How to Configure Step-Up Authentication

Step-Up Authentication is a feature that lets you require additional authentication for access from outside the allowed IP addresses (i.e., outside your office network). This makes it possible to configure settings so that access from your office IP addresses is authenticated using your TrustLogin ID and password, while access from outside the office requires a One-Time Password or Client Authentication in addition to the TrustLogin ID and password.

Note: A PRO plan subscription is required to use this feature.

Note: Before enabling Step-Up Authentication, you must first configure IP Address Restriction, One-Time Password, Client Authentication, and Cookie Authentication.

Configuration Steps

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and click the "Settings" button to the right of "IP Address Restriction."

    Step-Up-Authentication_Latest-Logo-Replacement.png

  2. Click the "Edit" button, select the authentication option you want to enable for "Step-Up Authentication," and click the "Save" button.

    stepup01.png

    stepup02.png

    ① Disabled
    Access is not possible from networks other than the allowed IP addresses (outside the office).
    Click here for how to configure IP Address Restriction

    ② Client Authentication/Device Restriction
    This setting requires Client Authentication or Device Restriction for access from networks other than the allowed IP addresses (outside the office).
    Note: You must assign the option to the target members and install a certificate on member devices in advance.
    Note: The client certificate/device certificate used when logging in via the certificate import tool "Secure Authentication Suite" will no longer be required.

    Click here for how to configure the Client Authentication option
    Click here for how to configure the Device Certificate option


    ③ One-Time Password
    This setting requires authentication by One-Time Password for access from networks other than the allowed IP addresses (outside the office).
    Note: You must assign the One-Time Password option to members and configure the One-Time Password on members' mobile devices in advance.
    Click here for how to configure One-Time Password

    ④ Cookie Authentication
    This setting requires confirmation of device registration via Cookie Authentication for access from networks other than the allowed IP addresses (outside the office).
    Note: You must assign the Cookie Authentication option to members and register their devices in advance.
    Click here for how to configure Cookie Authentication

How to Configure Step-Up Authentication

Step-Up Authentication is a feature that lets you require additional authentication for access from outside the allowed IP addresses (i.e., outside your office network). This makes it possible to configure settings so that access from your office IP addresses is authenticated using your TrustLogin ID and password, while access from outside the office requires a One-Time Password or Client Authentication in addition to the TrustLogin ID and password.

Note: A PRO plan subscription is required to use this feature.

Note: Before enabling Step-Up Authentication, you must first configure IP Address Restriction, One-Time Password, Client Authentication, and Cookie Authentication.

Configuration Steps

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and click the "Settings" button to the right of "IP Address Restriction."

    Step-Up-Authentication_Latest-Logo-Replacement.png

  2. Click the "Edit" button, select the authentication option you want to enable for "Step-Up Authentication," and click the "Save" button.

    stepup01.png

    stepup02.png

    ① Disabled
    Access is not possible from networks other than the allowed IP addresses (outside the office).
    Click here for how to configure IP Address Restriction

    ② Client Authentication/Device Restriction
    This setting requires Client Authentication or Device Restriction for access from networks other than the allowed IP addresses (outside the office).
    Note: You must assign the option to the target members and install a certificate on member devices in advance.
    Note: The client certificate/device certificate used when logging in via the certificate import tool "Secure Authentication Suite" will no longer be required.

    Click here for how to configure the Client Authentication option
    Click here for how to configure the Device Certificate option


    ③ One-Time Password
    This setting requires authentication by One-Time Password for access from networks other than the allowed IP addresses (outside the office).
    Note: You must assign the One-Time Password option to members and configure the One-Time Password on members' mobile devices in advance.
    Click here for how to configure One-Time Password

    ④ Cookie Authentication
    This setting requires confirmation of device registration via Cookie Authentication for access from networks other than the allowed IP addresses (outside the office).
    Note: You must assign the Cookie Authentication option to members and register their devices in advance.
    Click here for how to configure Cookie Authentication