MFA Requirement for FE and RE
- Does the new MFA requirement accept hardware authentication like a Yubikey? This is widely supported now, but unfortunately, I don't see Blackbaud on this list:
- I'd like to officially request this support ASAP. We have a mixed bag of people who use iPhones, Android, MacOS, Windows, and different devices at home vs work, etc. Not everyone is comfortable using business authentication on their personal devices. Being able to have a portable and encrypted hardware authenticator would be immensely useful here, especially if we already own one that we can add Blackbaud to. Also, SMS is generally unencrypted - not the best choice for authentication codes on financial software logins (despite banks continuing to do this, but then banks are often behind in security technology).
- 2nd question: The knowledgebase pages the MFA emails link to explain how to turn MFA OFF as well as how to use it. Will we be allowed to turn it off on a person by person basis, or is MFA going to be absolutely required as the email stated? (Maybe the KB pages need updating here.)
Thank you very much!
Comments
-
Absolutely agree with @Roberta A Gilbert on needing access to a hardware authentication option. Not all of our users are comfortable with using their personal (phone) devices for business authentication, which would be out of step with our existing user practices. (For example, we don't use our own personal computers when remoting into work - we use work-issued laptops, to avoid security vulnerabilities.)
In a system like RE where fundraisers use the software on the road, you can't be restricted to a business landline for your two-factor authentication. Blackbaud's new requirement, therefore, requires users to register their personal cellphone numbers, which seems unacceptable.
Our bank provides us with a fob specific to our user and which requires an additional PIN number to access. Can BB provide us with the option to implement fobs?
2 -
I asked, earlier this week, and BB is not yet supporting a hardware auth process. I have an idea already in the idea bank. You can go vote for it.
0 -
I have troubles linking to a specific idea rather than the main Ideas Bank page, so I'll add that it's idea “number” RENXT-I-5096 and titled “Enable Multi Factor Authentication on a hardware security device in addition to mobile usage.”
1 -
Heather MacKenzie:
I have troubles linking to a specific idea rather than the main Ideas Bank page, so I'll add that it's idea “number” RENXT-I-5096 and titled “Enable Multi Factor Authentication on a hardware security device in addition to mobile usage.”
Here is the link and it did take a bit of work to copy so it went directly there:
2 -
I agree this is a needed option. Our solution right now is to connect Blackbaud to a Single Sign-On provider like Microsoft, Google, Okta, etc. which support Yubikeys.
0 -
Hi @Roberta A Gilbert, similar to @Michael Panagos noted in this thread, the solution to have control over your organization's security is to establish an SSO connection between your Identity Provider and Blackbaud.
Please note that any users signing in with SSO will not be impacted by the MFA enforcement.
0 -
@Roberta A Gilbert Unfortunately, there is no option to turn it off. We have users who can't get on and establishing an SSO connection isn't a 10 minute process. So I guess if users can't access RE it must be more secure!
0 -
@Roberta A Gilbert I wanted to give you an update that I've personally verified Yubikeys do work with Blackbaud ID MFA. You can read about it in the Enable MFA with a hardware token and authenticator app (no mobile phone required) section we've added to:
0 -
Thank you so much for replying and updating the online docs! This is great news, much appreciated!
For those considering buying a hardware security key, Yubico offers a 20% educational discount on 2 or more keys to anyone teaching/working at a school. The offer is good through 12-31-22. They have other program discounts too. Thanks again!
0 -
I found the answer to my previous question, so re-posing a new one. ? Can a Yubikey key work with a Last Pass account on a PC for the purposes of logging into Blackbaud?
0
Categories
- All Categories
- 6 Blackbaud Community Help
- 209 bbcon®
- 1.4K Blackbaud Altru®
- 395 Blackbaud Award Management™ and Blackbaud Stewardship Management™
- 1.1K Blackbaud CRM™ and Blackbaud Internet Solutions™
- 15 donorCentrics®
- 359 Blackbaud eTapestry®
- 2.5K Blackbaud Financial Edge NXT®
- 646 Blackbaud Grantmaking™
- 563 Blackbaud Education Management Solutions for Higher Education
- 3.2K Blackbaud Education Management Solutions for K-12 Schools
- 934 Blackbaud Luminate Online® and Blackbaud TeamRaiser®
- 84 JustGiving® from Blackbaud®
- 6.4K Blackbaud Raiser's Edge NXT®
- 3.7K SKY Developer
- 243 ResearchPoint™
- 118 Blackbaud Tuition Management™
- 165 Organizational Best Practices
- 238 The Tap (Just for Fun)
- 33 Blackbaud Community Challenges
- 28 PowerUp Challenges
- 3 (Open) Raiser's Edge NXT PowerUp Challenge: Product Update Briefing
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Standard Reports+
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Email Marketing
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Gift Management
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Event Management
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Home Page
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Standard Reports
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Query
- 779 Community News
- 2.9K Jobs Board
- 53 Blackbaud SKY® Reporting Announcements
- 47 Blackbaud CRM Higher Ed Product Advisory Group (HE PAG)
- 19 Blackbaud CRM Product Advisory Group (BBCRM PAG)




