Forum Discussion

IFMsolutions's avatar
IFMsolutions
Contributing Cover User
1 month ago

Clarification on SMS - 2FA requirements

Hi All,

I have confirmed with Doreen from MYOB that while we are mandated to set up SMS-based 2FA, we are not required to actively use it. (see her response below)

We can continue to use email-based 2FA as our primary authorisation method only and never use SMS 2FA in practice. The only requirement is that SMS 2FA must be configured as one of the available authorisation methods.

Hope this helps to clear a lot of confusion out there.

(including myself)

 

Re: 2FA - SMS

Hey IFMsolutions,

Yes. You can still use email for 2FA, setting up SMS 2FA is just an additional option. Here’s a link you can check for setting up additional 2FA methods

 

Cheers,

Doreen

2 Replies

  • Will_H's avatar
    Will_H
    MYOB Moderator
    1 month ago

    Quick clarification for any Enterprise Division customers reading this.

    Requirement for SMS to be an available authorization method does not apply to MYOB Acumatica or MYOB Exo Business users.

    With that said, as someone who has to worry about customer account security, I encourage everyone to use App Based authenticators where possible, as these are most secure.

    In terms of cyber security threats, App authenticators are safest, SMS is technically easier to intercept, and Email is the least preferable option.
    The reason is that often if a bad actor has access to your computer they also have access to your emails, but they probably don't have access to your phone.  Coupled with it being relatively easy to breach email accounts. 

  • PrueMYOB's avatar
    PrueMYOB
    MYOB Moderator
    1 month ago

    Great to hear IFMsolutions,

     

    Picking this up to add onto to Doreen's awesome reply! SMS 2FA needs to be configured as an available option and customers can continue to use email-based 2FA or the Authenticator app as their preferred option. Having SMS 2FA enabled simply helps ensure there's a secure way back into the account if access to the primary method is ever interrupted. 

     

    Thanks again, Prue