DSM Version
7.4

Secure SignIn

Overview

  • Enhances the sign-in service for DSM accounts with two sign-in methods — Approve sign-in and hardware security key
  • Provides sign-in methods that can replace the use of passwords, creating a seamless DSM sign-in experience
  • Supports DSM web portal and DSM applications' login portals
  • Integrated with Auto Block and Account Protection functions to include failed login attempts and failed identity verification in login failures
  • Requires signing in to Synology Account (Secure SignIn Service depends on this)

Approve Sign-in

  • Synology Secure SignIn mobile app supports Android and iOS devices
  • Can be used to replace the password or as the second step of the 2-factor authentication process
  • Provides seamless DSM sign-in via a single tap on a connected device
  • Offers quick setup through scanning a QR Code via the Synology Secure SignIn mobile app
  • Supports connection to Synology NAS via public IP, domain name, or QuickConnect
  • Requirements/Limitations
    • Requires the DSM push notification service; cannot operate normally if the Synology NAS cannot connect to the Synology Account
    • Available only on the Synology Secure SignIn mobile application

Hardware Security Key

  • Supports hardware security keys that comply with the U2F and FIDO2 standards for signing in to DSM account (see compatibility list)
  • Supports various key types, including USB-like external keys or built-in keys (Touch ID on macOS devices or Windows Hello on Windows devices)
  • Can be used to replace the password or as the second step of the 2-factor authentication process
  • Requirements/Limitations
    • Requires accessing Synology NAS through domain name over HTTPS
    • Does not support connection to Synology NAS via IP or QuickConnect
    • Only supports specific browsers and operating systems (Learn more)
    • The manufacturer and model of the security key supported by DSM may vary; use Synology tested and recommended products (see compatibility list)

2-Factor Authentication

  • Integrates the identity verification function in DSM for a more powerful 2-factor authentication function — in addition to a one-time verification code (OTP), users have the option to use Approve sign-in or a hardware security key as the second step
  • Supports Approve sign-in, hardware security key, and the Time-based One-Time Password (TOTP) protocol
    • Supports mobile apps such as Synology Secure SignIn, Google Authenticator, and Microsoft Authenticator that use the TOTP protocol
  • 2-factor authentication enforcement for specific user groups
  • Allows trusted devices to skip 2-factor authentication

Affiliated Utility

Synology Secure SignIn Mobile

Overview & System Requirements

  • Supports Android and iOS devices
  • Supports using one app for two verification methods: Approve sign-in and one-time verification code (OTP)
  • System requirements
    • iOS: 11.0 or above
    • Android: 9 or above
  • Screen lock will be turned on by default on the mobile device when using Synology Secure SignIn to ensure security

Approve Sign-in

  • Integrates DSM's Login Analysis to alert Approve sign-in users of abnormal login activities
  • Supports receiving real-time login requests through push notification on the mobile device
  • Supported even without push notification turned on, as long as user is able to pass screen lock
  • Supports using HTTPS connection to ensure the security of network transmission
  • Supports manual set up without signing in to DSM desktop
  • Supports using public IP, domain name, or QuickConnect to set up
  • Supports up to 20 Approve sign-in accounts
  • Limitation: Does not support accessing Synology NAS through private IP when setting up or using Approve sign-in

One-Time Verification Code (OTP)

  • Supports the Time-based One-Time Password (TOTP) standard for receiving OTP for DSM as well as for other third-party services that support the same standard
  • Supports obtaining the verification code even without network connection (NTP time synchronization is recommended to ensure the correct time on the mobile device)
  • Supports up to 500 OTP profiles per mobile device
  • Limitation: Does not support HMAC-based One-time Password algorithm (HOTP; specified in IETF RFC 4226)

Auto Backup and Sync

  • Supports backing up Approve sign-in and OTP profiles to Synology Account and restoring them when the mobile device is lost
  • Supports automatically backing up Approve sign-in accounts and OTP profiles to Synology Account from multiple devices. Data will be synced across the devices that are signed in to the same Synology Account
  • Supports automatically syncing any modifications to cloud storage
  • If there is a backup in a Synology Account, turning on auto backup and sync and signing in on a new mobile device will restore the backup