Trusted Devices
Trusted Devices let employees reduce repeated authentication prompts while maintaining system security. When enabled, users can mark a device as trusted when completing additional authentication, allowing them to bypass that step for a limited time. The Master user enables this functionality on the Logon Setup page by setting the Allow Trusted Devices drop-down to Yes and selecting a specific number of days to trust the user's device.
Note: The Allow Trusted Devices functionality is available on the Logon Setup page under the Logon Properties section.
Quick reference
- Trusted Devices allow users to skip additional authentication on recognized ("remembered") devices.
- The Allow Trusted Devices setting must be enabled.
- Trusted device status is maintained using a secure cookie stored in the user’s browser.
- Each device and browser must be configured separately.
- Trusted access expires based on the Trusted Device Duration.
- When the cookie expires or is cleared, the user must authenticate again.
What are Trusted Devices?
Trusted Devices allow employees to remember a device after successfully completing additional authentication.
- The system recognizes the device on future logins.
- The user is not prompted to complete additional authentication again until the trusted period expires or a system-wide action or user action has invalidated the stored cookie.
Enable Trusted Devices
To allow users to trust their devices:
- Log on to Sage Employee Self Service as the Master user.
- On the System Administrator menu, select Roles and Logon > Logon Setup.
- Set Allow Trusted Devices to Yes.
When Allow Trusted Devices is enabled, the check- box appears on the Additional Authentication screen.
When Allow Trusted Devices is set to No:
- Users cannot select devices as trusted.
- Existing trusted devices are no longer valid.
- Users must complete additional authentication at every login if authentication is required.
Note: If Additional Authentication is set to None at the system or user account level, no Additional Authentication is required.
Trusted Device Duration
The Trusted Device Duration determines how long a device remains trusted.
- The trusted device cookie automatically expires after the configured number of days.
- After expiration, the device is no longer recognized as trusted and the user must re-authenticate at the next login.
Remember This Device
When Employee Self Service is configured to allow trusted devices, the system allows users to mark a device as trusted during the authentication process. Select the Remember This Device check-box on the Additional Security Verification page to skip the Additional Authentication step the next time you login on this device.
- On the ESS Logon page, enter your Username and Password.
- Click Sign In.
- On the Additional Security Verification page, enter your code or security answer
- Select the Remember This Device check-box
- Click Save.
Note: When you select the Remember This Device check-box, and successfully complete the additional authentication requirement, a secure cookie is saved on that device. Your ESS account is also updated with this information. This action allows you to skip the Additional Security Verification step; however, you will still be required to enter your Username and Password each time you login on the same device until the cookie is expired or is cleared. Each device and browser must be configured separately.
What happens when Remember This Device is selected
- A secure, persistent cookie is created for that device.
- The system generates a unique identifier for the device.
- The cookie stores the trusted status and expiration time frame.
- Future logins bypass additional authentication until the cookie expires.
What happens when the cookie expires
- The device is no longer considered trusted.
- The user must complete additional authentication at the next login.
- The user must select again to reestablish trusted status.
Changing Trusted Device settings
Changes to Trusted Device settings affect all users.
- Existing trusted device cookies are cleared.
- Users must complete additional authentication at their next login if authentication is required.
If Allow Trusted Devices is set to No:
- All trusted device cookies are cleared for all users.
- Trusted access is no longer available on the Additional Security Verification page.
Clearing Trusted Devices (clear cookies)
There are multiple ways a trusted device can be cleared in Sage Employee Self Service:
- Trusted Device cookie automatically expires based on Trusted Device Duration
- ESS Account Locked by an Administrator
- ESS Account Locked by failed logon attempts by the user
- Browser cache is cleared by user
- User changes their password using the Username and Password Help link
- Admin resets the user's password from the Logon Maintenance page
- User selects Clear All Trusted Devices from the Change Logon page
- User registers a new Authenticator app
- Admin selects Clear Trusted Devices For These Employees from the Logon Maintenance page
- Master user changes the Additional Authentication method on the Logon Setup page
- Master user also selects the Overwrite Custom Additional Authentication Set At The User Level check-box when changing the Additional Authentication type
- Master disables the Allow Trusted Device feature