What is Strong Customer Authentication (SCA) and how does it work?

  • Updated

Strong Customer Authentication (SCA) is a security measure that helps protect your Remote account and sensitive data. It adds another layer of protection by requiring you to verify your identity in more than one way.

Why do I need SCA, including when using single sign-on?

SCA makes it more difficult for unauthorized individuals to access your Remote account and sensitive data. It requires you to verify your identity using two or more pieces of information.

Single sign-on (SSO) allows you to sign in to Remote using your company’s login details instead of a separate Remote password. However, SSO does not always replace Remote’s security requirements.

Remote may still ask you for a two-factor authentication (2FA) code when:

  • Your company must comply with SCA requirements. In this situation, 2FA is mandatory and cannot be turned off or skipped.
  • Your company enabled 2FA for everyone.
  • You enabled 2FA by signing in with a password before switching to SSO. In this case, 2FA remains active until you remove it from your account settings.

Being asked for a 2FA code when using SSO does not necessarily mean there is a problem with your account or your company’s SSO configuration.

How does SCA work?

To use SCA, you need to set up 2FA. When signing in, you provide two pieces of information:

  1. Your password or company SSO credentials.
  2. A 2FA code generated by an authentication app, such as Google Authenticator, Authy, or Microsoft Authenticator.

See also: How can I activate two-factor authentication for my account?

Is an email verification code the same as a 2FA code?

No. A code sent to your email is an email verification code. It means that 2FA is not set up on your account.

Check your inbox and spam folder for the code. If you do not receive it, request a new one. You do not need to reset 2FA.

What are the specific SCA requirements?

To meet SCA standards, Remote uses the following security measures:

  1. Two-factor authentication: You need to use 2FA every time you sign in.
  2. Account lockout: If you enter your password incorrectly five times within 30 minutes, Remote temporarily locks your account.
  3. 2FA for sensitive actions: You need to use 2FA for actions such as changing your password or editing sensitive personal information.
  4. Automatic sign-out: Remote automatically signs you out after a period of inactivity.

Was this article helpful?

1 out of 1 found this helpful

Submit a request

Comments

0 comments

Article is closed for comments.