Two-factor authentication
Updated at:
When Two-Factor Authentication (2FA) is enabled, users must first enter their password to log on to a cloud server. After the password is verified, they must then enter a dynamic password (SMS/MFA) to complete the logon.
Background
Two-Factor Authentication applies in the following scenarios:
- Password-based O&M logons
- local users and AD/LDAP users must use a phone verification code for secondary verification.
- RAM users must always use MFA for secondary verification.
- Public key-based O&M logons
- local users and AD/LDAP users must use a phone verification code for secondary verification.
- RAM users must use MFA for secondary verification if this option is enabled.
To enable or disable Two-Factor Authentication, follow these steps.
Procedure
- Log on to the Bastionhost console.
- Find the Bastionhost instance to manage and click Manage in the Actions column.
- Select an access method and connect to the web management page of the target Bastionhost instance.
- Navigate to the page. In the Two-Factor Authentication section, select or clear the check boxes for the features you want to configure.
The available options are: Two-factor authentication is required for password-based O&M logons (local users and AD/LDAP users must use a phone verification code for secondary verification; RAM users must always use MFA for secondary verification); Two-factor authentication is required for public key-based O&M logons (local users and AD/LDAP users must use a phone verification code for secondary verification; RAM users must use MFA for secondary verification if this option is enabled).
- Click Save Settings and then refresh the page for the changes to take effect.
Is this page helpful?