Note: This scenario only applies to institutions that do not support email as a two-factor authentication (2FA) method. Permitted 2FA methods can be customized via Narmi Command under Institution Settings > Permitted Two-factor Authentication Methods.
If your institution has users who cannot enroll in Narmi Banking because they cannot receive 2FA codes to their phone (most commonly because they have non-US/international phone numbers), they can bypass the 2FA requirement if a staff member generates backup codes. Staff users with the permission "Can generate lockout codes user" can generate backup codes for customers. Only Admin-level staff users with the permission "Can generate lockout codes user" can generate backup codes for other staff users in addition to customers. Each code can only be used once.
Warning: This is a very high-risk action. You should only generate backup codes for a user if you are absolutely certain they are who they claim to be.
To generate backup codes for enrolling a user in Narmi Banking, ensure the user has completed all enrollment steps prior to the 2FA step. Once you’ve verified their identity, follow the steps below to get them past the 2FA step and finish enrollment:
From the Narmi Command sidebar, select Customers/Members.
Select the user's name from the user list.
Scroll down to the Two-Factor Authentication section and select Generate Backup Codes.
In the warning that appears, select Generate Backup Codes again to continue.
Once the backup codes appear in Narmi Command, instruct the user to refresh the 2FA enrollment page (and complete any additional steps on that page, if applicable). They should select Finish and proceed to Narmi Banking.
Immediately, once Narmi Banking opens, instruct the user to navigate to the profile menu > Settings > Security and add an authentication app (or US phone number) for future use. Note: If the user does not complete this step, they will need to call in for a backup code at each subsequent login. If the user does not already have an authentication app, they must download one.