{"id":76370,"date":"2023-06-05T13:11:28","date_gmt":"2023-06-05T17:11:28","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=76370"},"modified":"2023-09-12T10:59:06","modified_gmt":"2023-09-12T14:59:06","slug":"configure-totp-mfa-for-user-accounts","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/configure-totp-mfa-for-user-accounts","title":{"rendered":"Configure TOTP MFA for User Accounts"},"content":{"rendered":"\n
Use Multi-Factor Authentication with JumpCloud to secure user access to your organization\u2019s resources. This guide shows you how to set up TOTP Multi-factor authentication (MFA) for JumpCloud users. TOTP MFA can be used to authenticate to the User Portal and other JumpCloud-managed resources like devices. See Configure MFA for Your Org<\/a> before you begin.<\/p>\n\n\n\n Watch how to set up JumpCloud TOTP MFA for user accounts and the Admin Portal in Tutorial: TOTP MFA for Users and Admins<\/a>. <\/strong><\/p>\n\n\n\n <\/p><\/div> To learn how to set up TOTP MFA for Administrator accounts, see Enable MFA in the Admin Portal<\/a>.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n You can also secure user access to resources with JumpCloud Protect, Duo MFA, and WebAuthn MFA. See MFA for Admins<\/a> to learn more. JumpCloud recommends using JumpCloud Protect<\/a> for your MFA solution. <\/p>\n\n\n\n To require MFA on an individual user account:<\/strong><\/p>\n\n\n\n To require MFA on multiple user accounts:<\/strong><\/p>\n\n\n\n You can extend enrollment periods for users by resetting their TOTP MFA.<\/p>\n\n\n\n To extend a user’s enrollment period:<\/strong><\/p>\n\n\n\n After you reset TOTP MFA for a user, they are prompted to set up TOTP for their account.<\/p>\n\n\n\n If users lose the device containing their TOTP app, admins can reset TOTP MFA for their account.<\/p>\n\n\n\n To reset TOTP MFA for a user:<\/strong><\/p>\n\n\n\n After you reset TOTP MFA for a user, they are prompted to set up TOTP for their account.<\/p>\n\n\n\n See Enable TOTP MFA for Devices<\/a> for information about enabling TOTP MFA on your JumpCloud managed systems.<\/p>\n\n\n\n The Users list MFA<\/strong> column, which defaults to TOTP, shows you a user’s TOTP MFA status. When you hover over the status, you can see TOTP MFA status details for a user. The following TOTP MFA Statuses are possible:<\/p>\n\n\n\n You can also view a user’s MFA status in their user details.<\/p>\n\n\n\n You can filter the Users list to show MFA status and requirement. See Get Started: Users<\/a>. <\/strong><\/p>\n\n\n\n To see users in an enrollment period, filter apply both<\/em> the required and inactive MFA status filters. Likewise, to see users with an expired enrollment period, also apply both<\/em> the required and inactive MFA status filters.<\/p>\n\n\n\n Admins can disable TOTP MFA from guarding the User Portal. When TOTP MFA for the User Portal is disabled, other TOTP MFA protected resources like systems, RADIUS, and the Admin Portal aren\u2019t impacted. <\/p>\n\n\n\n Considerations<\/strong>:<\/p>\n\n\n\n To disable TOTP MFA for the User Portal<\/strong>:<\/p>\n\n\n\n Admins can re-enable TOTP MFA to guard the User Portal. Re-enabling TOTP MFA for the User Portal doesn\u2019t impact other TOTP MFA protected resources like systems, RADIUS, and the Admin Portal. <\/p>\n\n\n\n Considerations: <\/strong><\/p>\n\n\n\n To re-enable TOTP MFA for the User Portal<\/strong>:<\/p>\n\n\n\n Next Steps:<\/p>\n\n\n\n <\/p><\/div> TOTP attempts are not unlimited. Allowed number of user attempts is set by the IT Admin; admin attempts are limited to five. If settings are selected, that will count toward password or MFA attempts.<\/p>\n <\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":" Use Multi-Factor Authentication with JumpCloud to secure user access to your organization\u2019s resources. This guide shows you how to set […]<\/p>\n","protected":false},"author":204,"featured_media":0,"template":"","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","inline_featured_image":false,"footnotes":""},"support_category":[2908,2854,2850],"support_tag":[],"coauthors":[2838],"acf":[],"yoast_head":"\nRequire MFA on Users<\/h2>\n\n\n\n
Requiring Multi-factor Authentication on an Individual User Account<\/h3>\n\n\n\n
\n
Requiring TOTP MFA on Multiple User Accounts<\/h3>\n\n\n\n
\n
Extending Time for a User to Enroll in TOTP MFA<\/h2>\n\n\n\n
\n
Resetting TOTP MFA in Case of Device Loss or Failures<\/h2>\n\n\n\n
\n
View User TOTP MFA Status<\/h2>\n\n\n\n
\n
Disabling TOTP MFA for the User Portal<\/h2>\n\n\n\n
\n
\n
Re-enabling TOTP MFA for the User Portal<\/h2>\n\n\n\n
\n
\n
\n
\n