Enable phone PIN

If you select Phone Call as an authentication mechanism for users, then those users must create a PIN to authenticate into CyberArk Identity using their phones. Before users can create a PIN, you must enable the feature in the Admin Portal. This phone PIN configuration option is only available for new tenants as of 17.10.

To enable phone PIN:

  1. Log in to the Admin Portal.
  2. Click Core Services > Policies and select the policy you want to edit or click Add Policy Set to create a new one.
  3. Click User Security Policies > User Account Settings.
  4. Select Yes in the “Enable users to configure a Phone PIN for MFA” drop-down list.

  5. (Optional) Specify the minimum PIN length users must create.
  6. (Optional) Specify the authentication profile users must use to configure and edit their PINs.

    The authentication profile is where you define the authentication methods. If you have not created the necessary authentication profile, select Add New Profile at the bottom of the drop-down list. See Create authentication profiles.

  7. Click Save.

Users can now create their PINs on User Portal > Account > Organization > Phone PIN.