Entering the one-time security code many times a day

Options

Hi, I was wondering if anyone else had a similar problem, and if so, what they've done about it if anything? For many years my NetCommunity has timed out if I've left it unattended for more than about ten minutes, forcing me to re-enter my password. Now, due to the new security, I am also entering a one-time security code many times a day (five times today so far). There doesn't seem to be a way to change this setting and it's becoming quite tiresome.

Tagged:

Comments

  • @Terry Abbott
    I have no “solution” to this but I agree!

  • David Seager
    David Seager Blackbaud Employee
    Tenth Anniversary Facilitator 1 Name Dropper Blackbaud Partner

    @Terry Abbott

    PCI DSS (Credit card compliance) requirement 8.1.8 requires the user to re-authenticate to reactivate the terminal or session if a session has been idle for more than 15 minutes. The PCI DSS inactive session timeout requirement applies only to administrative or internal accounts.

    SInce Blackbaud is also now requires its users to use MFA, you will need to enter your MFA code each time the login page is presented to you after a timeout, this cannot be changed as Blackbaud needs to be PCI DSS compliant.

  • I also agree and am getting similar feedback from teammates who use Net Community - needing to use MFA every time seems excessive compared to any other website I've ever used. The typical experience would be doing MFA once every few weeks, maybe, and then it remembers you for a while. And please be very careful if the thought is to ever require this security step of donors (at least as it works now) - it will not go well!

  • @David Seager, Thank you for this, that's useful background. The curious thing is, I'm the only member of my team who needs to reauthenticate every fifteen minutes. I understand that my Manager only needs the MFA code once a day.

  • David Seager
    David Seager Blackbaud Employee
    Tenth Anniversary Facilitator 1 Name Dropper Blackbaud Partner

    @Terry Abbott NetCommunity MFA requirement is per session. Could your manager be referring to Blackbaud.com or RE NXT? they are using a different method then we do for NetCommunity.

  • @David Seager, no - my manager is only entering MFA in NC once a day. We sit next to each other and I can see that he's doing exactly the same as me, but getting different results.

  • David Seager
    David Seager Blackbaud Employee
    Tenth Anniversary Facilitator 1 Name Dropper Blackbaud Partner

    @Terry Abbott This should not be happening, could we connect so I can troubleshoot the issue? NetCommunity should be asking for MFA for every session unless your manager is keep their session alive in NetCommunity all day. I will be creating a support ticket and reaching out to you.

  • JoAnn Strommen
    JoAnn Strommen ✭✭✭✭✭
    Ancient Membership Facilitator 4 Name Dropper Photogenic

    @David Seager Help me grasp this. I can go to NetC within RE and not have to deal with timing out as long as RE is is operating. But when I need to get into our alumni directory (hosted by BB/tied to NetC) I have to enter MFA every 15 minutes?

    Was working with an alum who was having difficulty getting into alumni directory. I would give him directions, he would try and then call me back. I had to enter MFA 4 times just while dealing with him.

    I'm assuming that somewhere in the backend credit card info is recorded in NetC. But do you think a wall could be built between data storage and alumni directory/website page editing? Sure would be nice.

  • David Seager
    David Seager Blackbaud Employee
    Tenth Anniversary Facilitator 1 Name Dropper Blackbaud Partner

    @JoAnn Strommen

    This should be possible in NetCommunity, another admin would need to remove rights to your NetCommunity access so you only have content edit rights (like page and part editing).

    But if you need to reset passwords or edit merchant accounts or doing anything of a full admin access level then you would be subject to the MFA requirement and 15 min inactive timeout window.

Categories