Online Banking Password and Security Questions

Screen ID:

UCUOBSEC-02

Screen Title:

Online/Mobile Password and Security Settings

Panel ID:

UCUOBSEC-02

Tool Number: Multiple
    Click here to magnify

Access this screen by using Enter on the first Online Banking Password and Security Questions screen.

This screen allows you configure and activate MFA for a one-time passcode to log on to It's Me 247 and BizLink 247. Knowledge Base items on this subject appear on below.

For instructions on It's Me 247 MFA security, refer to the It's Me 247 Strategies for Controlling Member Access. For instructions on BizLink 247 MFA security, refer to the Biz Link 247 Online Banking Guide.

Overview

Require that the member request a code for authentication to online banking; these are also referred to as “one-time passcodes” or two-factor authentication. Members can opt to register their device so that authorization isn’t required each time they log in. (See the MFA FAQ for more details!)

  • Concerned about your members having to use MFA frequently? Configure a set number of days for the device to be remembered.

  • Concerned your phone database and personal details are not up to date in CU*BASE? Encourage your members to update their phone number information using an online banner, form, or Xtend campaign. (See Knowledge Base items below for more details.)

  • Interested in having different controls for business banking, standard browser banking, and mobile app? Set different controls for each in the configuration screen.

On this screen select whether the one-time login passcode will be sent to the member’s email, phone, or both. Then designate the number of days the device registration will be active on the member’s device before they will need to register via MFA (999 is never expire). Use Update (F5) to save the changes. When ready, return to this screen to activate this feature.

Frequently Asked Questions

For a full list of frequently asked questions on MFA for login, refer to the Knowledge Base.

See individual knowledge base items below:

  1. After my credit union activates It’s Me 247 multi-factor authentication (MFA), will my members who use their MACO credentials (voice, fingerprint, photo ID, or custom PIN) with the Mobile App also be required to use a one-time passcode to register with device registration?

  2. Will my credit union be able to activate multi-factor authentication (MFA) for business online banking (BizLink 247)? How is MFA different for this environment?

  3. I see there are “mobile phone” and “can send text messages to this number” checkboxes on the phone database screen in CU*BASE. Do either of these need to be checked in CU*BASE for that phone number to be used for multi-factor authentication (MFA)?

  4. My member has four phone numbers associated with their membership. Can they use any of these numbers for muti-factor authentication (MFA) for It’s Me 247?

  5. With multi-factor authentication (MFA), can I set different expiration days for the device registration for members using a browser versus mobile app banking to access It’s Me 247?

  6. Does online membership open process (MOP) support multi-factor authentication (MFA)? How does that process work?

  7. With multi-factor authentication (MFA), what situations would cause a member who had already registered their device with a one-time passcode to need to register it again?

  8. I hear that when it is implemented multi-factor authentication (MFA) will only work with members who authenticate using the aggregator Plaid. What can I do about other aggregators my member have given their login credentials to?

  9. What are some strategies I can use to clean up my phone database for my multi-factor authentication (MFA) rollout?

  10. Does Xtend offer a data hygiene campaign to assist me with cleaning up my email and phone numbers for my MFA rollout?

  11. What considerations should I have about Money Map and multi-factor authentication (MFA)?

  12. What phone numbers are presented to the member for the one-time passcode for multi-factor authentication (MFA) for It’s Me 247?

  13. I see you can set online banking MFA (multi-factor authentication) to require device registration after a set number of days. What happens if my credit union changes this number of days in the CU*BASE configuration?

  14. Do It's Me 247 standard online banking and BizLink 247 business online banking support two-factor authentication (2FA)?

  15. My credit union is activating multi-factor authentication (MFA) during online banking login. Can we now discontinue members having to answer their security questions?

  16. If members receive their one-time passcode for multi-factor authentication (MFA) via a text, how will my CU be charged for that text message?

  17. After my credit union activates multi-factor authentication for It’s Me 247, do my members using the “jump” feature (to access a second membership without entering credentials) need to use MFA during this jump?

  18. Can you send a one-time passcode for multi-factor authentication (MFA) for BizLink 247 via text message?

  19. My credit union has activated multi-factor authentication (MFA) for personal information changes in It’s Me 247. How does the member experience for MFA during login differ?

  20. When I activate multi-factor authentication (MFA) during logon at my credit union, can I turn it on for just some of my memberships?

  21. Are international phone numbers supported for multi-factor authentication (MFA) for online banking?

  22. Are phone numbers flagged as “wrong” phone numbers presented to the member during multi-factor authentication (MFA) for online banking?

Field Descriptions

Activation

Require two factor authorization

Use to activate the feature. Activate it for just It's Me 247 (personal), just BizLink 247 (business), or both.

Standard Online Banking Member Login

Use these settings for how the member experience will be in It's Me 247.

If two factor, use [code sent via text or email, code sent via email, code sent via text]

This selection will determine what options the member will have to select for the one-time passcode to be sent.

  • If an email option is selected, the email on the membership is displayed. If a text option is selected, the phone numbers associated with the membership are displayed. (Both are displayed with masked characters.) The email and phone number are pulled from the membership information.

  • See the Knowledge Base items above for more details.

Remember my device feature for desktop/mobile web:

Expire device registration after xxx days

This setting determines the number of days that a member can go without needing to register their device when they view personal online banking in the desktop/mobile web environment.

  • 999 means unlimited days. Any lesser number is a configured number of days.

  • See Knowledge Base items above for more details.

Remember my device feature for mobile app

Expire device registration after xxx days

This setting determines the number of days that a member can go without needing to register their device when they view personal online banking in the mobile app environment.

  • 999 means unlimited days. Any lesser number is a configured number of days.

  • See Knowledge Base items above for more details.

Business Banking Multi-Login

Use these settings for how the business member experience will be in BizLink 247.

  • Only email is supported for sending the one-time passcodes. This is the same email used for BizLink 247 password resets.

Remember my device feature for desktop/mobile web:

Expire device registration after xxx days

This setting determines the number of days that a member can go without needing to register their device when they view business online banking in the desktop/mobile web environment.

  • 999 means unlimited days. Any lesser number is a configured number of days.

  • See Knowledge Base items above for more details.

Remember my device feature for mobile app

Expire device registration after xxx days

This setting determines the number of days that a member can go without needing to register their device when they view business online banking in the mobile app environment.

  • 999 means unlimited days. Any lesser number is a configured number of days.

  • See Knowledge Base items above for more details.