What was done?
Added User Security with Multi-Factor Authentication
With this release, Multi-Factor Authentication (MFA) can now be enabled for all Positive Pay Financial Institution and Business Client users.
Once the MFA setting is enabled by a financial institution, their users and their BC users will be required to utilize SMS/Text Message, email or a third-party authenticator app (Google Authenticator, Microsoft Authenticator, etc) to securely validate their access to the Positive Pay portal.
Multi-factor authentication is disabled by default and can be enabled by Administrators through their Account Settings screen in Positive Pay. This will enable MFA for all users for the FI and their related BCs. While enabling MFA, admins can also determine the length of time before a user is prompted to complete MFA again (from being prompted every logon to every 30 days, depending on your user security needs).
Administrators can also reset an individual user’s MFA enablement and manage their trusted devices.
Why is this useful?
Enabling multi-factor authentication adds another level of security when accessing your Financial Institution and Business Client transactional data.
As an admin, how do I manage MFA for my FI and BCs?
1. Navigate to Account Settings.
2. Under the Security Settings section, there is a new setting toggle: “Enable MFA”. This will be disabled by default.
a. Clicking the toggle will enable MFA for all users under the financial institution including BC users.
3. Once the toggle is enabled, you will be presented with a new setting: “Require MFA Verification”. This controls the amount of time before the user is prompted to complete MFA again.
a. When MFA is enabled, the default is to prompt users to reverify MFA every seven days.
b. Other reverification timing options include:
i. After Every Logon
ii. After Every 24 Hours
iii. After Every 14 Days
iv. After Every 30 Days
4. Once you’ve finished updating account settings, click Save Changes to apply changes and enable MFA.
a. If MFA has not been enabled before, all users will be required to complete MFA the first time they log in after enabling MFA.
As a user, how do I use multi-factor authentication (MFA)?
1. Once multi-factor authentication is enabled, a user will automatically be required to complete MFA when logging in the first time after enablement.
2. Upon logging in with their credentials, the user will be prompted to select a verification method to be their default: Email, Text Message, or a third-party Authenticator App.
a. Selecting “Email” will send a verification code to the user’s Email Address on file.
b. Selecting “Text Message” will send a verification code to the user’s Phone Number on file.
i. “Text Message” will not display if the user doesn’t have a Phone Number in their My Info screen.
c. Selecting “Authenticator App” will require the user to enroll using a third-party verification app (Microsoft Authenticator, Google Authenticator, etc) to receive their verification code.
3. Once a method is selected, the code will be sent to the preferred location.
a. Note: The user should remain on the Configure Multi-Factor Authentication screen as they retrieve their code.
4. Once a code is received, the user must enter that code into the “Code” field.
a. If the code is entered correctly, the user will gain access to Positive Pay.
b. If the code is not entered correctly, the user will have to either send a new code using the same method or successfully enter a new code from another method before gaining access to Positive Pay.
As an admin, how do I reset MFA for an individual user?
1. Navigate to Users panel on the Settings screen.
2. Select Edit on the user you want to reset MFA for.
3. On their user screen, there’s a new Multi-Factor Authentication Settings section. In this section, you can see if the user has set up at least one MFA method successfully.
a. If their MFA Status is Onboarded, the admin can “Reset MFA” for this user, causing the user to reverify their access the next time they attempt to log on to Positive Pay.
b. If their MFA Status is Not Enrolled, then the user has not yet completed MFA and there are no additional steps on this screen.
4. Click Update User.
What was done?
Updating Stop Payments and Voided Checks in Positive Pay
With this release, we have added the ability for FIs to upload Stop Payments and Voided checks files from their cores so that the most recent and accurate cancelled check data is in Positive Pay. Uploading Stop Payments/Voided Checks will update existing Issued Checks in Positive Pay, ensuring that exceptions are appropriately triggered for Business Client review.
If a check is uploaded with a Routing Number, Account Number, Check Number, and Amount that matches an existing Issued Check record in Positive Pay, and the IsStopPayment or IsVoided value has changed, the existing Issued Check record will be updated with the new IsStopPayment or IsVoided value.
To allow for this, we’ve updated the duplicate Issued Check detection logic so that uploaded Stop Payments and Voided checks on existing Issued Checks doesn’t trigger a duplicate exception.
Why is this useful?
Financial Institutions can upload Stop Payments and Voided checks files to ensure that Positive Pay exceptions are appropriately added to existing Issued Checks for Business Client review
As a user, how do I add a Stop Payment or Voided Check?
1. Navigate to Issued Checks in Positive Pay
2. Select Add Check
3. Select the Business Client and Account
4. Enter the appropriate check data.
5. There are two options: Stop Payment and Voided Check
a. If this is a Stop Payment, click the Stop Payment toggle to Yes
b. If this is a Voided Check, click the Voided Check toggle to Yes
6. Once complete, click Add New Check
As a user, how do I upload an Issued Checks file with Stop Payments and Voided Checks?
1. Navigate to Issued Checks in Positive Pay
2. Select Uploaded Checks
3. Select Upload File
4. Upload your Issued Checks File
a. Any checks that are uploaded and match existing Issued Checks (Routing Number, Account Number, Amount, and Check Number) that have a different IsStopPayment or IsVoided value as what’s in Positive Pay will be updated to the new value.
What was done?
Positive Pay API Updates
Integrators are now able to retrieve the External ID (optional Client ID field in the Business Client settings) via the BusinessClientsUsers API response. This will allow integrators the ability to verify whether a user has already been created in Positive Pay.
In addition to this, the following endpoints have been updated to allow for more refined settings when creating and updating business clients via API:
• UpdateBusinessClient
• AddNewBusinessClient
• AddNewBusinessClientByIntegrator
The new settings “enableACHCredit” and “enableACHDebit” are now available as properties in the ACH setting object of the API call. Integrators can add these properties to their calls and enable/disable ACH Credit and ACH Debit for their BCs by API.
By default, if “enableAch” is set to True, then both “enableACHCredit” and “enableACHDebit” will be set to True. Conversely, if “enableAch” is set to False, both ACH Credit and Debit settings will also be set to False.
Why is this useful?
This gives integrators greater API control over the initialization and configuration of new and existing business clients.
How do I use it?
1. No user action is required
Comments
0 comments
Article is closed for comments.