While Two-Factor Authentication and Two-Step Authentication may look similar at a first glance, they do have important differences.
Both authentication procedures involve two factors that need to be fulfilled to securely authenticate the user. For classic 2SA, these factors include the user name and password (knowledge) and a code that is sent to the users account. While this login procedure involves two steps of authentication, it does not necessarily define as two-factor authentication because the second factor may be accessed without the actual possession of the device (for example phone). A true Two-Factor Authentication includes one factor of knowledge (for example the ID) and one factor of either possession (the mobile device) or biometric identification (fingerprint). While one-time-codes generally used for Two-Step Authentication may be intercepted by hackers, that is not possible with true Two-Factor Authentication.

The basic difference between both authentication services is the
If it is possible for a hacker to obtain the factor without being in the possession of the device (for example by mirroring the SIM card or knowledge of login data), it is not a true Two-Factor Authentication but a Two-Step Authentication. If it is impossible for the hacker to obtain the possession factor without being in the actual possession of the device (for example SecSign ID), it is a true Two-Factor Authentication.
SecSign ID offers a true Two-Factor Authentication, which can be supplemented with an additional 2SA for your convenience. For the 2FA login with the SecSign ID, the user needs to provide one factor of knowledge (his SecSign ID) and one factor of possession (his mobile device) or biometric identification (fingerprint or FaceID). The SecSign ID 2SA Atlassian extension adds the factor of a user name and password (additional factor of knowledge) to this authentication procedure.
More information about the difference between 2FA and 2SA are summarized on our blog.
To activate the 2-step authentication for your JIRA and Confluence users you first need to setup the SecSign ID Atlassian plugin. More information about the plugins and the tutorial on the respective setup are available in our Atlassian overview.
ATLASSIAN OVERVIEWTo activate the feature you also need administrative rights as well as a corresponding SecSign ID that is assigned to your user name.
The 2-step authentication option (2SA) allows for an increased security on top of the two-factor authentication. Once the option is activated the user is prompted to provide his user name and password before authenticating with the two-factor authentication. If the user name and password authentication is successful, the user is then automatically promoted to complete the SecSign ID two-factor authentication. Only after both the user name and password and the two-factor authentication are successful the user is logged into the system.

Activating the option is not possible if no administrator has a SecSign ID because the system would be inaccessible for the administrator upon activating the 2SA option. Also, users can not be assigned more than one SecSign ID because a definite assignment of the user to an ID is no longer possible. User without a SecSign ID need to have an ID assigned to by an administrator to be able to login with the 2SA procedure.

To activate the SecSign ID Two-Step Authentication for Atlassian services please navigate to Administration – User management. Set the check mark at “Two-Step Authentication” to activate the feature.


For SecSign ID on-premise customers we offer complete customizations of the Login experience, from the login screen to enrollment and features for both the user and the administrator. Show your corporate identity and increase your brand recognition with your customized ID app. Contact us for more information and a customized offer.
MORE INFORMATION
We provide an ever growing list of APIs and plugins to easily integrate the SecSign ID Two-Factor Authentication in any project. An overview is available at Plugin and APIs.
We do not only offer APIs in different programming languages but also plugins for CMS, Server and VPN environments, oAuth2 and many more. These plugins use our APIs and offer additional functionalities, for example user management, easy and native installation, logging or integration in firewalls or Active Directory.
The JIRA plugin for example uses the JAVA-API. The PHP-Api and JS-API is used by WordPress, Joomla, Drupal, Typo3 and many more. The ASP.net/C#-API is used for the Windows and Cisco VPN and the C-API is used for protecting Unix SSH services. The Objective-C API is used by our AppleTV and iPhone/iPad apps.

You can experience the SecSign ID two-factor authentication and the two-factor login by simply integrating the plugin into your website or test environment. Or you can try out the login process on our website without having to register first. You already have a SecSign ID or you want one? Login now and use the portal or use our hassle free registration.
See for yourself how fast and convenient the login process using challenge-response authentication with 2048-bit key pairs is. There is no need for passwords, and no passwords or other confidential information are ever transmitted. It is easy to integrate and simple to use.
For more information about the patented SafeKey procedure and it's unique security can be found here.
If you are missing an API for the programming language you are working with, feel free to contact us and we’ll find a solution with you. If you need help with the integration into an existing system or you can’t find the plugin for your content management system you are working with, don’t hesitate to contact our support team.
On premise installations of SecSign ID offer the flexibility to connect with your preferred servers, services, and devices. And you can customize the SecSign ID with your own organization’s branding.


Choose between our SecSign ID Cloud or operate your own on-premise Two-Factor Authentication server.

Operate your own YourBrand ID app - Two-Factor Authentication customized to your needs.
Integrate SecSign ID Two-Factor Authentication in existing apps with our ready-to-use SDK.
Use the Two-Factor Authentication Server to secure your company Active Directory/LDAP. Your own Identity and Access Management System, for example for mandatory updates and additional security features.

Integration in any login environment: web, local, VPN, remote desktop, mobile logins and many more.

No need for complex integration: we have plugins for almost all environments.
Want to learn more about SecSign’s innovative and highly secure
solutions for protecting your user accounts and sensitive data?
Use our contact form to submit your information, and a SecSign sales representative will contact you within one business day.
If you need assistance with an existing SecSign account or product
installation, please see the FAQs for more information on the most common questions. You don’t find the solution to your problem? Don’t hesitate to contact the
Product Support
I am Interested in