By default, all users can enable multi-factor authentication on their account. In addition, account administrators can choose to require either:
All users MUST have multi-factor authentication enabled in order to sign in; or
For high security environments, require that all users (or users with particular roles) utilize a CryptoRouter issued Hardware Authentication Token (HAT) for authentication
The CryptoRouter Hardware Authentication Token (HAT) provides users with a very high degree of assurance that only the authorized user is able to access protected accounts. When an account is HAT enabled, all authentication to the account requires the use of the CryptoRouter issued HAT. This ensures that even if a physical password is compromised, access to the account is still protected.
HATs can be purchased individually or in bulk, and can either be sent to the end user directly, or to the customers office for issuance. Users can also chose to enable HAT Self Fulfillment, which will allow users to order a new HAT to be shipped to them directly, replace lost HATs, and obtain temporary multi-factor backup access while their new or repalacement device is shipping.