Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.
Really disappointing that you have to go to a third party, and pay additional fees, because HCL refuse to implement something that there is a clear business case for in many organisations that use Domino.
Once again, a new feature that would be great if only HCL would take that final step.
Since this has been denied and we solved it long ago, I'll just let you know how we did it. We used a product called CYONE https://cyone.eu/products-and-solutions/two-factor-authentication/ It's happily running on our (currently) HCL Domino 14.5 FP1 Server and it has options to restrict to just email if needed.
Regarding NIST compliance. The guest is correct to say that "NIST SP 800-63B, Section 5.1.3.1, prohibits the use of email as an out-of-band authenticator because it does not reliably prove possession of a specific device."
However our threat model is primarily concerned with offboarding of our customers at other external institutions over which we have no control and are not notified. Our "Email Only" policy is a compensating control designed to leverage the fact that the only thing we can rely on those external institutions to do is to block email to users when they leave.
In this era of BYOD devices, having a user-installed MFA app on their phone or using the phone's SMS - or even providing the user with a physical token is only effective if you have control over the user and knowledge that the user has left that place of employment.
2FA codes do not superseed propper user access control, e.g. by putting the user into an access deny/terminations group. So I'm sorry but I have to reject this idea.
FYI - NIST SP 800-63b prohibits the use of email for 2FA:
https://pages.nist.gov/800-63-FAQ/#q-b11
"Q-B11:
Is the use of email acceptable in two-factor authentication?
A-B11:
NIST SP 800-63B does not allow the use of email as a channel for single or multi-factor authentication processes. This is specified in Section 5.1.3.1, Out-of-Band Authenticators:
[Authentication] methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentication."
We have the same issue. Additionally, some of our clients are prevented from using their mobile phones on site at their work place so the emailing the code would be the only option.