How do I enroll in ADSelfService Plus?

ADSelfService Plus authenticates your identity using the information you provide during the enrollment process. Enrollment is mandatory for:

Note: Your admin might choose to enforce any or all the authentication techniques available in ADSelfService Plus. Based on that, you'll be required to provide the required information.

Enrollment using security question and answers

Enrollment using email address

Get verification code via email ID

Enrollment using Mobile numbers

Get verification code via mobile number

Enrollment using Google Authenticator

Prerequisite:

Configuration steps:

Enrollment using Azure AD MFA

To enable Azure AD MFA, enrollment is not required from the ADSelfService Plus portal. You must already be enrolled for authentication methods configured by your administrator in the Azure AD user portal. Contact your administrator if not.

Enrollment using DUO Security

Enrollment using RSA SecurID

For RSA Authentication, enrollment is not required from ADSelfService Plus portal. Please contact your administrator for the RSA hardware token that is mapped to your account.

Enrollment using RADIUS Authentication

For RADIUS Authentication, enrollment is not required from ADSelfService Plus portal. Please contact your administrator for the RADIUS password that is mapped to your account.

Enrollment using SAML Authentication

For SAML Authentication, enrollment is not required from ADSelfService Plus portal. Please contact your administrator to receive the identity provider credentials that is mapped to your account.

Enrollment using AD Security Questions

For utilizing AD Security Questions method of authentication, you are not required to enroll from ADSelfService Plus portal. If you are unsure about the answers for the displayed AD security questions, please contact your administrator.

Enrollment using Push Notification Authentication

Enrollment using push alert authentication

Enrollment using Fingerprint Authentication

Enrollment using Fingerprint authenticator

Enrollment using QR code Authentication

Enrollment using QR code authenticator

Enrollment using TOTP Authentication

Enrollment using TOTP Authentication

Enrollment using TOTP Microsoft Authenticator

Prerequisite:

Download the Microsoft Authenticator app on your mobile device from the Google Play Store or the Apple App Store.

Configuration steps:

Can't scan the code?

Microsoft Authenticator

Prerequisite

Download the Microsoft Authenticator app on your mobile device from the Google Play Store or the Apple App Store.

Configuration steps:

Can't scan the code?

Enrollment using Zoho OneAuth TOTP Authentication

Note: Install Zoho OneAuth in your mobile device. You can download it from the Google Play Store or the Apple App Store.

Backup verification codes

Backup verification codes

Backup verification codes are 12-character codes that you can generate and use to verify your identity. Backup codes come in sets of five. You can use these codes if you're unable to use your enrolled MFA methods for authentication or you don't have access to your MFA device. Each code can be used only once for verifying your identity during machine, VPN, and ADSelfService Plus logins or for performing any self-service actions.

Backup code generation:

The MFA backup codes section can be accessed from the:

Offline MFA

Offline MFA ensures that your identity is authenticated and the access to your machine is secured even when the ADSelfService Plus server is unreachable. ADSelfService Plus supports offline MFA during local and remote Windows logins and User Account Control prompts. It uses the following authenticators:

How do I enroll a particular machine for offline MFA?

Once you successfully complete MFA when connected to the ADSelfService Plus server, based on admin configuration, you will be prompted to enroll for any authenticators required for offline MFA. You will then either be automatically enrolled or prompted to enroll your machine for offline MFA as shown in this image:

Offline MFA

Click Enroll & Continue to enroll your machine for offline MFA and access your machine. Your machine is now successfully enrolled for offline MFA. The next time the ADSelfService Plus server is unreachable, you can verify your identity using offline MFA and continue using your machine.

How to disenroll from offline MFA?

If you do not want to continue using offline MFA in a machine, you can revoke the enrollment information. For this:

Note: The enrollment information will be erased only after this particular machine is connected back to the ADSelfService Plus server during online authentication.

Thanks!

Your request has been submitted to the ADSelfService Plus technical support team. Our technical support people will assist you at the earliest.

 

Need technical assistance?

  • Enter your email ID
  • Talk to experts
  •  
  •  
    By clicking 'Talk to experts', you agree to processing of personal data according to the Privacy Policy.

Copyright © 2023, ZOHO Corp. All Rights Reserved.