2 Factor Authentication

I see there is a message for implementation of 2fa.

Shouldnt be much of a problem onshore, but how is this considered to work offshore with field workers? we already experience problems with license and updates thats not alway working, having to restart the android units, and then having to use 2fa when we doesnt have individual microsoft users, but groupe users per position are going to be difficult.

With some times high latency on satelite connections and no individual users on mobile devices this does seem to be another hurdle in getting the offshore staff to utilize Onix.

Hi @Lars_Morten_Nesse, 2FA for Onix account is optional at the moment, so the offshore workers can skip it and just sign in with their email and password for a while.

In the meantime, please let us take this chance to get more insights on your offshore problems to improve the feature in future releases.

These’re 3 main problems that I can identify in your sharing and will redirect to the relevant teams later. Kindly let me know if any of them is incorrect and which Onix app your offshore colleagues are using. Thanks in advance :blush:

  1. Many people are sharing one Onix user account, but 2FA sign-in requires each person to use the authenticator app on their own personal mobile device.
  1. Your company doesn’t use work mobile devices, and your offshore workers also don’t install an authenticator app on their personal mobile devices.
  1. Offshore Internet connection is weak, which may make verification codes or temporary access codes expire before the user completes the sign-in.

Hi.

This is really not thought through by Onix. We are not able to equip all individual users with their own personal work device. And there will be resistance, understandably, bu the users to utilize their own units.

Offshore internet will be behind firewall and sometimes on satellite systems. we are already having issues with connecting, multiple attempts are often needed. with an authenticator app in addition, when the users have to use two units just two get access to the application, this will be pushed out to the next shift.

it is really diappointing to see how little effort Onix put in to understand the system from the en users perspective.

Hi Lars, thanks for explaining your concerns with details.

First of all, I want to reassure you that 2FA setup is not mandatory. Offshore staff can continue to sign in with email and password as before. There is no change to their current access unless your company chooses to require 2FA.

When we introduce 2FA, the goal is to improve security without creating unnecessary friction. We understand that offshore operations have different constraints than onshore environments. Your suggestions are therefore very important so we can improve the solution based on real usage scenarios.

To move this discussion forward constructively, it’d help a lot to focus on suggestions of functionalities, for example: Changes to the 2FA setup process, alternative 2FA opt-out methods,… If you can describe a specific functionality that would make 2FA (or the sign-in process in general) easier for offshore staff, Onix Product team can assess feasibility and prioritize more quickly.

Regarding weak internet connectivity: authenticator apps create verification codes locally on the device and don’t require a strong connection. However, signing in to an online Onix application (for example, Onix Worker or Onix Tool Store) has always required a stable connection, regardless of 2FA usage. If you have experienced failed sign-ins in the past, we would appreciate more details so we can better assess potential risks for offshore 2FA usage.

We want to ensure the solution works in real-life conditions and we’re looking forward to your input.