Lucy Awareness
Visit our WebsiteContact Support
  • Wiki Overview
  • Guides
    • Quick Guides
      • Create Your First Campaign
        • Adding a New Client
        • Register an Attack Domain
        • Campaign Setup
          • Selecting an Attack
          • Attack Settings
          • Awareness Settings
          • Recipients
          • Review
        • Whitelisting
    • Installing Lucy
      • On-Premise vs Cloud Installation
      • Architecture
      • Hardware Requirements
      • Network Communication
      • Installing Lucy
      • Post Installation
    • Manage Blacklisted Domains
      • Managing Google SafeBrowsing Alerts
    • Whitelisting a Lucy Server
      • Google Workspace Whitelisting
      • Microsoft O365 Whitelisting
      • File Attack Whitelisting
    • Attack Simulations
      • Attack Types
        • Data Entry Attack
        • Hyperlink Attack
        • File Attack
        • Portable Media
        • Smishing
        • Lures
        • QR Codes
        • Ransomware Emulation
        • Technical Malware Test
          • Malware Toolkit Test Suite
        • Mail & Web Filter Test
        • Email Spoofing Test
      • Attack Template Customization
      • Firewall Protection Interval
      • Email Tracking Technologies
      • Advanced Information Gathering
      • Regular Expressions in Login Fields
      • Copy a Website
      • Redirecting Users
    • Awareness Training
      • Awareness Template Customization
      • Awareness Only Campaigns
        • Using Multiple Awareness Trainings
      • Use extended method of tracking the end of the quiz
    • Reporting Plugin
      • Deploying Office 365
      • Deploying Outlook Native
      • Deploying Gmail
  • Application Screens Reference
    • Statistics Dashboard
    • Campaigns Dashboards
    • Campaigns
      • New Campaign
        • Wizard Mode
          • Selecting an Attack
          • Attack Settings
          • Awareness Settings
          • Recipients
          • Review
        • Expert Mode
      • Campaign Settings
        • Configuration
          • Base Settings
          • Awareness Settings
          • Attack Settings
          • Schedule
            • Schedule Plan
          • Recipients
        • Advanced Settings
          • User Settings
          • Filters
          • Custom Fields
          • Reminders
        • Campaign Checks
        • Logs
        • Results
          • Summary
          • Statistics
          • Reports
          • Exports
    • Templates
      • Attack Templates
      • Awareness Templates
      • File Templates
      • Report Templates
      • Campaign Templates
      • Training Diploma
      • Download templates
      • Variables in Lucy
    • Users
      • Recipient Groups
      • End Users
      • End User Portal Settings
      • Administrative Users
      • Reputation Levels
    • Settings
      • Common System Settings
        • Domains
          • Supported TLDs
        • Firewall
        • Web Proxy
        • Mail Settings
        • SMTP Servers
        • SSL Settings
          • SSL for Campaigns
        • SMS Settings
        • Filter Settings
        • API Whitelist
          • API Routes
        • LDAP Servers
          • LDAP Sync Tool
        • LDAP Settings
        • Azure Applications
        • Azure AD Settings
        • SSO Configuration
      • Advanced System Settings
        • Advanced Settings
        • SSH Password
      • Submitted Email Settings
        • Custom Rules & Score Factors
        • Abuse Reports
        • Incident Autoresponder
        • Plugin Settings
      • Clients
        • Client Invoices
        • Client Invoice Settings
      • Backup and Restore
        • Backup Settings
      • Benchmark Sectors
      • Whitelabeling
      • File Browser
    • Incidents
    • Support
      • Status
        • Status
        • System Monitoring
        • System Health Check
        • Notifications
      • System Tests
        • Test Email
        • Performance Test
        • Spam Test
        • Mail Spoofing Test
        • Mail and Web Filter Test
      • System Logs
      • Manual
      • Update
      • Reboot
      • Mail Manager
      • Terms & Conditions
    • Account Settings
      • Two Factor Authentication
      • License
      • Invoices
    • Notifications
  • Release Notes
    • 5.4
    • 5.3.5
    • 5.3.4
    • 5.3.3
    • 5.3.2
    • 5.3.1
    • 5.3
    • 5.2.1
    • 5.2
    • 5.1
    • 5.0
    • Version 4
      • 4.14
      • 4.13
      • 4.12.1
      • 4.11
      • 4.10.1
      • 4.9.5
      • 4.9.2
      • 4.9.1
  • Legal
    • EULA
    • Privacy Policy
    • DPA, Customer and Partner Info
    • Service Level Agreement
    • Confidentiality of Campaign Data
  • When to Contact Us
    • Contact Technical Support
Powered by GitBook
On this page

Was this helpful?

  1. Application Screens Reference
  2. Account Settings

Two Factor Authentication

PreviousAccount SettingsNextLicense

Last updated 9 months ago

Was this helpful?

Lucy provides Email and SMS-based two-factor authentication.

Navigate to Account -> 2FA Configuration

SMS-based 2FA has been deprecated by Twilio. Please use Email-based authentication which is available on all Lucy servers from version 5.

Overview

Email-based authentication will generate secret codes directly from your Lucy server and send them to the registered email address of your administrative user.

This method is advantageous as it does not require any external third-party services.

Please note, your delivery method determines how your Lucy server will send the 2FA verification code. This delivery method is defined in the of the platform.

Setup Steps

  1. Select Email as your 2FA Method.

  1. Click Save to commit your 2FA method

  2. Click "Configure 2FA"

The following screen will prompt you to enter the token that was sent to your defined administrator email address. This token will remain active for 20 minutes.

The email received will be displayed as such:

Once the code has been entered, you have successfully integrated and authenticated your user using email-based two-factor authentication.

SMS-based 2FA has been deprecated by Twilio. Please use Email-based authentication which is available on all Lucy servers from version 5.

Overview

Lucy utilizes the Authy service for 2-factor authentication (2FA), enabling login via a security token from a mobile app or SMS.

Setup Steps

  1. Create a Twilio Account:

  2. Set Up Application:

    • In the dashboard, navigate to "Authy" → "Applications" → "Get Started."

    • Verify your phone number by entering it and the received code.

    • Name your application (e.g., Lucy) and create it.

  3. Add User and Retrieve API Key:

    • Add your first user's email and phone number.

    • Select "App Token" and enter the generated token from the Authy app on your phone.

    • Choose your created application, go to "Settings," and view your unique API key by clicking the eye icon next to "Production API KEY."

    • Copy this API key for use in Lucy.

Configure Lucy:

  1. Open Lucy's interface.

  2. Go to Settings → Advanced System Settings -> Advanced Settings

Setup 2FA for User Accounts:

  1. Each user should go to the "Account" page.

  2. Enter their phone number in the corresponding fields and save.

  3. Press "Configure 2FA" and follow the on-screen instructions.

After configuring 2FA, users will be logged out and will need a 2FA token for the next login, obtainable via the Authy mobile application or SMS.

Important Notes:

  • Email-based authentication is beneficial for air-gapped environments as it doesn’t rely on external services.

If you do not receive the code, please check your spam folder and ensure you have defined a system notification email in the .

Sign up for a free Twilio account .

Log in to the .

Paste the API key into the and save.

here
Authy dashboard
Mail Settings
Advanced System Settings
"2FA" field