Using OTP - Dow Jones PKI Portal

Document: DJ Secure: Using OTP - Revised on 10/03/2014
Two Factor Authentication and OTP
(for mobile devices)
What’s happening?
Dow Jones is implementing two factor authentication to increase security and provide ease of use to
end users.
What is ‘Two Factor Authentication’?
When you authenticate yourself against a system two times, its two factor. This means that AFTER you
log on to DJNAMERICAS you will be prompted to enter another password that will be sent to a separate
device of your choice.
How am I impacted and what’s in it for me?
Two factor authentication will cut down on the number of passwords needed to log into various DJ
systems. This will mean another login AFTER you log on to DJNAMERICAS. And that’s it! You will be able
to access various systems without entering passwords for each one.
1|Page
How do I get there?
There are two ways to do this (step by step instructions are below):
1. Load the PKI soft token on your normal working machine.
2. Load the authentication app (OTP) on your smartphone or tablet.
Note: The Fanso Soft Token is now known as PKI Token. If you have the Fanso Soft
Token already installed in your computer, you can skip this process and go to the OTP setup,
needed for your smartphone or tablet.
Which one to get?
If you use the same machine on a daily basis, then get the PKI soft token. If you bounce around to
different machines, then the authentication app is for you. You can also get both! No harm done.
The PKI token is installed on your computer, and pops up when you login. You will enter your pin in the
pop up window. Then, the first time you access a system on Single Sign On (SSO,) it will come in to play.
OTP
The One Time Passcode (OTP) is an authentication method for mobile devices (smart phones and
tablets). OTP should be used when a corporate laptop is not available.
2|Page
Quick Overview
To ensure security, you need to be on the Dow Jones corporate network to enroll in OTP. To enroll in
Dow Jones OTP (One Time Passcode) on your mobile device, you’ll need:

A smartphone or tablet: i.e. iPhone, Android, Windows Phone or Blackberry.

Your Windows login ID and password.

To install the Google Authenticator app on your mobile device from your mobile app store.
Note: To enroll more than one mobile device, you will need to provide the same OTP code.
By default, if an invalid OTP is used, the system will alert you via email.
Now, let’s get started.
How to enroll in Dow Jones OTP on a mobile device?
Step 1: Type https://token.dowjones.net/otp in the URL field to set up Google Authenticator. This will
take you to the Enterprise Token Management Web Portal Page.
3|Page
Step 2: Log in using your network User Name and Password.
Network user name
Network password
Upon logging in, you will be taken to the USB Token User Portal page, containing a barcode.
4|Page
Step 3: To set up the Google Authenticator app for your phone (iPhone Example shown), please follow
the instructions listed below:
I.
On your phone, go to App Store.
II.
Search for Google Authenticator.
5|Page
III.
Click FREE.
IV.
Click INSTALL to download Authenticator App on your mobile device.
6|Page
V.
Sign in to your account.
VI.
Click OPEN.
7|Page
Step 4: To install Authenticator App on your phone, follow the instructions listed below:
I.
Click Begin setup.
II.
Hold the phone up to the barcode, then click Scan Barcode to generate a code.
8|Page
III.
Make note of this code to enter on your desktop/laptop.
IV.
Enter code and then click Verify & Register.
882954
9|Page
The following message will appear when the PIN is verified.
(882954)
Your device is now ready and can generate codes for secure access to corporate resources from noncorporate computers and laptops.
10 | P a g e