
When discussing access to the ALIS portal of BNP Paribas, most guides describe a simple scenario: an employee, their professional position, a VPN connection. The problem is that this situation does not cover everyone. Apprentices, interns, agency employees on shared positions, or those teleworking from personal equipment often find themselves facing an authentication wall without understanding why.
ALIS Access for Non-Standard Profiles: Apprentices, Interns, and Shared Positions
The ALIS portal (accessible via alis.hr.bnpparibas) centralizes HR documents, pay slips, and career tracking. Its architecture is based on a group SSO with redirection to the BNP Paribas IDP. In practice, the employee does not create a separate account: they authenticate using the group’s unique identifier, which automatically redirects them to their personal space.
For a permanent employee with a position enrolled in the internal network, this redirection works seamlessly. The browser recognizes the machine certificate, the IDP validates the session, and access is granted in a few seconds.
The case for apprentices or interns is different. Their workstation is not always enrolled in the group’s information system. Some share a computer in the agency, while others use equipment from their school. The SSO does not recognize them as trusted terminals, which blocks the connection or triggers redirection loops.
The first step for these profiles is to check with their manager or local IT support that their group identifier is active and linked to ALIS. A signed contract is not enough: the link to the HR portal requires a separate activation, sometimes with a delay of a few days after starting the position.
To better understand how the portal works and its prerequisites, a detailed guide on secure access to Alis BNP Paribas exists and covers both common and atypical situations.

ALIS Multi-Factor Authentication: What the Second Factor Changes for Teleworking
Since the latest security developments of the group, off-network access requires a second authentication factor. Simply entering your password is no longer sufficient. This second factor can take the form of a push notification on a corporate mobile app, a temporary code sent via SMS, or a physical token distributed by the IT department.
Have you ever tried to log into ALIS from home and received an error message after entering the correct password? It is likely related to the lack of enrollment of your second factor.
Enroll Your Second Factor Before You Need It
Enrollment of the second factor must be done from the internal network. The employee must associate their mobile device or retrieve their physical token before leaving the office. If this step has not been completed, the connection from an external network will systematically fail, without an explicit error message in most cases.
For an apprentice who only comes to the company three days a week, or an agency employee who regularly changes positions, this constraint has a concrete impact. Here are the steps to follow:
- Log in from an internal BNP Paribas network workstation and access the security settings of their group account.
- Associate a mobile phone number or install the authentication app recommended by the IT department.
- Validate a first multi-factor connection test before attempting remote access, to confirm that the enrollment is operational.
- Keep the IT support number handy in case of a blockage, as the reset of the second factor cannot be done independently.
Without prior enrollment, no remote access to ALIS is possible. This is the most common blockage point for newcomers.
ALIS Portal Outside VPN: Limits to Know
Another common misunderstanding concerns the VPN. On the internal network of BNP Paribas, ALIS is directly accessible. Off-network, the situation depends on the type of position and the security policy applied to each entity of the group.
Some employees have a corporate VPN installed on their work laptop. In this case, activating the VPN restores an internal network connection, and ALIS functions as it would in the office.
Personal Workstations and Browser Access
For those without a VPN (a common case for interns or employees in temporary mobility), the portal alis.hr.bnpparibas remains accessible via a standard web browser, provided that the second factor is active. The external portal functions as a distinct entry point from the intranet, with features sometimes reduced compared to internal access.
The available documents (pay slips, certificates, training tracking) remain viewable. However, some advanced management functions or hierarchical validation may be restricted depending on the connection context.

Personal Data Security on the ALIS Portal
ALIS concentrates sensitive information: payroll data, bank details, contractual documents. Therefore, the question of security is not limited to technical access; it also concerns connection habits.
- Never save the ALIS password in a shared browser, especially on a workstation in an agency used by multiple employees.
- Always log out after each session, even on a personal professional workstation.
- Check that the URL starts with alis.hr.bnpparibas before entering your credentials, to avoid phishing attempts.
For hybrid profiles, vigilance is even more necessary as they alternate between several work environments. A workstation at school, a workstation in the agency, a personal computer in the evening: each context has its own risks.
The ALIS portal of BNP Paribas remains an accessible tool for all employees of the group, regardless of their status. The difficulty does not come from the tool itself, but from technical prerequisites that are rarely explained for profiles that fall outside the standard framework. Verifying the activation of one’s identifier, enrolling the second factor from the internal network, and adopting a few security reflexes are sufficient in the vast majority of cases to resolve the situation.