Skip to content

Multi-factor authentication

Multi-factor authentication asks for a second proof of identity after the password, so a stolen password alone is not enough to reach your data. CyberGuard supports authenticator apps producing time-based one-time passwords (TOTP) and security keys — hardware tokens, Touch ID, Windows Hello and other WebAuthn authenticators. Both can be enrolled on the same account.

My profile → Settings → Security settings, reached from the user menu. Everything on this page applies to your own account.

  1. Open My profile → Settings and stay on the Security settings tab.

  2. In the Multi-factor authentication block, next to Authenticator app, select Enable MFA.

  3. Scan the QR code with your authenticator app. If the camera is not an option, use Enter the following code manually into the app and type the secret.

  4. Enter the six-digit code the app generates and confirm with Enable MFA.

From the next sign-in onward, CyberGuard asks for a code after your password.

In the Security keys block, select Add security key, give the credential a Key name you will recognise later, and follow the browser prompt — insert and tap a hardware key, or confirm with your fingerprint, face or device PIN. Enrol more than one if a key is your only second factor: a lost key with no backup is the most common lockout.

At sign-in, a security key is offered first when one is enrolled, with Use authenticator app as a fallback.

Recovery codes are your way back in when the phone is wiped or the key is lost. Use List recovery codes to display the current set, and Regenerate recovery codes to issue a fresh one — regenerating invalidates the previous codes immediately.

At the second-factor prompt, Use a recovery code swaps the code field for a recovery-code field.

An administrator can require MFA across the instance: Extra → Settings → General → Security → Enforce multi-factor authentication. While it is on, every local user except superusers is redirected to the MFA setup page and cannot reach the rest of the application until enrolment is done. Users who sign in through SSO are exempt, because the second factor is your identity provider’s responsibility there.

Announce this before enabling it — everyone who has not enrolled hits the setup screen on their next page load.

When someone has lost every enrolled factor and has no recovery codes left, an administrator in the global administrator group can clear their enrolment.

  1. Go to Organization → Users and open the affected user.

  2. Select Edit. In the security section, follow the disable their MFA link.

  3. On the confirmation page, type the confirmation word shown on screen — Yes in English — and submit.

All of that user’s authenticators are removed: authenticator app, security keys and recovery codes. They sign in with their password alone next time, and must enrol again if enforcement is on. The action is recorded in the backend logs, and the link never appears on your own edit page — use My profile → Settings to change your own MFA.

  • Users — where the administrator reset lives.
  • SSO — SSO users are exempt from enforced MFA.
  • Session security — idle session lock and failed-login lockout.