16.2.6 Soft Token Authentication

This topic describes the systematic instruction to Soft Token Authentication option. This option enables Multi-factor authentication for a specific user and for a specific device.

This same device must be used to generate the time-based one-time passcode every time the user signs in.

A Soft token authentication is a two - factor authentication based on Passcode or PIN. Using this option, the user can generate security token i.e. a single-use 6 digit login PIN or passcode.

If you set up 2-Step Verification, you can use the Oracle Mobile Authenticator(OMA), Google Authenticator, Microsoft Authenticator with TOTP only app to receive QR codes.

  1. From the Dashboard, click on the My Profile icon, and then click Settings. From Settings, click Password & Security, and then click Soft Token Authentication.

    Figure 16-13 Soft Token Authentication



    Note:

    The fields which are marked as Required are mandatory.

    For more information on fields, refer to the field description table.

    Table 16-8 Soft Token Authentication - Field Description

    Field Name Description
    Choose Authentication Type Specify the authentication type for to generate the time-based one-time passcode every time the user signs in.

    The options are:

    • Oracle Mobile Authenticator
    • Other Mobile Authenticator
    Can’t scan? Copy the key Click on the link to generate the key to authenticate.
    QR Code Generated QR code to authenticate.
  2. In the Choose Authentication Type field, select the desired authentication type.
  3. Click Submit to generate QR Code. QR code is generated by application.

Figure 16-14 Scanning QR Code



  1. Get the authenticator app from the App Store.
  2. Install the authenticator app on iphone or android device.
  3. Open authenticator app.
  4. Click on the + icon of the authenticator.
  5. Choose option to scan the QR code or enter authentication key.
  6. Scan the QR code by authenticator app.

    Note:

    If you can’t scan the QR Code, click on the Can’t scan? Copy the key link to generate the key to authenticate.

    The success screen appears as user is all set to use authenticator to authorise.