Email OTP 📥
Starting from February 2022, Tripathon’s new security update includes e-mail One Time Password (OTP) for Tripathon Travel system users.
A pop-up will ask the agents to enter an OTP number, which will be sent to their profile’s main email address.
The user will be able to resend the OTP up to 3 times before their account gets deactivated, and they can enter the wrong OTP 3 times before their account gets deactivated. Each time the user must wait for one minute before being able to resend the OTP.
If you reactivate the agent after getting deactivated for reasons related to OTP, they will be able to have another three attempts to enter the OTP and then get deactivated again, and so on.
There are 3 levels for OTP that can be changed from the Backoffice’s agent settings:
Mandatory OTP: each time agent tries to sign in they will be asked to enter an OTP
7 Days OTP: when agent enters OTP, a cookie will be saved for that browser only (not the whole device). Whenever cookies are cleared from that browser, user will be requested to enter new OTP. Alternatively by the end of the 7day trigger, they will be asked for a new OTP, that will last another 7days as well.
The 7 day OTP is for each browser, so for example if you are using Chrome and entered the OTP, then wanted to enter from Mozella Firefox, a new OTP will be requested. However, both browsers in this case will function at the same time unless the 7 days timer is finished.
No OTP: agents will not be asked for OTP in any case.
Also note that OTP will be requested each time agent tries to edit their profile’s information.
“What to do” scenarios?
– If agent is not getting the OTP email:
First check their profile setting from back office, ask the agent about his/her email and see if it matches the email set in their profile.
For Security reasons: Do not advise the email on the profile to the agent before they advise it, and in case it is not similar, advise the first three letters of the email only and wait for the agent to confirm or complete the email
For Security reasons: Do not change the email of the agent based on chat or call conversation, only change it if they send an email requesting it from the same email that is set on their profile. Even then, you need to confirm it first verbally before changing. If agent no longer has access to that email address, contact the account manager or account executive of that agent.
– If agent received emails for OTP without trying to enter to Tripathon:
First, make sure to ask them to check if someone else (colleague or owner) is trying to enter, If not, this might be indication that their account is being hacked or attacked. The procedures for handling this is as the following:
First, make sure to ask them to check if someone else (colleague or owner) is trying to enter. If not, this might be an indication that their account is being hacked or attacked. The procedures for handling this are as follows:
1- Deactivate agent’s sign.
2- Advise your management and/or supervisor.
3- Remove permissions of agent to book, remove any credit available.
4- Deactivate all suppliers from agent settings.
5- Check the profile of the agent to see if their email address has been changed to something strange or suspicious.
6- Check the latest bookings of the agent within the last 24 hours to see if there is anything suspicious (names of the passengers, huge amounts for bookings, new destinations that are not regular for the agent). In case any suspicious bookings are
found, refer it immediately for your supervisor and/or manager
7- At that point, your manager or supervisor will advise the further actions to take.
– Agent keep on getting “you have entered incorrect log in information ” message when trying to enter.
This error occurred during the testing we did as a bug, but it was fixed. Ask the agent to reset their password from the sign in page, do not reset their password based on their verbal or text/chat request from other unrecognizable communication sources.
If the above didn’t work, ask the agent to clear the cookies and restart their device, and if that didn’t solve the issue, check with their account executive or account manager if it’s possible to remove their OTP temporarily and report it to the I.T. department.
Keep In Touch