How to Successfully Make Your First Connection to Alis BNP Paribas: A Beginner’s Guide

ALIS, the self-service HR portal of the BNP Paribas group, relies on the group IDP (login.extidp.bnpparibas) and requires multi-factor authentication from the first login. We observe that the majority of first login failures do not stem from an incorrect password, but from an unactivated second factor or an attempt outside the internal network without a VPN.

Multi-factor authentication on ALIS: activate the second factor before any attempt

The first login consistently fails without MFA activated. Since the generalization of multi-factor authentication on ALIS, the portal redirects each attempt to the group IDP, which requires a second factor (SMS, authentication app, or physical token). If this factor has not been configured during on-site onboarding, the system denies access without an explicit error message.

See also : How to Choose Essential SEO KPIs to Boost Your Digital Marketing Strategy

We recommend treating the activation of MFA as an administrative prerequisite, just like signing the employment contract. The procedure takes place on the BNP Paribas internal network, from a connected workstation. Attempting to complete it remotely, even via VPN, complicates the second factor enrollment sequence.

To properly prepare for your connection to Alis BNP Paribas, check with your HR manager that your IDP identifier is linked to a phone number or a token before even launching the browser.

Related reading : How to Effectively Organize Your Parenting Blog Content: Tips and Practical Advice

  • Request the MFA enrollment form from your manager or local IT support on your first day on site.
  • Verify that the mobile number entered in the HR system corresponds to your active line (temporary or foreign numbers can cause SMS reception issues).
  • Prefer the group authentication app over SMS if you frequently change your SIM card.

Middle-aged man consulting a banking connection guide for Alis BNP Paribas on a desktop computer in the office

Remote ALIS connection: why the group VPN is the only reliable channel

Connecting to ALIS from outside the BNP Paribas network is technically possible. In practice, without VPN and without MFA already activated on-site, the portal denies access. Feedback from union representatives (FO, CFDT) confirms that remote security blocks are the primary cause of first login failures, ahead of password errors.

The group VPN encapsulates the session within the internal network perimeter. The IDP portal then recognizes the IP address as legitimate and proceeds with the authentication sequence normally. Without VPN, the IDP applies geofencing and IP reputation rules that trigger a preventive block, sometimes without a readable error code.

Typical scenario for a remote worker

A new employee receives their work laptop by courier, without prior visit to the agency. They open the browser, type in the ALIS URL, arrive at the IDP page, and enter their identifier. The system prompts them for a second factor that they have never configured. The form loops endlessly.

On-site presence remains the only guaranteed method for a frictionless first enrollment. If this visit is impossible, IT support can exceptionally trigger remote MFA enrollment, but the procedure requires managerial validation and a processing time that varies by entity.

Common errors on the BNP Paribas IDP portal and resolution

The portal login.extidp.bnpparibas displays several types of blocks. Distinguishing them helps avoid multiple attempts, which can eventually lock the account.

  • ERR_BLOCKED_BY_CLIENT: this message comes from the browser, not the server. An ad blocker, a security extension, or a local proxy policy intercepts the request. Temporarily disabling extensions resolves the issue in the vast majority of cases.
  • Blank page after entering the identifier: the IDP session cookie has not been set. Clear the browser cache, then restart the connection in private browsing mode.
  • Redirect loop between ALIS and the IDP: the second factor is partially configured (number registered but not validated). Contact IT support to finalize enrollment.
  • Account lockout after several attempts: the unlock delay depends on the security policy of the entity. The HR manager or IT help desk can force a reset.

Browsers and technical compatibility

The IDP portal works optimally on browsers validated by the group. Outdated browser versions, configurations with personal proxies, or non-standard mobile browsers cause erratic behaviors. We recommend using the pre-installed browser on the work station, without modifying the default security settings.

Young man following a beginner's guide to connect to Alis BNP Paribas from his living room with a laptop

ALIS and MyHR BNP Paribas: distinguishing the portals to avoid confusion

New employees often confuse ALIS and MyHR. ALIS is the historical self-service HR portal, focused on pay slips, certificates, and leave management. MyHR, gradually deployed, covers a broader scope (evaluations, internal mobility, training). The identifiers are common, but the URLs and access rights differ according to the entity of attachment.

A successful login on MyHR does not guarantee functional access to ALIS, and vice versa. If you can access one but not the other, the issue usually stems from incomplete attachment in the group directory, not a password issue. The HR support of your entity can verify this attachment in a few minutes.

The first login to ALIS is determined before the login screen. Activating MFA on-site, verifying the attachment of your identifier in the group directory, and using the VPN for remote connection are the three technical conditions that eliminate almost all blocks. Keeping the IT help desk number of your entity handy remains the last useful safety net.

How to Successfully Make Your First Connection to Alis BNP Paribas: A Beginner’s Guide