Applies to: Xerox DocuShare 8.1
Overview
DocuShare 8.1 provides multi-factor authentication (MFA) for privileged administrator accounts. When MFA is enabled, an eligible administrator signs in with a password and a six-digit, one-time password (OTP) delivered to the administrator's registered email address.
MFA applies to users with the Site Administrator, Content Administrator, or Account Administrator role. Regular users continue to sign in with a password alone. SAML-authenticated sessions bypass DocuShare MFA because authentication and MFA are managed by the identity provider.
MFA is enabled by default for administrator accounts.
Before you begin
- Confirm that DocuShare SMTP email is configured and working.
- Confirm that each administrator has a valid email address.
- Arrange for a second Site Administrator or Account Administrator to be available during rollout for account recovery.
Configure MFA
- Sign in to DocuShare with an administrator account.
- Open Admin Home > Account Policies.
- Locate the Multi-Factor Authentication section.
- Confirm that the master enable option is selected.
- Review or update the following settings:
- OTP Code Lifetime: 60 to 600 seconds; default is 300 seconds.
- Lock After Failed Attempts: 1 to 20 attempts; default is 5.
- Lockout Duration: 1 to 120 minutes; default is 15 minutes.
- Resend Cooldown: 10 to 300 seconds; default is 60 seconds.
- Recovery Codes at Enrollment: 4 to 16 codes; default is 8.
- Trust Device Duration: 0 to 10 days; default is 10 days. Set to 0 to disable device trust.
- Click Save. Changes take effect immediately; a server restart is not required.
Complete first-time enrollment
On the next sign-in, each eligible administrator is prompted to enroll:
- Confirm the email address on the account or enter one if none is configured.
- Retrieve the verification code from email and enter it on the enrollment page.
- Save the displayed recovery codes in a secure location. They are shown only once.
- On later sign-ins, enter the six-digit OTP when prompted.
An administrator may select the trusted-device option to reduce how often an OTP is requested. The trust period is controlled by Trust Device Duration.
Reset an administrator's enrollment
If an administrator loses access to both the registered email account and recovery codes, another Site Administrator or Account Administrator can reset the enrollment:
- Open the affected user's profile.
- Select the Reset MFA Enrollment tab.
- Confirm the reset.
- Have the affected administrator sign in and complete enrollment again.
If no administrator can sign in, contact DocuShare Support for the emergency command-line recovery procedure. Do not modify MFA configuration files unless directed by Support.
Troubleshooting
The enrollment email does not arrive
Verify that SMTP is configured, the administrator's email address is correct, and DocuShare can send a test message. MFA enrollment cannot complete until outgoing email is available.
An administrator is locked out
Wait for the configured lockout duration, use a recovery code, or ask another Site Administrator or Account Administrator to reset the enrollment.
MFA is not shown for a SAML login
This is expected. SAML sessions use the identity provider's authentication and MFA policies instead of the DocuShare administrator MFA prompt.