerservice.consumer

{#configure-csm-multifactor-auth__ul_tpl_t5x_g3b} Users with these roles will be required to use multi-factor authentication. For more information, see [Configure user-based multi-factor
criteria](https://www.servicenow.com/docs/access?context=t_RequireMultifactorAuthForAUser&version=xanadu&pubname=xanadu-platform-security&ft:locale=en-US).

*[\>]: and then


