Due to Australia Legislation, a requirement for Single Touch Payroll is that Digital Service Providers (COINS) who offer products and or services hosted by the client and use web services must have MFA enabled. This is a mandatory requirement under the Operational Framework issued by the ATO and in which COINS must meet the required security standards prior to consuming ATO wholesale services. The framework seeks to protect tax and superannuation related information.
This document will familiarise COINS users of changes to the login procedure and related screens, prior to MFA taking affect.
Login Procedure
Once MFA is enabled, each user will follow the new login procedure as shown in the screenshots below. The change will apply to all personnel accessing COINS.
Login Screen and User Authentication
When you attempt to log in to COINS OA with MFA enabled, you must fill in the existing login screen as usual.
When the user ID and password have been submitted, an additional form is presented that prompts you for a onetime use passcode.
At the same time an email is sent to you, to provide you with the passcode (example below):
Enter the code in the passcode field and click log in.
Provided the passcode is correct and was entered within the allowed time limit, you will be taken to your normal login page, menu and desktop.
If you enter the passcode incorrectly or after it expires, an error is shown.
You can click Cancel to be returned to the Log In page to try again.
If someone attempts to access COINS using your user ID and password, you will be notified with the passcode email message, which would alert you to this access attempt.
2. Expired Password
If your password expires, you will need to change it when you login.
The change will only be accepted after you supply the passcode
3. Reset Password
To reset your password when multi-factor authentication is enabled, click the FORGOTTEN PASSWORD link on the log-in screen.
Enter the email address associated with your user ID.
Click on email me a recovery link
COINS sends an email to that email address
Follow the link, which takes you to the password reset screen.
