Set up multi-factor authentication to secure access to your Splunk Intelligence Management environment
Multi-factor authentication (MFA) is an additional layer of security can help prevent your account from being compromised. MFA requires anyone trying to log into your account to have two things: an access code and your password.
There are two parts to this process:
- The company administrator enables MFA for users.
- Each user then enables MFA for their account.
Enable MFA for the company
You must have administrator access to perform these steps.
- After logging into your Splunk Intelligence Management account, you are prompted to follow the setup instructions provided by Duo, Splunk Intelligence Management's trusted third party MFA provider. Duo supports the following MFA options: push notification, sms, or a phone call to your mobile number. Learn more about Duo's setup process on the Guide to Two-Factor Authentication page in the Duo Security documentation.
- Click Settings > Users to enable MFA for your users.
- Click the Edit icon for the first user
- Toggle MFA enabled to on.
Activate MFA for each user
After MFA is enabled, users will see an MFA prompt when they log in.
- Click Start Setup to begin the process of setting up MFA for that account.
- Specify the type of device you will be using with MFA and click Continue.
Splunk Intelligence Management and Duo recommend that you use a mobile phone.
- Enter the phone number for the device and click Continue.
- Confirm the type of phone you are using and then click Continue.
- Follow the instructions on-screen to install Duo Mobile on that device and then click I have Duo Mobile installed to continue.
- Follow the instructions to activate Duo Mobile on your device.
Contact Splunk Intelligence Management Support Portal if you have questions about enabling MFA with Splunk Intelligence Management.
Use the redaction library to remove information from reports
Set up a dedicated service account for API keys and tracking
This documentation applies to the following versions of Splunk® Intelligence Management (Legacy): current