Question
I have some questions about making OTP entry mandatory for Admins.
Answer
Below are frequently asked questions and answers regarding making OTP entry mandatory for Admins.
Do Admins need to enter OTP every time they sign in?
In principle, OTP entry is required every time you sign in to HENNGE Access Control from a browser or app.
However, as long as you remain logged in on the same browser, etc., you will not be prompted for additional entry even when performing SSO to other services.
If you explicitly sign out or your Session Status expires, you will need to sign in to HENNGE again, and you will be asked to enter your OTP again at that time.
I already use OTP for my Admin account. Will anything change due to this update?
Nothing will change for Admin accounts that already use OTP. No additional Configuration is required.
For my Admin account, I use OTP only under specific conditions, such as "OTP is required when no Device Certificates are present." Will anything change due to this update?
Yes.
Currently, the experience is such that "OTP is not used under specific conditions (e.g., when logging in from a device with Device Certificates installed)." This will change to an experience where "OTP is required under any condition (e.g., even when logging in with Device Certificates)."
I am using the initial Admin account with a Password. Can I register OTP for a user and continue using this account as is?
Yes, you can continue using the initial Admin account as is.
By registering OTP for your current account, you will be able to continue using it even after migration.
For details on how to configure this, please refer to the following articles.
[Access Control] Configuration for Receiving OTP (One-Time Password) via Connected Application
[Access Control] Configuration for Receiving OTP (One-Time Password) via Email
We outsource administrative tasks, and it is difficult to configure a Smartphone. What should we do?
If you are unable to use a Smartphone app (such as HENNGE Lock), you can use the method of receiving a one-time password via email.
[Access Control] Configuration for Receiving OTP (One-Time Password) via Email
I use two accounts: one dedicated to administration and my own Personal account. Is my Personal account also subject to this requirement?
This requirement applies only to accounts with 【Admin】 privileges that can access the HENNGE Access Control Administration screen.
Accounts with General User privileges that do not have "Admin" in their Role name are not subject to this requirement.
※How to determine whether your account is an Admin account:
If, when accessing the User Portal screen (ap.sssso.hdems.com/portal/your company's domain), there is no "Administration" icon, that account does not have the "Admin" Role.
With regard to making OTP entry mandatory for Admins, is it necessary to notify General Users or distribute a manual to them?
This update applies only to "Admin accounts."
Therefore, there is no need to notify General Users or distribute a manual to them.
We use HENNGE to Federate with Microsoft 365. Is it acceptable to set a Microsoft 365 Email Address as the destination for receiving OTP?
Please receive OTP at an Email Address that can be accessed without requiring OTP, or use an OTP app on your Smartphone.
Since a HENNGE OTP is required to sign in to Microsoft 365, if the destination Email Address is within Microsoft 365, there is a risk of getting into a situation where "you want to log in to check your email, but you cannot see the OTP email needed to log in."
I already have to enter OTP when logging in to HENNGE, and now I'm also being asked for MFA on the Microsoft side. This is honestly a hassle—is there anything that can be done about it?
By performing OTP authentication once on the HENNGE side, you can skip MFA on the Microsoft 365 side.
The Configuration is very simple and can be completed in a short time. Since it can significantly reduce the effort required for each Login, we encourage you to take this opportunity to set it up if you have not already done so.
For details, please refer to the following release information.
Release Information: [Access Control] Added a feature to skip Microsoft 365 multi-factor authentication when specific authentication is performed in Access Control in the 3rd week of February 2026
We have multiple Admin accounts. Can we check the Configuration status in a Summary list?
You can Search for the OTP Configuration status of Admins from the "Filter" option in the Users menu of the Administration screen.
You can filter in detail by Admin Role or Configuration status.
You can Search for "Admins with OTP Not set" using the following conditions.
- Role:Admin
- Admin Role:All
- OTP:"-"
Even though OTP has already been set, a screen prompting you to register OTP for a user is displayed. Why does this happen?
The current Configuration type may not be correctly detected on the System side.
We apologize for the inconvenience, but please reconfigure the OTP Notifications.
Registering OTP for a user is already required for Admins. Isn't OTP entry for Admins only going to become mandatory starting from December 2026?
For environments where the HENNGE One Tenant was set up on or after Tuesday, July 14, 2026, OTP entry for Admins is enforced, and it is not possible to change whether OTP entry is required.
In this case, please refer to Release Information: [Access Control] Second Week of July 2026 - Addition of Dedicated Setup Screen for Administrator Accounts with Unconfigured OTP to configure OTP.
Translation Disclaimer
This article has been automatically translated from the original Japanese version for your convenience.
While we strive to ensure accuracy, we cannot guarantee its reliability or completeness.
In the event of any discrepancies or questions regarding the content, the official Japanese version shall prevail.