A software token is obtained via the RSA Authenticator (SecurID) app, which you can install on your smartphone or tablet.
SecurID software token guide
This guide has been designed to help you use SecurID tokens as an additional authentication method.
It is aimed at both users and administrators.
Follow these steps to add the SecurID token as an authentication method to online banking for business.
A SecurID software token is a two-factor authentication (2FA) method that provides an additional layer of security to your password when you sign in to online banking.
It allows you to:
- Sign in with an auto-generated code every 30 seconds, on your phone or tablet.
- Authorize a user to sign electronic transfers.
Good to know:
A $3 monthly fee applies to each token ordered per user.
What is the difference between a physical and software token?
The SecurID software token is an alternative to the physical tokens offered in online banking.
A software token is not a physical product since it is installed on an smartphone or tablet. To use it, you’ll need to download the RSA Authenticator (SecurID) app.
What are the benefits of a SecurID software token?
Using a SecurID software token offers many advantages, including:
- Mobility: You have it with you at all times, so there's no risk of forgetting it.
- Security: It introduces an additional layer of protection against unauthorized access and hacking attempts.
1. App installation
2. Association with your account
Once the token is ordered and activated, you must associate it with your online banking account.
3. Security code generation
Once it is associated with your account, the software token generates a one-time security code which changes every 30 seconds.
4. Secure connection
When you sign in to online banking, you must enter your user ID, as well as:
- Your password
- The code generated by the SecurID software token
Important:
An employee of the Bank will never ask you for your token code. Do not share it with anyone.
The SecurID software token is secure
SecurID software tokens offer users reduced risks of loss or theft when used correctly.
Here are some practices we highly recommend adopting:
- Make sure your devices are password protected.
- Do not lend your devices to others.
- Take reasonable steps to prevent the loss of your device.
- If you lose your device, let us know as soon as possible.
Before you start:
- Note that you must be an administrator to order a SecurID software token.
- Make sure the RSA Authenticator (SecurID) app is downloaded on your device or the device of the person you are ordering for. This app is available on the App Store and Google Play for smartphones and tablets.
- If you have a business group, you need to access the main entity to order the SecurID software token.
- Before placing an order for your users, make sure you have their linking ID and device type (iPhone or Android).
Steps to follow
- Sign in to online banking for business.
- In the left menu under Administration, select Other administration options.
- Click Order SecurID tokens.
- Check the information and fill in any empty fields.
- Select your username or the username of the person for whom you wish to order a software token.
- Select the type of device used by the user.
- Open the RSA Authenticator (SecurID) application, or ask your user to open it if you are placing an order for them.
- Select Accept, then select More (...) on the bottom right of the screen.
- Select About to copy the binding ID.
- Enter the binding ID in online banking for business.
- Click on Confirm to confirm the order.
Once the token has been ordered, you will receive an email to confirm its activation after 2 to 3 business days. You can then link your SecurID software token to your profile.
Good to know:
- If you are an administrator placing an order on behalf of another user, that user must first download the RSA Authenticator (SecurID) app on their device and provide you with their binding ID.
- You cannot order a SecurID software token without a binding ID.
- If you are an administrator using a physical token to sign in, you will need to call the National Bank to temporarily change your authentication method to a password. If a user is authorized to sign wire transfers, please refer to the Transitioning from a physical token to SecurID software token (and wire transfer consideration) section for the procedure to follow.
- A $3 monthly charge applies to each token assigned to a user.
- Please be aware that deleting the RSA Authenticator (SecurID) app does not automatically cancel the $3 monthly fee for the token. To cancel the fee, you will need to switch back to password-based authentication.
- You can order SecurID tokens for multiple users by repeating the steps above.
Any administrator or user with a SecurID token must associate their token with their online banking account to use it for signing in.
Here's how to associate your SecurID token with your account:
- Sign in to online banking for business.
- In the left menu, click My profile under My information.
- Click Consult my permissions, under the Permissions section.
- In the top drop-down menu, select Authentication method.
- Under Type of access, select the With SecurID token option.
- Scan the QR code with your smartphone or tablet and click OK to finalize the setup.
Good to know:
If you are an administrator using a physical token to sign in, you will need to call the National Bank to temporarily change your authentication method to a password. If a user is authorized to sign wire transfers, please refer to the Transitioning from a physical token to SecurID software token (and wire transfer consideration) section for the procedure to follow.
Before you start:
Only administrators and authorized users can change a user’s authentication method.
Here's how to change your authentication method to a SecurID token:
- Sign in to online banking for business.
- In the left menu, click Manage access, under Administration.
- In the Users and permissions tab, find a user by entering their first name, last name or username in the search bar, then select the user.
- Click the Change Permissions button.
- Select Change the authentication method.
- Under Type of access, select the With SecurID token option.
- Click on Confirm.
Good to know:
If you'd like to revert to your previous authentication method, consult our guide on changing from a SecurID token to a password. This will cancel the monthly fee of $3 per token per user.
To replace a physical token with a SecurID software token, you must first temporarily switch back to using a password.
Beware: You will not be able to authorize wire transfers as long as your authentication method remains password-based. The wire transfer feature will be restored once your authentication is switched to the software token.
If a user is authorized to sign wire transfers, their administrator must:
- Temporarily revoke the user's signing rights.
- Switch from a physical token to password-based authentication.
- Reinstate the signing rights once the SecurID software token has been successfully activated.
For more information, consult our guide How do I change the authentication method from a SecurID token to password?
Before you sign in to online banking with a SecurID software token, make sure you have:
- Your user ID
- Your password
- The RSA Authenticator (SecurID) app installed and activated on your phone.
Then, follow these steps:
- Go to https://www.nbc.ca/business.
- Click Sign on the top right corner of the screen, and then on Business.
- Enter your user ID and your password. Then click Sign in.
- Enter the 6-digit code displayed on the RSA Authenticator (SecurID) app on your phone.
- Click Confirm.
For additional help, watch our Sign in with SecurID token demo.
Important:
If you are unable to sign in with a SecurID software token, check your authentication method:
- Under Administration, click Manage access.
- Select the Users and permissions tab.
- Enter your first name, last name, or user ID, and make your selection.
Consult the How do I change the authentication method from password to a SecurID token? page to learn more.