Securing your CESoft account with Multi Factor Authentication (MFA)

Securing your CESoft account with Multi Factor Authentication (MFA)

Essentials

At Cutting Edge we take data security very seriously. Follow these steps to keep your data safe!
  1. Each individual user must have their own login. Never share a login with others. If several staff need to access CE please contact us to arrange additional logins.
  2. Each user should have a mobile phone number or individual email address entered in their settings.
  3. You should activate Multi Factor Authentication (MFA) in your settings. This provides an additional level of security with a 'one time password' (OTP) which is a 6-digit code that automatically changes every 30 seconds. 
  4. Cutting Edge staff will never ask you for your password or MFA codes. Treat any such requests with suspicion and report to us immediately.

Setting up MFA

Each CE user has a separate security setup. To activate yours, log in to CE then click on your user name in the top right corner and select User Settings. 









In the Security Settings panel you'll see a dropdown menu with several options. You can choose to get the code sent to you by SMS or Email, or to use an Authenticator app.


Send OTP code by SMS

To have the code sent by SMS, first ensure your mobile phone number is set in the User Information panel. Then select SEND SMS from the dropdown. You will get a test SMS message with the OTP, enter the code in the 'Confirm Access' dialog that appears. If the codes match you're set to go! On subsequent logins CE will send an SMS to your phone whenever required.



Send OTP code by Email

To have the codes sent by email, first ensure your correct email address is set in the User Information panel. Then select SEND EMAIL from the dropdown. You will get a test email, enter the code in the 'Confirm Access' dialog that appears. On subsequent logins CE will send you an email with the OTP whenever required. 

Use an Authenticator app

There are several apps for smart phones that can store and generate codes for you.

Google Authenticator is available on
  1. Google Play https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2
  2. Apple App Store https://apps.apple.com/au/app/google-authenticator/id388497605
Microsoft Authenticator is available on 
  1. Google Play https://play.google.com/store/apps/details?id=com.azure.authenticator
  2. Apple App Store https://apps.apple.com/au/app/microsoft-authenticator/id983156458
There are other apps that may also work for you. If you use a password manager such as 1Password or LastPass, you can also store the MFA setup along with your login details for CE, and the current OTP code will be automatically generated and entered for you. We recommend using a password manager as the most streamlined and secure way to manage your access to CESoft.

To use the Authenticator option first ensure you have a suitable app installed on your smart device or computer, then select AUTHENTICATOR from the dropdown menu, this will display a QR code. Scan that code with your app and save, then enter the current OTP from the app. For example in 1Password, look for or create a One-Time Password section, click on the grey QR icon to scan the QR code.


Alternatively you can copy and paste the displayed setup key to manually create an authenticator entry.
DO NOT SHARE THESE DETAILS - they are specific to your user account.



Logging in with OTP

When MFA is set up on your account, you will be asked for a OTP for the first login each day, or if you log in from a different device/location.
Enter your Minor ID, Username and Password in the usual way. If the OTP is required a box will display under the password. Enter the OTP from your SMS, email or Authenticator, and click the 'Authenticate' button to login.



If the code is rejected you will be presented with buttons to resend by SMS or email. Please note that for security the codes are only valid for ~ 1 minute. You can't use a code from an old email or SMS.



What to do if you don't have access to your phone/email/authenticator

Try entering a random 6-digit code, this will fail and bring up the alternatives to send by email or SMS.
 If that fails, contact support@cesoft.com.au and we can assist you.

How to reset MFA

To reset your MFA details, go to you User settings and change MFA to NONE. This will clear your existing settings. The select one of the MFA options (SMS, EMAIL or AUTHENTICATOR) and re-verify. This will replace the prior MFA settings.

    • Related Articles

    • How to add a shortcut to CESOFT on your handheld device

      If you want to use CESOFT on your tablet or handheld device you may prefer to place a shortcut on your home screen. Android devices Open this link https://s8.cesoft.com.au/cesoft in “Chrome” app on your Android device Tap the menu icon (3 dots in ...
    • Some patient emails sent from CESOFT are going to SPAM or getting rejected

      When using the "Send Email" function from CESoft, you may notice that some of your outbound emails to patients are ending up in their spam folder, or the mail gets rejected with a Subject line "Subject: complaint about message from xxx.xxx.xxx.xxx" ...
    • Users and user permissions

      User logins Every individual using CESoft should have their own user login. This allows you to know who has done what in the software for audit purpose. Never share logins! There's no additional fee for user logins so please contact ...
    • Integrated Payment Portal - Payrix

      Cutting Edge has partnered with PayRix to create a payment service that is fully integrated into the software, with very favourable rates. There are no setup or monthly fees when using this integrated service. You can easily sign up from your ...
    • Moving An Invoice From One Provider To Another - Journal Entry

      When an invoice has been created at a site for one provider, Provider A for example, occasionally the actual procedure will be carried out by a different provider, e.g. Provider B. In this scenario, while CESoft Admins can shift the invoice itself to ...