{"id":5749,"date":"2019-12-02T14:14:12","date_gmt":"2019-12-02T11:14:12","guid":{"rendered":"https:\/\/www.protectimus.com\/blog\/?p=5749"},"modified":"2020-07-03T15:45:32","modified_gmt":"2020-07-03T12:45:32","slug":"sophos-2fa-with-hardware-tokens","status":"publish","type":"post","link":"https:\/\/www.protectimus.com\/blog\/sophos-2fa-with-hardware-tokens\/","title":{"rendered":"Sophos 2FA with Hardware OTP Tokens"},"content":{"rendered":"\n<p>Sophos solutions allow for reinforcing Sophos 2FA (two-factor authentication) with Protectimus OTP hardware tokens with one of these two methods:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Enabling \u2018Auto-create OTP tokens for users&#8217; feature. This automatic method allows for using our programmable <a href=\"https:\/\/www.protectimus.com\/protectimus-slim\">Slim NFC token<\/a> instead of the standard application for multi-factor authentication.<\/li><li>Disabling \u2018Auto-create OTP tokens for users&#8217; feature. This manual method allows for adding classic TOTP tokens <a href=\"https:\/\/www.protectimus.com\/protectimus-two\">Protectimus Two<\/a> or <a href=\"https:\/\/www.protectimus.com\/protectimus-crystal\">Protectimus Crystal<\/a> to generate the Sophos one time password.<\/li><\/ul>\n\n\n\n<p>Both methods have their advantages, but the second one is a bit more lucrative.<\/p>\n\n\n\n<p>Today we will provide you with a guide on how to implement each of the two methods for your Sophos 2 factor authentication and answer the most common questions on Protectimus OTP tokens for Sophos client authentication.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-button aligncenter\"><a class=\"wp-block-button__link has-background\" href=\"https:\/\/www.protectimus.com\/tokens\/?ref=Sophos-MFA-token-article-button\" style=\"background-color:#269400\">Buy hardware tokens for Sophos MFA<\/a><\/div>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Definitions<\/strong><\/h2>\n\n\n\n<p>Let&#8217;s give a couple of definitions for a better understanding of what comes next, so you won\u2019t have to google \u201cWhat is OTP?\u201d or \u201cwhat is a token?\u201d First things first \u2014 OTP stands for <a href=\"https:\/\/www.protectimus.com\/blog\/otp-generation-algorithms-and-token-types\/\">One Time Password<\/a>. Once generated, one OTP is valid only for one single transaction. Now let\u2019s move to the more complicated matters.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><em>OTP secret<\/em> \u2014 a completely unique 128bit encryption key, used for password creation. Each user has his or her own secret.<\/li><li><em>OTP code<\/em> \u2014 a time-limited one-time code, usually consists of 6 digits and is attached to the user passwords to allow authentication.<\/li><li><em>OTP token<\/em> \u2014 an object that assembles each of the necessary authentication elements (User, OTP secret, OTP pass).<\/li><\/ul>\n\n\n\n<p><span style=\"color: #ff0000;\">| Read also:<\/span> <a href=\"https:\/\/www.protectimus.com\/blog\/how-does-2-factor-authentication-work\/\">How does 2-factor authentication work?<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How to Enable Automatic Creation of OTP tokens in Sophos<\/strong><\/h2>\n\n\n\n<p><strong>Note: To configure programmable hardware token Protectimus Slim NFC you\u2019ll need an Android smartphone with NFC support.<\/strong><\/p>\n\n\n\n<p>Virtually every Sophos product comes with this option (Sophos UTM, Sophos Central, Sophos XG Firewall and others).<\/p>\n\n\n\n<p>For example, Sophos Central 2FA can be done via <a href=\"https:\/\/www.protectimus.com\/blog\/sms-authentication\/\">SMS<\/a> or a <a href=\"https:\/\/www.protectimus.com\/blog\/10-most-popular-2fa-apps-on-google-play\/\">2FA application<\/a>, which allows for switching to our Slim NFC hardware token. And thus upping the Sophos 2FA security level to the highest. Let\u2019s see the steps to enable this option.<\/p>\n\n\n\n<div class=\"schema-how-to wp-block-yoast-how-to-block\"><p class=\"schema-how-to-description\"><\/p> <ol class=\"schema-how-to-steps\"><li class=\"schema-how-to-step\" id=\"how-to-step-1575024666712\"><strong class=\"schema-how-to-step-name\">Go to the One-Time Password tab<\/strong> <p class=\"schema-how-to-step-text\">To do this go to the Settings section at Configure > Authentication > One-Time Password.<br\/><img decoding=\"async\" alt=\"Sophos OTP with hardware tokens Protectimus Slim NFC - Step 1\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-1.png\"\/><\/p> <\/li><li class=\"schema-how-to-step\" id=\"how-to-step-1575024982427\"><strong class=\"schema-how-to-step-name\">Enable Auto-create OTP tokens feature<\/strong> <p class=\"schema-how-to-step-text\">To permit the OTP and Auto-create tokens features, simply switch both buttons to \u2018on\u2019, don&#8217;t forget the \u2018Apply\u2019 button at the bottom.<img decoding=\"async\" alt=\"Sophos OTP with hardware tokens Protectimus Slim NFC - Step 2\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-2.png\"\/><\/p> <\/li><li class=\"schema-how-to-step\" id=\"how-to-step-1575025849291\"><strong class=\"schema-how-to-step-name\">Get the QR code with the secret key<\/strong> <p class=\"schema-how-to-step-text\">Go to the user login page at Sophos. Since we\u2019ve turned the auto-create option on, the login page now offers a QR code.<br\/><img decoding=\"async\" alt=\"Sophos OTP with hardware tokens Protectimus Slim NFC - Step 3 (QR code)\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-4.png\"\/><\/p> <\/li><li class=\"schema-how-to-step\" id=\"how-to-step-1575025713876\"><strong class=\"schema-how-to-step-name\">Configure Slim NFC for Sophos multi-factor authentication<\/strong> <p class=\"schema-how-to-step-text\">4.1. Download and launch the <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.protectimus.totpburner.nfc&amp;hl=en\">Protectimus TOTP Burner application<\/a> (available for Android only).<br\/>4.2 Turn on NFC.<br\/>4.3. Open the Protectimus TOTP Burner app and click on \u2018Burn the seed\u2019.<br\/>4.4. Scan that QR code with the secret key using your Burner app.<br\/>4.5. As soon as the QR is finished scanning, turn on your Slim NFC token. Hold the hardware device within the range of your phone&#8217;s NFC antenna, click \u201cContinue\u201d and wait for the confirmation message. Now your 2FA hardware token is ready to become your Sophos 2FA authenticator.<img decoding=\"async\" alt=\"Sophos OTP with hardware tokens Protectimus Slim NFC - Step 4 (Configure Slim NFC for Sophos multi factor authentication)\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-3.png\"\/><\/p> <\/li><li class=\"schema-how-to-step\" id=\"how-to-step-1575026104921\"><strong class=\"schema-how-to-step-name\">Log in by combining your user password with OTP<\/strong> <p class=\"schema-how-to-step-text\">Return to the User Portal and log in by combining your user password with your Sophos OTP generated using the Protectimus Slim NFC token. The password will look something like this \u2014 userpass123456, where \u201cuserpass\u201d is the password created by the user and \u201c123456\u201d is the OTP generated by the token.<\/p> <\/li><\/ol><\/div>\n\n\n\n<p><span style=\"color: #ff0000;\">| Read also:<\/span> <a href=\"https:\/\/www.protectimus.com\/blog\/two-factor-authentication-types-and-methods\/\">The Pros and Cons of Different Two-Factor Authentication Types and Methods<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How to Add Classic Hardware Tokens to Sophos XG and UTM<\/strong><\/h2>\n\n\n\n<p>The following guide is done with Sophos XG user authentication but the steps are pretty much the same for Sophos UTM two-factor authentication. The guides for Sophos UTM vs XG look alike, <a href=\"https:\/\/community.sophos.com\/kb\/en-us\/120324\">here&#8217;s the one<\/a> for the unified threat management for you to check out.<\/p>\n\n\n\n<p>1. <strong>Enable OTP.<\/strong> <\/p>\n\n\n\n<p>To do this go to the Settings section at the One-Time Password tab in Configure &gt; Authentication, switch the &#8216;Enable OTP&#8217; feature on.<\/p>\n\n\n\n<p>And set up the necessary timestep depending on the model of the classic hardware token you use:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>60 seconds for <a href=\"https:\/\/www.protectimus.com\/protectimus-crystal\/\">Protectimus Crystal<\/a><\/li><li>30 seconds for <a href=\"https:\/\/www.protectimus.com\/protectimus-two\/\">Protectimus Two<\/a><\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"426\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-5-1024x426.png\" alt=\"Sophos two-factor authentication with classic TOTP hardware tokens - step 1\" class=\"wp-image-5755\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-5-1024x426.png 1024w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-5-300x125.png 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-5-768x319.png 768w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-5-610x254.png 610w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-5.png 1145w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>2. <strong>Start adding the OTP token manually.<\/strong><\/p>\n\n\n\n<p>Press the &#8216;Add&#8217; button to manually add Sophos XG or Sophos UTM OTP token.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"669\" height=\"255\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-6.png\" alt=\"Sophos MFA with classic TOTP hardware tokens - step 2\" class=\"wp-image-5756\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-6.png 669w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-6-300x114.png 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-6-610x233.png 610w\" sizes=\"auto, (max-width: 669px) 100vw, 669px\" \/><\/figure>\n\n\n\n<p>3.<strong> Select a user and add the secret key<\/strong><\/p>\n\n\n\n<p>Select a user and add the secret key to authorize this Sophos XG firewall two-factor authentication token to the chosen user account.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"670\" height=\"256\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-7.png\" alt=\"Sophos 2FA with classic TOTP hardware tokens - step 3\" class=\"wp-image-5757\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-7.png 670w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-7-300x115.png 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-7-610x233.png 610w\" sizes=\"auto, (max-width: 670px) 100vw, 670px\" \/><\/figure>\n\n\n\n<p>Now the selected account has Sophos XG OTP switched on.<\/p>\n\n\n\n<p><span style=\"color: #ff0000;\">| Read more:<\/span> <a href=\"https:\/\/www.protectimus.com\/blog\/4-reasons-two-factor-authentication-isnt-a-panacea\/\">4 Reasons Two-Factor Authentication Isn\u2019t a Panacea<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Sophos 2FA Backup Codes<\/strong><\/h2>\n\n\n\n<p>In Sophos XG 2-factor authentication you can have 10 more emergency passcodes in case a user lost the Sophos two-factor authentication device. To create these additional codes go to the user account you want to enable them for and click the edit button. Find the advanced section and the additional codes field at its bottom:<\/p>\n\n\n\n<img loading=\"lazy\" decoding=\"async\" width=\"661\" height=\"380\" src=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-8.png\" alt=\"Sophos OTP with classic TOTP hardware tokens - backup codes\" class=\"wp-image-5758\" srcset=\"https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-8.png 661w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-8-300x172.png 300w, https:\/\/www.protectimus.com\/blog\/wp-content\/uploads\/2019\/11\/Sophos-two-factor-authentication-8-610x351.png 610w\" sizes=\"auto, (max-width: 661px) 100vw, 661px\" \/>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>By clicking the \u2018+\u2019 you will automatically create 10 additional passcodes each consisting of 6 digits.<\/p>\n\n\n\n<p>The user will have to request an additional code from the administrator.<\/p>\n\n\n\n<p><span style=\"color: #ff0000;\">| Read also:<\/span> <a href=\"https:\/\/www.protectimus.com\/blog\/google-authenticator-backup\/\">How to Backup Google Authenticator or Transfer It to a New Phone<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>FAQ<\/strong><\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1575027822759\"><strong class=\"schema-faq-question\">Which<strong> Protectimus hardware tokens can be used for Sophos two factor login verification and how much will they be?<\/strong><\/strong> <p class=\"schema-faq-answer\"><a href=\"https:\/\/www.protectimus.com\/protectimus-two\">Protectimus Two<\/a> \u2014 $10.99, <a href=\"https:\/\/www.protectimus.com\/protectimus-crystal\">Protectimus Crystal<\/a> \u2014 $11.99, re-programmable token <a href=\"https:\/\/www.protectimus.com\/protectimus-slim\">Protectimus Slim NFC<\/a> \u2014 $29.99 plus shipping.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1575027861660\"><strong class=\"schema-faq-question\">What<strong> is the minimum quantity of tokens for Sophos Firewall that can be ordered?<\/strong><\/strong> <p class=\"schema-faq-answer\">Any Protectimus order can be as small as only one token.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1575027872727\"><strong class=\"schema-faq-question\"><strong>Are there any discounts for Sophos Firewall tokens?<\/strong><\/strong> <p class=\"schema-faq-answer\">Sure, the discounts start from 50 pieces an order.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1575027884662\"><strong class=\"schema-faq-question\">Does<strong> Protectimus Slim NFC support multiple secret keys (seeds)?<\/strong><\/strong> <p class=\"schema-faq-answer\">Only one seed at a time is allowed. But the best feature of the Slim NFC token is that it can be reused. You just need to program it for another account once the initial one is no longer in use.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1575027896677\"><strong class=\"schema-faq-question\">Can<strong> I order a hardware token with my company logo?<\/strong><\/strong> <p class=\"schema-faq-answer\">Protectimus Slim NFC device can be branded from as small as one device per order. Protectimus TWO branding can be done from 1000 pieces per order.<\/p> <\/div> <\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Read more:<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/www.protectimus.com\/blog\/digital-security-risks-fintech\/\">10 Steps to Eliminate Digital Security Risks in Fintech Project<\/a><\/li><li><a href=\"https:\/\/www.protectimus.com\/blog\/2fa-chatbots-vs-sms-authentication\/\">2FA Chatbots vs. SMS Authentication<\/a><\/li><li><a href=\"https:\/\/www.protectimus.com\/blog\/time-drift-in-totp-hardware-tokens\/\">Time Drift in TOTP Hardware Tokens Explained and Solved<\/a><\/li><li><a href=\"https:\/\/www.protectimus.com\/blog\/2fa-security-flaws\/\">2FA Security Flaws You Should Know About<\/a><\/li><li><a href=\"https:\/\/www.protectimus.com\/blog\/office-365-mfa-hardware-token\/\">Office 365 MFA Hardware Token<\/a><\/li><li><a href=\"https:\/\/www.protectimus.com\/blog\/hardware-token-azure-mfa\/\">Hardware Tokens for Azure MFA<\/a><\/li><li><a href=\"https:\/\/www.protectimus.com\/blog\/two-factor-authentication-for-windows\/\">Two-factor authentication for Windows 7, 8, 10<\/a><\/li><li><a href=\"https:\/\/www.protectimus.com\/blog\/paypal-two-factor-authentication\/\">PayPal Two-Factor Authentication with Hardware Security Key<\/a><\/li><li><a href=\"https:\/\/www.protectimus.com\/blog\/mitm-prevention-and-detection\/\">Man In The Middle Attack Prevention And Detection<\/a><\/li><li><a href=\"https:\/\/www.protectimus.com\/blog\/ransomware-to-pay-or-not-to-pay\/\">Ransomware \u2013 to Pay or Not to Pay<\/a><\/li><\/ul>\n<span class=\"et_bloom_bottom_trigger\"><\/span>","protected":false},"excerpt":{"rendered":"<p>Sophos solutions allow for reinforcing Sophos 2FA (two-factor authentication) with Protectimus OTP hardware tokens with one of these two methods: Enabling \u2018Auto-create OTP tokens for users&#8217; feature. This automatic method allows for using our programmable Slim NFC token instead of the standard application for multi-factor authentication. Disabling \u2018Auto-create OTP tokens for users&#8217; feature. This manual [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":5771,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[15,329],"tags":[16,12,120,10,194,479,335,478,421,976,139,581,99],"class_list":["post-5749","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-rd","category-setup-guides","tag-2fa","tag-mfa","tag-multifactor-authentication","tag-otp","tag-protectimus-en","tag-protectimus-crystal","tag-protectimus-slim-nfc-en","tag-protectimus-two","tag-setup-guides","tag-sophos","tag-tokens","tag-totp","tag-two-factor-authentication"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts\/5749","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/comments?post=5749"}],"version-history":[{"count":28,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts\/5749\/revisions"}],"predecessor-version":[{"id":6754,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/posts\/5749\/revisions\/6754"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/media\/5771"}],"wp:attachment":[{"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/media?parent=5749"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/categories?post=5749"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.protectimus.com\/blog\/wp-json\/wp\/v2\/tags?post=5749"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}