Skip to main content
Digital Collaborator
August 22, 2024
Parked

Authenticaton Settings for Recipients

Categories:AuthenticationeSignature
  • August 22, 2024
  • 20 replies
  • 545 views

I just found out today that if a recipient forwards the email that they receive with the link to the envelope and they already opened and authenticated their access using and Access Code, then the person that they sent the link to can open the document and basically just sign it as the first person.  This seems risky to me.  Also, the Authentication Settings for the Access Code feature basically do not allow for a person to require an access code for each new browser.  Basically, its either every single time or only once - no in between.  So all someone who is being nefarious would need to do is wait until you look at your document, allow you to enter your access code and then - boom, they’re in signing as if they were you with no record on the certificate.

https://support.docusign.com/s/document-item?language=en_US&bundleId=pik1583277475390&topicId=muh1583277327950.html&_LANG=enus

Per the Authentication Settings, "When using Access Codes with this setting, the recipient is not prompted to authenticate again after the first time, even if using a different device."

I would like to suggest that this be changed in light of the forwarding issue, to allow for this to be switched to allow for the same as Phone Authentication, SMS Authentication, and Knowledge-Based ID checks. It should be allowable to require the access code every time they log in from a different browser. Like in the setting "Any recipient must authenticate on every envelope sent from this account"

20 replies

matt.pelham
Docusign Employee
Docusign Employee
April 11, 2025

Hi ​@newtoclm.  I’d like to help, but I’m struggling to understand what isn’t working they way you’d like.  Let me share what I think the desired outcome is and how Docusign can be used to provide it.  If you could tell me where I’ve gone wrong, that would help me focus on what you need.

Desire Outcome:  To require a free authentication method each time an envelope is accessed in order to reduce the risk that others could use a forwarded Docusign email to access an envelope without being required to authenticate and potentially sign as the intended recipient.

Instructions:  From Admin → Account → Security Settings → Enable the “Every time a recipient accesses an envelope” setting under Recipient Authentication Triggers.  This will require all recipients receiving envelopes from this account to use the authentication methods set by envelope senders every time anyone attempts to access the envelope.  This includes free access codes and all other methods.

Behavior:  For every envelope sent from the account, all recipients will be required to use the authentication methods set by senders each time they, or anyone else, accesses the envelop.

To the point about using “The first time a recipient accesses an envelope per device” setting, you are correct that authentication will only be used on the first access and that if anyone attempted to access the envelope after that, there would be no authentication challenge.  That is by design to meet what customers have asked for and it is certainly less secure, so it doesn’t seem like the fit for what you want.

To the other point about using the “Recipients can skip authentication when accessing subsequent envelopes from any sender when using the same browser on a device for the following duration:” setting allowing others to access an envelope when the message is forwarded, this should not be the case unless the person who receives the forwarded email is on the same browser and same device within the duration specified.  The language used there is not clear and could easily be misinterpreted as skipping authentication if the person receiving the forwarded email had the same device and same browser.

It seems like what you described can be met and that the concerns mentioned can be addressed...at least I hope so!  If not, please be patient with me and we will get this figured out.

MPelham
newtoclmDigital CollaboratorAuthor
Digital Collaborator
April 11, 2025

I agree that “allowing others to access an envelope when the message is forwarded, this should not be the case” but it was.  Not only was it not limited to the initial browser and device but it also signed as if the person who originally got it had signed it.  

I put in an enhancement.  If they fixed it, then the enhancement was completed.  If not then forwarding breaks the system if you use Skip at all.  

As you can see we had to setup as follows which is slightly less friendly if a person has a lot to sign:

 

matt.pelham
Docusign Employee
Docusign Employee
April 11, 2025

Hi ​@newtoclm .  The settings you show are what I used to test.  When I required an access code, I was prompted to enter it before I could reach the envelope.  After seeing the documents, I clicked Finish Later to close it.  I then forwarded the DS message to another email account where I tried accessing envelope several different ways:  same laptop and browser, my phone and a different browser, and even forwarded it to my wife.  In every case a free access code was required to access the envelope.  If you can reproduce this problem, we’d want our Support team to investigate in case there could be a bug.

If there are any use cases that can’t be addressed by the current functionality or if anything isn’t working as expected, please let us know.  I also sent you a private message in case you’d like to share a screen so we can look at this together.  It should never have taken so long your post to be answered and I’d like to make sure things are addressed.

MPelham
Docusign Employee
April 15, 2025

Hello ​@newtoclm,

I hope you are doing well. Just checking if you still need further assistance. To share, I mirrored your current settings and got the same results as my colleague, where an access code is asked each time when the link is forwarded, and the envelope is accessed using a different browser/ device. If this is not what you experienced, please send me a private message with your details (email and account number), and we will have a Technical expert take a closer look at this to see if it is a potential bug. Or if there is already an existing case, I can help with the follow up (kindly send me a private message of the case number). Rest assured, this will be highly prioritized. 

Please let us know if you have other concerns or questions and we'd be happy to help and are here to provide any further assistance you may need. We are converting this post as a question for now, and we look forward to hearing from you. Thank you!

 

Best regards,

Melanie | Docusign Community Moderator

"Select as Best" below if you find the answer a valid solution to your issue.

newtoclmDigital CollaboratorAuthor
Digital Collaborator
April 15, 2025

Hello, 

Yes.  I know that my settings work.  That is why we set them that way.  

We wanted to allow the signers to have a window where they do not have to enter an authentication code.  That was the start of the rabbit hole with forwarding.  When we found out that if you use that setting, the forwarded envelope could be signed by the next person as if they were the first person without any indication or notice or traceability, that is when we set our settings to the above.  

According to Matt.Pelham above, I believe he indicated that the settings may have been updated to allow you to choose, allow “the first time” and it will not allow the forwarded email to be used without an access code by the new person, however I have not tested that out since it was updated.  

The reason I know that this was not working is that an officer forwarded an email to another officer asking him a question and that officer signed the contract without using an access code.  The first officer went to sign and it said it was already signed and indicated that he was the one that signed it.  Meanwhile, he did not.  We then did two more tests and forwarded envelopes were able to be signed as long the person forwarding had used their access code to open the item first.  If they did not enter the access code then the person who received the forwarded item had to enter an access code. It is distinctly possible that the per device was not there when we first opened the ticket.  If it was, then at the time of my original post (as well as others) it was not per device as indicated as the forwarded email was on a different device.

We opened a support ticket at that time and they said “don’t forward” and yep, that’s right - basically.  We opened an enhancement.  From the flurry of activity on this post the last couple of days, it seems that this may have been fixed since the enhancement request was submitted.  As the person who submitted the enhancement request does not receive notice that it was completed (mostly), I am glad it went through, or at least according to your testing.  I, however, have not had the opportunity to confirm that this is the case.  

We also put in an enhancement request to force the use of another authentication method at the ORG company level (for all accounts) with the inclusion of the “free” methods or the other “pay” methods.  I don’t think that happened yet. The ORG would like to dictate the use of access codes or another method across all accounts.  

Also, I have not tested the Skip options at this time.  It looks like the option: Recipients can skip authorization when assessing subsequent envelopes from same sender…. would help with recipients not having to repeatedly entering codes, but I am guessing there is a reason we have that switched off.  It’s been a hot minute since we set up our e-sig side.   

 

Hopefully the first part of the enhancement request truly is corrected and myself and others no longer need to worry about which Trigger Option we choose. 

Thank you for the feedback.

Docusign Employee
April 15, 2025

Hello ​@newtoclm,

Thank you for getting back to me. Currently, the process is still the same. If you use "The first time a recipient accesses an envelope per device," then the Access Code requires one use as highlighted in the documentation: Authentication Settings.

In my understanding, Matt is saying that if you change your settings to "Every time a recipient accesses an envelope" this will solve the concern (because the Access Code would be required every time, no matter which browser the envelope is opened through). I understand this is your workaround and current settings, and I'm glad it is working as expected. However, we understand that your requests are specific.

I received your message and found your Enhancement request, EMT-3499, which is currently under review. All of the Docusign Release Notes are available here. We apologize for any inconvenience this might have caused you.

Don't hesitate to let us know if you have any questions or need further assistance. Thank you and have a great day!

 

Best regards,

Melanie | Docusign Community Moderator

"Select as Best" below if you find the answer a valid solution to your issue.

Docusign Employee
January 2, 2026
The following idea has been merged into this idea:

All the votes have been transferred into this idea.
Docusign Employee
January 9, 2026

Thank you for sharing this idea with us, ​@newtoclm! Here's a recap of your request:
1. When an envelope is forwarded, the recipient should be required to re-enter the access code. Enhance access code settings to require re-authentication for each new browser or device—mirroring paid options in "The first time a recipient accesses an envelope per device, where the recipient must pass authentication again when attempting to access the envelope from a different browser or a different device.
2. Add Access Code as an option under the authentication setting: “Any recipient must authenticate on every envelope from this account”. Additionally, allow Access Code for the Skip Option, not just paid methods.

We’ve reviewed the suggestions and truly appreciate the thought behind it. At this time, we’re not planning to pursue this request, so we’ve marked it as parked. While it’s not on our current roadmap, ideas like yours help shape future priorities if things change.
Thanks again for contributing your input.

 

Regards,

Melanie | Docusign Community Moderator

Docusign Employee
January 9, 2026
Idea SubmittedParked
newtoclmDigital CollaboratorAuthor
Digital Collaborator
January 12, 2026

Bummer.  My Information Security department has this as a major red flag and flaw with using docusign e-signature which they follow up on every quarter.  I was hoping that there would be a fix so they didn’t rethink the safety of e-signatures.