This guide helps you enable and configure Email Authentication settings to enforce Multi-Factor Authentication (MFA) for different user roles in your system. MFA adds an extra layer of security by requiring users to verify their identity via email during login.
Precondition
Ensure you have Admin access to the dashboard and that your email server settings are correctly configured if you're using a custom SMTP.
Steps to Configure Email MFA
1. Access Email Authentication Settings
- In your Admin Dashboard, go to Settings → Access Control → MFA Authentication.
- By default, MFA via email is set to NO (disabled).
- When disabled, related fields and buttons will appear grayed out.
.
2. Configure Email Server Settings
- Use Default Server → Toggle ON to use the system’s default email server.
- Relay Outbound Email To → Enter your SMTP server if using a custom email server.
- From Address of Emails → Set the sender address for authentication messages.
3. Set Authentication Triggers
Choose which user roles require email authentication during login:
- Authenticate Admin Login → Set to YES to require MFA for Admins.
- Authenticate Merchant Login → Set to YES to require MFA for Merchants.
- Authenticate Consumer Login → Set to YES to require MFA for Consumers.
- Authenticate Member of this Group → Select a group from the dropdown to apply MFA selectively.
4. Configure Verification Settings
These settings apply to first-time login verifications:
- Verify Admin Login → Set to YES to verify Admins via email on first login.
- Verify Merchant Login → Set to YES to verify Merchants via email on first login.
- Verify Consumer Login → Set to YES to verify Consumers via email on first login.
5. Save Your Settings
- Once all fields are configured, click Save to apply changes.
- MFA will now be enforced based on your selected rules.
What’s Next?
Once enabled, users will be prompted to verify their identity via email during login, adding a critical layer of protection to your platform.
Note:
Currently, Email MFA is fully supported for Admin users. Support for Merchant and Buyer accounts is on Arcadier’s roadmap to enhance security across all user roles.