Fortanix Armor - Getting Started

Prev Next

1.0 Introduction

This article helps you get started with the Fortanix Armor platform.

It also describes:

  • How to sign up and log in to the Fortanix Armor platform.

  • How to create a new account and use the existing accounts on the Fortanix Armor platform.

  • How to manage an account and a user profile on the Fortanix Armor platform.

2.0 Log In and Create an Account

Fortanix Armor is a platform provided by Fortanix. You must create an account on the Fortanix Armor platform if you do not already have one.

2.1 Sign Up On Fortanix Armor Platform - New Users

If you are a new user and do not have an account on Fortanix Armor, you must sign up for Fortanix Armor to create and access your account.

To sign up for Fortanix Armor for the first time,

  1. Go to the URL https://armor.fortanix.com/.

  2. On the Login page, click DON'T HAVE AN ACCOUNT? SIGN UP. You will be navigating to the Fortanix website.

    Figure 1: Sign up for Fortanix Armor

  3. In the SIGN UP FOR KEY INSIGHT form, fill in the required user information:

    • First name: Your first name.

    • Last name: Your last name.

    • Email: Your work Email.

    • Phone number: Your contact number.

    • Country: Select your country.

    • Optionally, you can select the checkbox - I agree to receive other communications from Fortanix- see our Privacy Policy for more information.

    50.png

    Figure 2: Fill in the signup form for Fortanix Key Insight

    NOTE

    Fortanix Armor offers a 30-day trial. After your free trial expires, contact Fortanix Support for assistance with next steps.

  4. Click SUBMIT. This will take you to the Fortanix Armor SaaS Sign Up page.

  5. On the Sign Up page,

    1. The Email address, First name, and Last name fields will be automatically filled out based on the details you provided in Step 3.

    2. Create a new Password and retype the same. For more information on password requirements for Fortanix Armor SaaS user accounts, refer to Section 2.1.1: Fortanix Armor SaaS Password Policy.

    3. Select I agree to the Terms of Service and Privacy Policy and I’m not a robot check boxes.

    4. Select I’m not a robot to complete reCAPTCHA and help prevent automated abuse, ensuring only legitimate users can sign up and protect against security attacks and account takeovers.

    5. Click SIGN UP to finalize your registration and complete the sign-up process.

    Figure 3: Sign up for Fortanix Armor

2.1.1 Fortanix Armor SaaS Password Policy

Below are the password-related settings and behaviors currently applicable to all Fortanix Armor SaaS user accounts:

  • Minimum Length: Passwords must contain at least 12 characters.

  • Maximum Sequence: No restrictions for sequential characters.

  • Maximum Repetition: No restrictions for repeating characters.

  • Password Complexity: No complexity requirements are enforced. Users may choose any combination of characters if the minimum length is met.

  • Password Expiration: Passwords do not expire. Users are not required to change their passwords periodically.

  • Password Change Frequency: No mandatory frequency for password updates. Users may change their passwords at any time, but are not forced to do so.

  • Incorrect Password Attempts: Accounts allow up to 10 incorrect password attempts before lockout. After exceeding this limit, the account is temporarily locked for 30 minutes (1800 seconds). To unlock your account and log in again, enter the correct password and complete reCAPTCHA verification.

  • Password Reuse: Password reuse is restricted. Users cannot reuse their previous 4 passwords. If users attempt to use a previously used password, the following error message is displayed: “Error: The new password has been used previously. Please choose a different password.”

  • Temporary Passwords: Temporary passwords are not used or issued for the login or onboarding process.

  • Password History: The system maintains a history of the last 4 passwords, preventing reuse during password updates.

2.2 Verify the Email Address

To verify your email address after signing up:

  1. After you click SIGN UP, an email will be sent to your registered email address. If you have not received the email, click RESEND VERIFICATION EMAIL to send the email again.

    Figure 4: Account creation confirmation

  2. In the received email, click CONFIRM EMAIL or paste the URL in your browser to verify your account.

    Figure 5: Confirm account creation

  3. After account verification, you will receive the confirmation message in Fortanix Armor. Click Proceed to accounts to create your first account on Fortanix Armor. For more information on adding your first Fortanix Armor account, refer to Section 2.4: Add an Account.

2.3 Log In to Fortanix Armor Platform - Existing Users

You can directly log in to the Fortanix Armor platform if you have already signed up and have an account on the platform.

To log in to the Fortanix Armor,

  1. Go to the URL https://armor.fortanix.com/.

  2. On the Login page, you can authenticate with Fortanix Armor using any of the following methods:

    • Using password

    • Using a Single Sign-On (SSO)

2.3.1 Authentication Using Password

To log in to Fortanix Armor using the password,

  1. On the Fortanix Armor Log In page, enter the Email address and click LOG IN WITHOUT SSO.

    Figure 6: Log in to Fortanix Armor

  1. Enter your Password. Click LOG IN to log in to Fortanix Armor.

Figure 7: Log in with a password

NOTE

  • Click  Hide Password.png to view your password and click  Show Password.png to hide your password for security purposes.

  • Click Forgot password? to reset your password. For more information, refer to Section 4.2: Change or Reset Password.

2.3.2 Authentication Using SSO

The Fortanix Armor accounts can be integrated with third-party Single Sign-On (SSO) providers. When an account is configured for SSO, users in that account can log in with their SSO credentials.

To set up SSO for your accounts, refer to Fortanix Armor Identity and Access Management (IAM).

To log in to Fortanix Armor using the SSO,

  1. On the Log In page, enter the Email address and click LOG IN.

  2. Select the necessary SSO authentications that have already been set up. Follow the specific instructions for the selected SSO and log in using that configuration.

    For example, you might log in using the AZURE_OAUTH configuration.

    Figure 8: Log in using SSO

    NOTE

    If SSO authentication is not set up, Fortanix Armor will prompt you to log in with a password as explained in Section 2.3.1: Authentication Using Password.

2.4 Add an Account

After you log in, you can add a new Fortanix Armor account to access different solutions - Key Insight, Identity and Access Management, and Data Security Manager.

To add a new account for the first time,

  1. On the Add Account page, enter the Account name and click CREATE to add the new account. You can also view the other available solutions on Fortanix Armor.

    Figure 9: Add a New Fortanix Armor account

  2. After adding the account, you will navigate to the Available Solutions page to access the required solutions. For more information on the available solutions, refer to Fortanix Armor - Solutions.

Figure 10: Access available solutions

The new account created will also be added to the Accounts page.

2.4.1 View an Account Details

After you add an account, you can view its details along with the available solutions for that account.

To view and manage the account details,

  1. Click ACCOUNT DETAILS drop down menu on the top-right corner of the page.

    Figure 11: Access account details

  2. You can view the following account details: Click HIDE DETAILS to hide the account details.

    • Account ID: A unique identifier of the account. You can copy the value if required.

    • Created On: Account creation date and time.

    Figure 12: View account details

  3. Click Edit Icon to update the account name and logo. For more information, refer to Section 2.4.2: Edit an Account.

  4. Click Three dots and select Leave account to leave the selected account. For more information, refer to Section 2.4.3: Leave an Account.

  5. Click Three dots.png and select Delete account to remove the selected account. For more information, refer to Section 2.4.4: Delete an Account.

2.4.2 Edit an Account

To edit an account's details:

  1. Click the overflow menu (Three dots.png) on the account details section.

  2. Click Edit.

  3. In the Customize Account dialog box,

    • Click Add custom logo to account to update the logo.

    • Update the required name of the account.

  4. Click SAVE to update the details.

2.4.3 Leave an Account

To leave or exit from an account,

  1. Click the overflow menu (Three dots.png) on the account details section.

  2. Click Leave account.

  3. Read the details in the Leave account dialog box and click LEAVE to confirm leaving the Fortanix Armor account.

    NOTE

    You can leave the account only if that account has more than one user with an Account Administrator role.

2.4.4 Delete an Account

To delete or remove an account if it is no longer needed or contains inappropriate data,

  1. Click the overflow menu (Three dots.png) on the account details section.

  2. Click Delete account.

  3. In the Delete Armor Account: <Account Name> dialog box,

    1. Review and confirm the dependencies to be deleted.

    2. Enter the account name to confirm the deletion.

    3. Click CONFIRM to remove the account from your Armor user profile. The account will then be removed from the list with a message Account deleted successfully.

NOTE

  • Before deleting the account, ensure that all active objects, such as groups, connections, and security objects, are removed. If any active objects remain, the deletion will fail, and the account will be deactivated instead. In that case, you can delete the remaining objects from the deactivated account and then proceed to delete the account.

  • When an account is deleted, it is first deactivated. This action is irreversible. During the deactivation or deletion process, you will not be able to create or update accounts, users, groups, group memberships, client applications (apps), or security objects within the account. You will only be able to view and delete user accounts, groups, client apps, and group membership details.

3.0 Manage Accounts

All the Fortanix Armor accounts associated with your user account will be displayed on the Accounts page.

On the Accounts page,

  • Click + ADD ACCOUNT or select ADD ACCOUNT from the Select account drop-down to add a new account.

    Figure 13: Add an account

  • For the account added, click GO TO ACCOUNT to access the solutions available for that account.

  • If you have more than one account, you can select the appropriate account using SELECT ACCOUNT or the Accounts dropdown.

    NOTE

    • If you created your first account after logging in, it will be selected by default.

    • Contact the account administrator to join an existing account.

    Figure 14: Select an account from the Accounts page

    NOTE

    Switching Between Accounts

    Fortanix Armor allows you to access multiple accounts, each using its own SSO or password-based authentication method. When switching accounts, you must select the relevant authentication method and may be required to re-authenticate.

    Figure 15: Manage authentication in multiple accounts

  • You can switch between the account list view and account card view using Accounts View Toggle.png.

    By default, you can see the accounts in the card view (Accounts card view.png). Click Account List View.png to switch to the accounts list view. If selected, you can see the list of your available accounts.

    On this page, you can perform the following operations:

  1. Search for a specific account.

  2. Copy the account ID.

  3. Add a new account.

Figure 16: Access Accounts list view

Figure 17: Manage the selected account

NOTE

Only users with the Account Administrator role can edit or delete a Fortanix Armor account.

4.0 Manage User Profile

On Fortanix Armor, you can manage the logged-in user profile.

Figure 18: Manage your user profile

  • Select Profile to manage the profile details and authentication.

  • Select Sign out to log out from Fortanix Armor. If selected, you will be logged out of the platform and redirected to the Login page.

4.1 Update User Name and Email

To update your profile name and email,

  1. Select Profile.

  2. On the My Profile page, click next to the user name and email to update the new values.

  3. Click SAVE to apply the updates.

    Figure 19: Update user profile

    NOTE

    When you change your email, all your pending account invites will be removed. You will need to be invited again using your new email.

    You can view your profile creation and last log-in date and time.

4.2 Change or Reset Password

You can change your password either by updating your user profile or during the login process. The new password will only be accepted if it meets all security requirements, including a minimum length of twelve characters.

For more information on password requirements for Fortanix Armor SaaS user accounts, refer to Section 2.1.1: Fortanix Armor SaaS Password Policy.

4.2.1 During User Profile Update

To update your password while editing your user profile,

  1. Select Profile.

  2. On the My Profile page, select CHANGE PASSWORD to create a new password. If selected,

    1. Enter your current password.

    2. Enter the new password.

    3. Confirm the new password.

    4. Click CHANGE PASSWORD to update your password.

4.2.2 During Login

You can also change your password using Forgot password? on the Log In page.

To reset the password,

  1. On the Log In page, click LOG IN WITHOUT SSO.

  2. Click Forgot password?.

  3. Enter your E-mail address used during login.

  4. Select I’m not a robot to complete reCAPTCHA and confirm that the request is made by a human, not an automated bot or malicious software.

  5. Click RESET PASSWORD.

  6. You will receive an email at the address provided in Step 3.

  7. In the received email, click the password reset link. On the Reset password page,

    1. Enter New password.

    2. Re Confirm new password.

    3. Click SAVE PASSWORD to reset your password.

  8. If your password is reset, you will be redirected to the Log In page to log in with the new password.

4.3 Configure Two-factor Authentication (2FA) at User Level

Multi-factor Authentication (MFA), specifically Two-factor Authentication (2FA), can be configured at both the user and account levels in Fortanix Armor.

For more details on setting 2FA at the account level, refer to Fortanix Armor Identity and Access Management (IAM).

When 2FA is enabled for a specific user, that user will be required to set up 2FA before logging into their account.

Ensure the following before configuring the 2FA at the user level:

  • You are a Fortanix Armor user

  • 2FA is currently supported using the FIDO2/WebAuthn standard, which is supported by devices such as YubiKey. This also works for FIDO U2F authenticators since FIDO2/WebAuthn is backward compatible with them.

NOTE

  • Your device must support FIDO2/WebAuthn to use 2FA.

    • Fortanix Armor uses FIDO2/WebAuthn for the 2FA requirements.

    • Fortanix Armor supports FIDO2 devices that provide either packed or fido-u2f attestation. See “Defined Attestation Statement Formats” section in https://www.w3.org/TR/webauthn-2 for more details.

After users are authenticated using a password, an additional layer of security can be added by enabling 2FA through a device that supports U2F or FIDO2/WebAuthn.

Fortanix Armor supports security keys for 2FA, leveraging FIDO2/WebAuthn-compatible devices (for example, YubiKey).

To enable 2FA at the user level,

  1. Select Profile.

  2. On the My Profile page, select Enable for Two-step Authentication. The 2FA is disabled by default.

  3. On the Two-step Authentication dialog box, enter the profile password.

  4. Click NEXT.

  5. Select where you want to register your security key based on your operating system:

    Linux:

    Perform the following steps:

    1. Select the USB security key option.

      Figure 20: Set security key for Linux

      b. Touch your YubiKey device and enter the PIN for your security key.

      c. Click Next.

      Figure 21: Enter the security key

      d. Touch your YubiKey device again to complete the registration.

    Windows:

    Use Security Key option to register your key. Avoid using methods like Windows Hello, Android/iOS devices, or a Google account, as they may cause errors.

    Perform the following steps:

    1. Select Windows Hello or external security key.

      Figure 22: Select the security key register type

    2. Click Use another device.

      Figure 23: Select your choice

    3. Select the Security key and click Next.

      Figure 24: Select the 'Security Key' option

    4. Click OK.

    5. Enter your Security Key PIN and click OK.

      Figure 25: Enter your security key

    6. Touch your YubiKey device once and click OK to register your security key.

  6. After successfully registering the security key, on the Two-step Authentication dialog box, assign a name and click NEXT.

  7. After your security key has been added, Recovery codes will be generated. Ensure to save them as they are used to access your account if you cannot connect the security key to the system.

  8. Click FINISH to add the security key to the Two-step Authentication section. 2FA will then be enabled at the user level.

  9. After the security key is added, you can perform the following actions:

    Figure 26: Manage a security key

    • Click ADD SECURITY KEY and follow Steps 3 to 8 to add another security key, if required.

    • You can edit the security key details using . If selected, you can change the name of the key and click SAVE to update the new value.

    • You can remove the security key if it is no longer needed using . If selected, on the Disable 2FA Authentication dialog box, click DELETE to remove the security key.

      NOTE

      If your Fortanix Armor account has account level 2FA enabled, you must disable it before deleting any user level 2FA.

    • You can regenerate the recovery code if required. To regenerate the recovery code,

      1. Click REGENERATE under Recovery codes.

      2. On the Regenerate recovery code dialog box, enter the profile password and click NEXT.

      3. Click REGENERATE on the Regenerate recovery code dialog box.

      4. The recovery codes will be regenerated. Ensure to save them and click CLOSE.

    • You can disable the 2FA configured. To perform this,

      1. Click DISABLE.

      2. On the Disable 2FA Authentication dialog box, enter your profile password and click NEXT.

      3. Click DISABLE to deactivate the 2FA configured.

  10. After 2FA is enabled, an additional authentication layer will be added to the password-based user authentication during login.

    For example, you will see the hard_key being added during login. Follow the necessary steps to log in to Fortanix Armor using 2FA.

    Figure 27: 2FA during login

4.4 Accept Terms and Conditions

On the My Profile page, you must select the You have accepted the latest Terms of Service and Privacy Policy checkbox to accept the latest terms and conditions of Fortanix Armor.

4.5 Delete User Profile

To delete your user profile from the Fortanix Armor platform permanently,

  1. Select Profile.

  2. On the My Profile page, click Delete my user profile. If selected,

    1. The dialog box with the details will be displayed. Read the details and enter your current password to confirm the profile deletion.

    2. Click DELETE MY PROFILE PERMANENTLY to delete your user profile permanently.