Frequently Asked Questions
I have enabled several methods, which one will be requested?⚓
If you have enabled multiple methods for your second factor, the page will by default suggest reusing the same as your last login. To use another one, click on the link “Other login method” then on the tile corresponding to the desired method.
Example of tiles with the TOTP, email and code grid methods enabled:
I do not wish to use a phone or personal device, how can I proceed?⚓
Several of the proposed methods can be used without a personal device. For example, you can choose:
The TOTP code with KeepassXC and, if desired, the browser extension performing automatic pre-filling.
The code grid, to be saved in KeepassXC or printed and kept safely.
I forgot my phone at home today, how can I use another method?⚓
If you have enabled multiple methods for your second factor, the page will by default suggest reusing the same as your last login. To use another one, click on the link “Other login method” then on the tile corresponding to the desired method.
Example of tiles with the TOTP, email and code grid methods enabled:
Do we need to perform all these steps every day to log in?⚓
Activation and configuration of your methods is done the first time. Then, for daily use, you can use the chosen factors when the authentication page asks for them. This will be the case on average once per day, like your primary password.
The maximum validity period of the second factor over 24 h (1 day) is a choice of the institution.
Could two-factor authentication be required less often than once a day?⚓
The maximum validity period of the second factor over 24 h (1 day) is a choice of the institution.
Can I receive a login code by SMS?⚓
No. Sending codes by SMS has been ruled out for several reasons, particularly the cost for the institution, the risk of non-delivery, and the lower security of this channel.
The ANSSI (National Cybersecurity Agency of France) therefore recommends prohibiting this delivery channel, for the following reasons, for example:
The majority of SMS messages travel via protocols that have many intrinsic vulnerabilities and can be easily intercepted. An attacker could then retrieve an authentication code sent by SMS and use it to perform fraudulent authentication
in some cases, it is possible to exploit the reuse of phone numbers to bypass multi-factor authentication that uses receipt of a code by SMS
Recommendations concerning multi-factor authentication and passwords, 2021
Do you offer video tutorials to enable and use two-factor authentication?⚓
Yes. We offer several short video tutorials to facilitate the setup and use of two-factor authentication. They are all available on the Pod channel of the Digital Directorate and integrated into this guide. Here is the list:
