Security FAQ

Multifactor Authentications (MFA)

Q. Does Powerpay offer multi-factor authentication (MFA)?

A. Yes. Powerpay is transitioning to MFA for Powerpay and Self Service users.

Q. What authentication is offered if a customer does not use MFA?

A. Powerpay has an additional factor of image selection beyond the user ID and password. Each Powerpay user selects a random image upon initial login. A random set of images containing the correct image is then presented for confirmation at each subsequent login. Multiple images (including the correct image) are repeated upon failed login attempts - so the correct image cannot be discerned by the fact that it is repeated.

Q. What authentication options do customers have for MFA?

A. Customers can choose to set up their MFA with 3 methods:

  • By Smartphone App named Twilio Authy.

  • By SMS or Voice Call.

  • By Email.

Q. Can users change their preferred authentication method or contact numbers after they complete the MFA setup

A. Yes, they can manage the setting via the 'Change Security Settings' page.

Q. How often are users required to authenticate via MFA

A. By default, users will be required to complete a MFA challenge (i.e. providing a one-time passcode or respond to a push notification) every time they login. Payroll administrators can modify the frequency on the User & Contact Mgmt page.Closed From the Company menu, select User & Contact Mgmt.

Q. What happen if users are unable to complete an MFA challenges or failed to verify a contact number?

A. If a user cannot provide a correct one-time password within 5 consecutive attempts OR they deny the push notifications 5 consecutive times, the account will be disabled immediately and they will require assistance to unlock.

Q. Can I use other popular authenticator app as a substitute of Twilio Authy?

A. No, Twilio Authy is the only authenticator app Powerpay MFA supports.

Q. Does the Powerpay MFA feature support using Email to receive one-time password?

A. Yes.

Q. What should I do if I lose my access to the phone I setup with MFA?

A. You can request to reset the MFA settings.  This can be done by another payroll administrator who has access to the same payroll or via assistance from your Customer Support Team. After a successful reset, users can do a fresh MFA setup for the payroll.

Q. If I access Powerpay via IAM, do I need to setup MFA again with Powerpay ?

A. No, users are not required to complete any MFA for Powerpay if they access Powerpay via Dayforce IAM application. However, they you will be required to complete MFA, if applicable, if you attempt to login via the main Powerpay login screen.

Q. Do I need to go through MFA when I switch to another payroll?

A. No, once a user logs into an active payroll, they can freely switch to another payroll attached to the account WITHOUT requiring to complete any MFA.

Q. Do I need to setup MFA multiple times if my user ID is linked to multiple companies?

A. Yes, each MFA setup is for one single company only. One workaround to avoid setting up MFA multiple times would be ALWAYS login to a designated payroll, then switch to other payrolls after successful authentication. That way you do not necessary setup MFA multiple times.

Q. What kind of verification code I will need for MFA?

A. This depends on the authentication method selected.

If you select 'Smartphone App' option, then you will first need to receive a 6-digit verification code to verify the phone number you have entered. Then the registration flow will require you to enter a 7-digit token code appear in your Powerpay account within your authy application, to complete the setup.

If you choose to use 'SMS or Voice Call' option, all you need is to enter the 6-digit code for verifying the phone number you have entered.

If you choose to use 'Email' as your verification method, then you should receive 7-digit codes for verification purpose in emails.

Q. Is there written material I can refer to for MFA?

A. Yes.

MFA Tutorial

Q. I am very interested in enabling the MFA functionality for my payroll, what can I do?

A. You can turn on MFA functionality by contacting your Customer Support Team.