Forum Discussion

RoderickGI's avatar
RoderickGI
Partner
3 months ago

Looking for information or experience regarding enforcing use of 2FA in the MYOB Advanced App

I’ve been looking for information on the use of 2FA with the MYOB Advanced App (Android in this case, but would like to know for iOS as well.)

 

Our customer wants to use an Android tablet for quick access to pricing. They have 2FA enforced for all users. In testing we found that users could log into MYOB using just the “Username / Password” button and were not prompted for any 2FA Code. We tested this on a “clean” tablet with a user who had not used the tablet before, and so we are sure that he had never logged in to the App or MYOB Advanced on that tablet, and hence his MYOB Account would not have been cached on the device.

 

I have noted that logging in using a fingerprint rather than the User ID and Password can be turned on in the Android App, which is an improvement, but still isn’t 2FA.

 

I have also noted that a user can log in using the “MYOB” button rather than the “Username / Password” button, and in that case 2FA is used, requiring a Code from, in this case, my Microsoft Authenticator setup.

 

However, 2FA is not enforced. Both buttons remain available, and the user can choose which to use.

 

So I am seeking clarification of the functionality, references, and timeline for when 2FA will be enforced in the App, consistent with the MYOB Advanced security preferences. I have searched quite a bit and not found anything regarding this.

 

I have asked MYOB who are looking for information resources for me, but also suggested I post here.

So, any more information or ideas?

No RepliesBe the first to reply