Multi-Factor Authentication
Multi-Factor Authentication
Enhancing Security with Multi-Factor Authentication (MFA) Using Authenticator
In today's digital landscape, securing user accounts and sensitive data has become a top priority for organizations. One of the most effective ways to enhance security is by implementing Multi-Factor Authentication (MFA) across applications. MFA adds an extra layer of protection by requiring users to provide multiple forms of verification before gaining access to an account. Authenticator, a widely used application, facilitates this process by generating time-based one-time passwords (TOTP).
However, integrating MFA into application testing workflows can be challenging, particularly due to the difficulty in automating the MFA process. This can hinder the creation of seamless end-to-end user experiences during testing. Fortunately, with tools like Leapwork, organizations can now automate MFA processes without compromising security.
Minimum Requirements for Automating MFA
Okta’s removal of manual secret key enrollment means users (and third-party tools) no longer have access to the shared secret used to generate Time-based One-Time Passwords (TOTP). Without that key, no system outside of the authenticator app itself (like Okta Verify) can generate valid codes.
Workaround
If your organization's security policy allows, a practical workaround is to enable support for key-based setup within Okta Verify. Google Authenticator is an available option that we know can work. This setting can be enabled selectively by your Okta administrator. It maintains MFA security while allowing Leapwork’s TOTP block to function as intended. Unfortunately, direct automation of Okta Verify–based MFA is currently not supported due to Okta’s architectural shift away from key-based TOTP.
Before automating MFA with Authenticator, ensure that the following requirements are met:
- TOTP Mechanism: The organization must support a Time-based One-time Password (TOTP) mechanism as part of their MFA strategy.
- Secret Key Generation: The ability to generate a secret key for the account linked to TOTP MFA is essential.
- Authenticator Applications: Few of the widely used authenticator apps, Microsoft and Azure-based authentication systems, such as:
- Microsoft Authenticator
- DUO Security
- PingID (with some potential issues)
- Google Authenticator
Automating TOTP MFA for Microsoft account (Azure users) with Leapwork
Leapwork simplifies the process of automating TOTP-based MFA, allowing for smooth execution of workflows that involve MFA. Follow these steps to set up and automate MFA using Authenticator:
Login to your Microsoft Account: Start by logging into your Microsoft account.
Navigate to Security Info: Go to the Security info section of your account settings.
Add a Sign-in Method: Click on "Add sign-in method" and choose the "Authenticator app" option.
Select an Authenticator App: opt for the "I want to use a different authenticator app" if you are not using the default app.
Set Up Your Account: Proceed by clicking “Next” on the setup screen.
Copy the Secret Key: When prompted, click on "Can’t scan image," and then copy the secret key provided.
Configure in Leapwork: Paste the copied secret key into the secret field of in "Time-based One-time Password" block and now, generate a TOTP by executing the TOTP block and sending the output to Log Message (refer to the below image).
Enter the OTP: Return to the Microsoft account setup page, hit "Next," and enter the 6-digit TOTP generated by "Time-based One-time Password" block in Leapwork. (as shown in above image)
Complete the Setup: Once the OTP is verified, MFA is successfully automated and ready for use whenever required. The same can be viewed in the Security Info page as well.
Conclusion
Automating MFA using Authenticator in conjunction with Leapwork streamlines the testing and implementation process, ensuring that security features remain intact while improving efficiency. By automating the generation of TOTPs, organizations can achieve both robust security and smooth operational workflows.
For any clarification, please contact our Priority Support.