Two-factor authentication
Hi,
Many customers are asking to enable two-factor authentication. It will be a very important security enhancement.
Thanks
jirazazabal
Posted 3 years ago·Last reply 9 months ago
20 comments
Hi,
Many customers are asking to enable two-factor authentication. It will be a very important security enhancement.
Thanks
Oleksandr_K
·9 months agoHi,
I’m happy to share that Two-Factor Authentication (2FA) is currently in active development and is planned for release in early 2026. (We will, of course, do our best to deliver it sooner if possible!)
I would like to share the major implementation concepts:
2FA will apply to native Sisense users only - those created in Sisense Admin and who log in with a Sisense username and password.
Active Directory (AD) or Single Sign-On (SSO) users will be excluded. This is intentional, as their authentication (including any MFA) is configured and managed by their external identity provider.
2FA will be available for both cloud and on-prem deployments, as long as an email server is configured for your instance.
The second factor will be a secure, one-time code sent to the user’s email.
Support for other methods (such as authenticator apps or SMS) is not planned at the moment.
This was a key part of your feedback. To ensure a smooth rollout and flexible control, we are implementing two levels of management:
Admins will be able to manage individual user configurations through a “Require Two-Factor Authentication” control in the Users list (GUI) or via the API.
The default value will be ON, allowing easy and secure enablement for the majority of users while still providing flexibility for exceptions (e.g., system, integration, or QA accounts).
Joseph Taylor
·9 months agoHi Oleksandr,
Thanks for your update on this feature.
Firstly, I’m pleased to hear our feedback has been taken on board and this has been put into active development. I have two points to raise off the back of this:
Firstly, my opinion is using email as a second factor (and having this as the only option) is a half-baked approach to 2FA. There is a flaw with this approach, in that if a user’s email is compromised, the attacker can both reset the account password AND receive a 2FA token to the email. This ‘single weak point’ goes against the spirit of 2FA in my view. Granted, this is more secure than not having 2FA at all, but has this weakness been considered by the team? (https://www.identityserver.com/articles/the-dangers-of-considering-email-as-two-factor-authentication)
Secondly, I appreciate it’s early days but it would be good to understand more about the mechanics of the rollout – specifically with the ‘default on’ approach. I am in a bit of an unusual position in that we have several thousand users of our platform and the majority will not want to use 2FA. Will I be able to control the rollout of this so that users receive no communications / prompts to use 2FA unless I decide to turn it on? (I don’t want the update landing, users being asked to use 2FA, and then me later turning it off). In other words, will I be able to configure this before it ‘goes live’ and starts affecting users?
Thanks again for the update on this - Joseph
Zach Williams
·1 year ago+1 for using 2FA
smoensted
·1 year agoAny updates on the roadmap status for this? Seems to be long time ago, there was a commitment to implementing it...
DRay
·1 year agoHi piyushrajput.
We appreciate your feedback, but please refrain from using insulting language.
piyushrajput
·1 year ago2FA is not currently on the product roadmap. The majority of our customers use a SSO provider to log in to Sisense, and currently our resources are focused on other projects that will impact greater portions of our users.
Well, that was just being lazy and passing on the responsibility to the end user for keeping the data secure. As a service provider, do you not feel even a little bit responsible for the platform's security? Am happy that this is getting another look.
In light of the recent breach, I would hope that platform security will be a priority and this feature gets the attention it deserves. Like most of the folks above, a setup that allows enabling MFA per user or a group of users or for one or more roles or for all the org would be ideal but will take what we can get quickly enough.
soporteparaptx
·2 years agoHi,
You can see that CDT already had this feature in the tool's core.
https://dtdocs.sisense.com/article/two-factor
Best
pb_si
·2 years agoThis is a security issue and has to be a high priority. Environments can be complex and SSO isn't always easy to set up for all users for a variety of reasons. Similar to others here, we have different groups of users that we need to tie into the system, which makes moving to SSO more challenging.
MFA is standard now for good reason. I'd support the approach above of flexibility (authenticator/SMS/none) on a per user basis.
Surya Kant
·2 years agoHi Team,
We would like to have MFA (Multi-Factor Authentication) feature to be brought into Sisense On-premise version as soon as possible.
Background:
Use Case:
Waiting to hear from Sisense to see this feature in their next release.
Joseph Taylor
·2 years agoHi YuliyaMotiyets, following your comment here would be my ideal use case:
At our business, we have 1000s of customer accounts using the Sisense platform. For the majority of these, we want users to have quick and easy access to Sisense. It's important for us to make viewing their data as simple as possible. Therefore, mandatory 2FA would actually be negative to our use case.
In our business, we would look for a solution that:
In short, it makes the 2FA:
I appreciate our use-case might be a little different to others, so I think a flexible amount of security is potentially what's key for Sisense customers as a whole here.
Yuliya Motiyets
·2 years agoThank you for your feedback and continued partnership! We understand the importance of implementing Multi-Factor Authentication (MFA), particularly for those of our clients not utilizing Single Sign-On (SSO) capabilities.
At Sisense, we are committed to continuously improving the security and integrity of our products. We are currently in the exploratory stage of assessing the feasibility and the best possible methods for integrating MFA into our platform. This effort is a high priority for us, aligning with our broader strategy of reinforcing our security measures to better protect all our users.
While we are dedicated to advancing this enhancement, we are not yet in a position to commit to a specific timeline. As we navigate through this exploratory phase, understanding your specific use cases and requirements would greatly assist us. We encourage you to share detailed scenarios where you envision MFA providing the most impact.
We appreciate your patience and support as we work towards this upgrade, and will keep you informed with any updates. We welcome your ongoing feedback and look forward to receiving more information from you regarding your security requirements.
jirazazabal
OP2 years agoRegarding to the comment:
The majority of our customers use a SSO provider to log in to Sisense
It's not true in our case. Almost all customers don't use SSO because they are using the tool for internal purposes only.
Best.
dnatatravelbi
·2 years agoFor dnata Travel insight platform which is both internal and external facing in light of recent security breach, we are guided by our intrenal security team to implement MFA and 90 day password expiry within the Travel Insight (sisense) product
Can you please advise on the timelines for this feature within Sisense?
Vinay Ambekar
·2 years agoI agree with the earlier post. The current security incident should highlight the need for Sisense to implement MFA.
jhaig
·2 years agoI am assuming after the data breach this will become a priority:
2FA is not currently on the product roadmap. The majority of our customers use a SSO provider to log in to Sisense, and currently our resources are focused on other projects that will impact greater portions of our users.
Not sure saying most of your customers use SSO is good enough. Surprised its not already available .
DRay
·2 years agoHello Everyone,
Thank you for all the feedback around two-factor authentication.
2FA is not currently on the product roadmap. The majority of our customers use a SSO provider to log in to Sisense, and currently our resources are focused on other projects that will impact greater portions of our users.
We may revisit this in the future though, so keep an eye out for it in the future.
Thank you,
Precisio
·3 years agoWe've worked with a few customers that don't use SSO but need MFA, or customers that use SSO for embedding but would like MFA on the direct login for security compliance reasons.
Joseph Taylor
·3 years ago+1 to this from me. We provide data to our customers via Sisense and have had some asking recently whether we can use 2FA to increase security.
I wouldn't want it as a blanket on/off requirement for all users (in general, I want customers to be able to log in to see their dashboards as easily as possible) but having the option to toggle it for specific users would be perfect.
jirazazabal
OP3 years agoHi Andrew,
Many customers has no SSO, and I think that just SSO does not fit the two-factor authentication thing. The definitition of two-factor authentication:
"2FA is an extra layer of security used to make sure that people trying to gain access to an online account are who they say they are. First, a user will enter their username and a password. Then, instead of immediately gaining access, they will be required to provide another piece of information."
AndrewLoomis
·3 years agoHello jirazazabal - can you elaborate on the need? Most Sisense customers integrate their SSO-provider to accomplish what you are asking for. Is there a reason you don't want to use SSO?