Using OTPs to authenticate
You can use a one-time-passcode (OTP) to log in to the Admin Portal. You use a third party authenticator (like Google Authenticator) or the Centrify client application to scan a Privileged Access Service generated QR code and configure the OTP. Centrify supports any authenticator app that support the OATH TOTP standard. Refer to https://openauthentication.org/about-oath/ for more information.
If an internet connection is not available, you can also use an offline OTP to log in to the Admin Portal. Users must log in first in online mode before an offline OTP profile is created.
Important: Your system administrator must enable these features before you can use them.

- Log in to theAdmin Portal > Profile.
-
Click Security > OATH OTP Client.
The QR code displays.
-
Use a third party authenticator application or the Centrify client application on your device to scan the QR code.
-
A passcode is displayed on the third party authenticator application and on the Passcodes page of the Centrify application.
You can now enter the passcode to log in to Privileged Access Service. This authentication works across tenants. On the Passcodes page of the Centrify application, you can tap the relevant code to silently send that code and authenticate for the relevant user/endpoint.

- Log in to theAdmin Portal > Profile.
-
Click Passcodes, then select Offline OTP Client.
-
Click Actions > Setup Offline OTP.
The QR code displays.
-
Use a third party authenticator application or the Centrify client application on your device to scan the QR code.
A passcode is displayed on the third party authenticator application and on the Passcodes page of the Centrify application.
-
Enter the verification code generated by the authenticator app, then click Verify.
You can now enter the passcode to log in to Privileged Access Service when your device is offline.
On the Passcodes page of the Centrify mobile application, you can tap the relevant code to silently send that code and authenticate for the relevant user/endpoint.

If your OTP fails, you might need to resynchronize your OTP with the Privileged Access Service.