Multi-factor Authentication (MFA) Set Up Guide for a Lenovo ID Organization for the ThinkSmart Manager portal
Multi-factor Authentication (MFA) Set Up Guide for a Lenovo ID Organization for the ThinkSmart Manager portal
Multi-factor Authentication (MFA) Set Up Guide for a Lenovo ID Organization for the ThinkSmart Manager portal
Description
Describe the Multi-factor Authentification set up for the ThinkSmart Manager portal (portal.thinksmart.lenovo.com) users which are using a Lenovo ID for authorization.
Multi-factor authentication ensures only legitimate users can access their organizations on ThinkSmart Manager platform.
ThinkSmart Manager uses the Microsoft Authenticator app as a Multi-factor Authentification (MFA) provider.
For information on creating a Lenovo ID Organization, click: Creating a Lenovo ID Organization for the ThinkSmart Manager portal.
Note: MFA is not available for Single Sign-On (SSO) methods. For example: Okta, Microsoft Azure, or Ping Identity.
For more information on ThinkSmart Manager portal, ThinkSmart Manager mobile app, and the ThinkSmart Manager Service (TSMS), visit: ThinkSmart Manager.
Applicable Brands
ThinkSmart
Applicable Systems
- ThinkSmart One
- ThinkSmart Core
- ThinkSmart Hub
- ThinkSmart Hub 500
- ThinkSmart Edition Tiny M920q
For more information on ThinkSmart systems, visit: Lenovo Product Specifications Reference (psref.lenovo.com).
Solution
Step 1: Enable MFA on the organization level
Owners can enable MFA for all users in their organization.
- Click the profile icon.
- Select Organization Settings.
- Open Security tab.
- Select Required option in Authentication drop-down.
- . Click Confirm.
Once settings are applied, and page is refreshed, all users in your organization will see Microsoft Two-Step Verification screen. This step is required for first MFA setup. All instructions are displayed on the screen and users will need to install Microsoft Authenticator app to set up MFA.
Follow the onscreen instructions and click Proceed to enable authentication. Users will need to enter 6-digits password from Microsoft Authenticator app every time for logging in to TSM organization. If MFA is enabled on the organization level by an Owner, users will not be able to turn it off in their account since it is a required process for the whole organization.
Step 2: Enable MFA on the user's level
Users can enable MFA for their particular account if multi-factor authentication is optional on the organization level. This ability is available for all user roles. To enable, follow these steps:
- Click the profile icon.
- Select My profile.
- Open Security tab.
- Turn on Microsoft Two-Step Verification toggle.
- Click the Turn On button in the confirmation dialog.
Step 3: Reset trusted device
In case a user changes their smartphone or has any issues with MFA, they can use Reset trusted device option to set up MFA one more time.
- Go to the ThinkSmart Manager portal (portal.thinksmart.lenovo.com).
- Log in using your Lenovo credentials.
- Click Reset trusted device option.
- Check your email box.
- Follow the link in the email.
- Follow the onscreen instructions to enable MFA.
Your feedback helps to improve the overall experience