Advanced Settings

The Advanced tab at the far right of the Multi-Factor Authentication (MFA) page contains important settings that you can configure to further control the MFA processes for password resets, ADSelfService Plus logins, and endpoint logins.

Reset/Unlock MFA

ADSelfService Plus Login MFA

Cloud Application Login MFA

Endpoint Settings

Machine Login MFA

MFA for OWA Login

Note: MFA for OWA logins requires the Professional Edition of ADSelfService Plus with Endpoint MFA.

VPN Login MFA

Note: MFA for VPN logins requires the Professional Edition of ADSelfService Plus with Endpoint MFA.

Configuring additional attributes:

  1. If you try to enable this feature before configuring the attributes, you will be shown a pop-up to configure them. Click OK. You can also click on the Configure Attributes link.
  2. You can configure RADIUS' Standard or Vendor-specific attributes and corresponding values to be sent to the VPN providers (other RADIUS endpoints).
  3. Enter the Vendor ID by clicking on the Edit [] button. The Vendor ID is the unique number that denotes your VPN provider. For example, if using Fortigate, the Vendor ID is 12356.
  4. Choose the Type of attribute and enter the Attribute Number, Format and Value in the fields displayed.
    • For attributes of format string, the values should be in characters and for the attributes of format int, the values should be in integers.
    • For enum attributes which contain multiple predefined values, provide the desired value in terms of their associated integers. For example, if you wish to use Login as the service-type attribute, enter 1 in the Value field.
    • In case attributes are in the IPv4 or IPv6 address formats, please provide a valid IP address in the Value field.
    • For example, your IPv4 address can look like "10.1.1.1", and your IPv6 address can look like "2001:0db8:85a3::8a2e:0370:7334".
  5. Click OK after configuring all the attributes you require.
  6. Once successfully configured, the Send additional attributes as a response to the VPN server after successful completion of MFA setting will be enabled.

Q&A Settings

Verification Code Settings

Mail/Mobile Attributes

Secondary Email/Mobile Number

Others

General

About backup codes

These one-time use backup codes allow users to prove their identities in case their MFA device is not reachable or they are unable to use their enrolled MFA methods of authentication. Once the Enable one-time backup codes setting is enabled, the backup codes can be generated. End-users can save them beforehand and use them to authenticate themselves during machine or VPN logon, ADSelfService Plus portal login, or self-service actions. Backup codes can be generated in two ways:

Note:
  • Users can use the backup codes during VPN logins only when RADIUS challenge-response authentication methods are used for VPN login MFA.
  • During VPN login MFA, the generated backup code can be entered in the field provided for one-time passcodes at the VPN client.
  • When identity verification is done using backup codes, the Trust this browser or Trust this machine option will not be considered.

About backup codes

Copyright © 2024, ZOHO Corp. All Rights Reserved.