Learn how Rublon MFA helps organizations enroll webmail users through a link delivered by SMS, without relying on access to the email account being protected.
Scenario
An organization plans to protect access to corporate webmail with multi-factor authentication (MFA). Before MFA is enforced, users need to register at least one authenticator so they can complete the additional verification step when signing in using MFA.
Challenge
An Enrollment Email is convenient when users already have secure access to their inboxes. However, using email as the only enrollment channel creates a circular dependency when email itself is being protected: users may need to open the mailbox to obtain the link that lets them register an authenticator for securing access to that same mailbox.
This can complicate an MFA rollout for new employees who do not yet have access to webmail, users who have lost access to their inboxes, and organizations that want to enroll authenticators through a channel independent of the email system being protected.
Solution
Use Rublon MFA to send an Enrollment SMS to the mobile phone number associated with the user. The administrator sends the message from the Rublon Admin Console, and the user opens the enrollment link on their phone to register an authenticator allowed by the organization’s configuration, such as Rublon Authenticator, a third-party authenticator app, a FIDO2 passkey, or a security key.
Enrollment SMS separates delivery of the enrollment link from the webmail account being secured. It does not require the user to choose SMS as the authentication method for future sign-ins. The user can enroll another supported authenticator and then use it to access webmail with Rublon MFA.
Benefits
- Remove the dependency on access to the mailbox being protected.
- Let users self-enroll approved MFA authenticators from a link received by SMS.
- Enroll users before enforcing MFA for webmail access.
- Support new employees and users who cannot currently open their corporate inboxes.
- Allow users to register phishing-resistant authenticators, such as FIDO2 passkeys or security keys, when permitted by the organization.
- Reduce enrollment-related lockouts and help-desk requests during an MFA rollout.