Manage MFA

更新时间:
复制 MD 格式

Multi-factor authentication (MFA) adds an extra layer of security beyond username and password to protect console logons.

Overview

MFA is enabled by default when you enable username and password logon for CloudSSO users. CloudSSO supports virtual MFA devices for authentication. The following table outlines the setup process.

Step

Description

Operator

References

1

Configure MFA.

The administrator enables MFA globally or per user based on business requirements.

CloudSSO administrator

Enable MFA for all CloudSSO users and Enable MFA for a CloudSSO user

2

Bind an MFA device.

On first logon to the CloudSSO user portal, the user must bind an MFA device and complete MFA verification.

CloudSSO users

Bind the first MFA device

The following sections describe how to enable MFA for all CloudSSO users, enable MFA per user, and unbind MFA devices. These operations require CloudSSO administrator privileges. For information about how users can manage their own MFA devices, see Bind or unbind MFA devices.

Enable MFA for all CloudSSO users

  1. Log on to the CloudSSO console.

  2. In the left-side navigation pane, click Settings.

  3. On the User Setting tab, in the Username-password Login section, click Edit next to MFA Requirement for Logon.

  4. In the Edit MFA Verification Settings dialog box, configure the following settings.

    1. Whether to Enable MFA When Logon

      • Enable: Enables MFA for all CloudSSO users.

        If you select this option, users must bind an MFA device on their first logon. For more information, see Bind the first MFA device.

      • Custom configuration: Enables per-user MFA configuration.

        Enable MFA for a CloudSSO user.

      • Required Only for Unusual Logon: Enforces MFA only for unusual logons, such as when the logon environment is untrusted due to a change in location or device. Otherwise, MFA is not required.

      • Disable: Disables MFA for all users.

    2. If you select Custom configuration or Required Only for Unusual Logon, configure the MFA verification policy for unusual logons.

      • Allow to skip binding MFA: During unusual logons, users are prompted for MFA verification but can skip it.

      • Must bind or verify MFA: During unusual logons, users must complete MFA verification.

  5. Click OK.

Enable MFA for a CloudSSO user

If you select Custom configuration when you configure global MFA, you must configure MFA for each CloudSSO user.

  1. Log on to the CloudSSO console.

  2. In the left-side navigation pane, choose User Management > User.

  3. Click the name of the user that you want to manage.

  4. On the Details tab, in the MFA Settings section, click Edit next to MFA Requirement for Logon.

  5. In the Edit MFA Verification Settings dialog box, configure MFA.

    • Enable: Enables MFA for the current user.

      If you select this option, the user must bind an MFA device on their first logon. For more information, see Bind the first MFA device.

    • Required Only for Unusual Logon: Enforces MFA only for unusual logons, such as when the logon environment is untrusted due to a change in location or device. Otherwise, MFA is not required.

    • Disable: Disables MFA for the current user.

  6. Click OK.

Unbind an MFA device

Both CloudSSO administrators and users can unbind MFA devices. This section describes the administrator workflow.

Warning

Unbinding an MFA device removes identity verification for the affected user, which reduces account security.

  1. Log on to the CloudSSO console.

  2. In the left-side navigation pane, choose User Management > User.

  3. Click the name of the user that you want to manage.

  4. On the Details tab, in the MFA Devices section, find the desired MFA device and click Delete in the Actions column.

  5. In the Unbind Virtual MFA Device dialog box, click OK.

References

Bind or unbind MFA devices