Two-factor authentication

Updated at:

When Two-Factor Authentication (2FA) is enabled, users must first enter their password to log on to a cloud server. After the password is verified, they must then enter a dynamic password (SMS/MFA) to complete the logon.

Background

Two-Factor Authentication applies in the following scenarios:

  • Password-based O&M logons
    • local users and AD/LDAP users must use a phone verification code for secondary verification.
    • RAM users must always use MFA for secondary verification.
  • Public key-based O&M logons
    • local users and AD/LDAP users must use a phone verification code for secondary verification.
    • RAM users must use MFA for secondary verification if this option is enabled.

To enable or disable Two-Factor Authentication, follow these steps.

Procedure

  1. Log on to the Bastionhost console.
  2. Find the Bastionhost instance to manage and click Manage in the Actions column.
  3. Select an access method and connect to the web management page of the target Bastionhost instance.
  4. Navigate to the System > System Settings page. In the Two-Factor Authentication section, select or clear the check boxes for the features you want to configure.
    The available options are: Two-factor authentication is required for password-based O&M logons (local users and AD/LDAP users must use a phone verification code for secondary verification; RAM users must always use MFA for secondary verification); Two-factor authentication is required for public key-based O&M logons (local users and AD/LDAP users must use a phone verification code for secondary verification; RAM users must use MFA for secondary verification if this option is enabled).
  5. Click Save Settings and then refresh the page for the changes to take effect.