Splunk® Intelligence Management (Legacy)

User Guide

Set up multi-factor authentication to secure access to your Splunk Intelligence Management environment

Multi-factor authentication (MFA) is an additional layer of security can help prevent your account from being compromised. MFA requires anyone trying to log into your account to have two things: an access code and your password.

There are two parts to this process:

  1. The company administrator enables MFA for users.
  2. Each user then enables MFA for their account.

Enable MFA for the company

You must have administrator access to perform these steps.

  1. After logging into your Splunk Intelligence Management account, you are prompted to follow the setup instructions provided by Duo, Splunk Intelligence Management's trusted third party MFA provider. Duo supports the following MFA options: push notification, sms, or a phone call to your mobile number. Learn more about Duo's setup process on the Guide to Two-Factor Authentication page in the Duo Security documentation.
  2. Click Settings > Users to enable MFA for your users.
  3. Click the Edit icon for the first user
  4. Toggle MFA enabled to on.

Activate MFA for each user

After MFA is enabled, users will see an MFA prompt when they log in.

  1. Click Start Setup to begin the process of setting up MFA for that account.
  2. Specify the type of device you will be using with MFA and click Continue.
    Splunk Intelligence Management and Duo recommend that you use a mobile phone.
  3. Enter the phone number for the device and click Continue.
  4. Confirm the type of phone you are using and then click Continue.
  5. Follow the instructions on-screen to install Duo Mobile on that device and then click I have Duo Mobile installed to continue.
  6. Follow the instructions to activate Duo Mobile on your device.

Contact Splunk Intelligence Management Support Portal if you have questions about enabling MFA with Splunk Intelligence Management.

Last modified on 20 May, 2022
Use the redaction library to remove information from reports   Set up a dedicated service account for API keys and tracking

This documentation applies to the following versions of Splunk® Intelligence Management (Legacy): current

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters