Two-Factor Authentication (2FA)
Two-Factor Authentication (2FA) adds an extra verification step to the login process, requiring both primary credentials and a time-based one-time password (TOTP) generated by an authenticator app.
This additional factor helps protect access even if a User's or Account's username and password are compromised. TOTP codes rotate every 30 seconds, limiting the usefulness of intercepted codes.
When 2FA is enabled, the User or Account is prompted to enroll at the next login. After enrollment, access to the UDMG Admin UI and the Web Transfer Client (WTC) requires the primary credentials (Standard or LDAP) plus a valid TOTP code.
2FA is supported only for Users and Accounts with Standard or LDAP authentication as their Login Method.
2FA Configuration
- Users
- Accounts
Two-Factor Authentication (2FA) for Users is configured at the User level (and therefore applies across the Domain).
To require 2FA for a User, follow these steps:
- From the Sidebar, click General > Users.
- Click the Username of the User you want to enable 2FA for. The User's Login Method must be Standard or LDAP.
- Click Edit.
- Enable the Require Two-Factor Authentication (TOTP) toggle.
- Click Update.
Two-Factor Authentication (2FA) for Accounts applies only to logins to the Web Transfer Client (WTC) and is configured at the Account level.
To require 2FA for an Account, follow these steps:
- From the Sidebar, click Configuration > Accounts.
- Click the Name of the Account you want to enable 2FA for. The Account's Login Method must be set to Standard or LDAP.
- Click the Edit button above the Account details.
- Enable the Require Two-Factor Authentication (TOTP) toggle.
- Click Save.
Only System Administrators or Domain Administrators can enable or disable 2FA.
2FA Enrollment
When 2FA is enabled, Users and Accounts must enroll in an external authenticator app at their next login and provide a TOTP code for every subsequent login.
The enrollment process uses an intuitive guided modal with three streamlined steps: Configure, Verify, and Activate. This one-time setup ensures secure access while maintaining a user-friendly experience.
Step 1. Configure
- From the modal, scan the QR code with your preferred authenticator app.
- If you're having trouble scanning the QR code, click the Can't Scan It? link.
- Manually enter the Secret Key, Issuer, and Account (Username) into your authenticator app.
- The authenticator app will display a new account entry for UDMG Admin UI.
Step 2. Verify
- Enter the 6-digit code from your authenticator app. You typically have 30 seconds to add the new code before a new code generates.
- Click Next.
Step 3. Activate
- You should see a "Setup Complete!" message. If not, click Back and enter a new code.
- Click Continue
- You'll be automatically redirected to the UDMG Admin UI or WTC landing page.
2FA Disabling
Disabling 2FA removes the TOTP requirement for future logins for that User or Account. It does not clear the existing 2FA enrollment (TOTP secret) stored in UDMG.
This means that if you later re-enable 2FA for the same User or Account, they do not need to enroll again and they can continue using the existing entry in their authenticator app.
To force re-enrollment (for example, if the User lost access to their authenticator app), use 2FA Reset instead of disabling 2FA.
- Users
- Accounts
To disable 2FA for a User, follow these steps:
- From the Sidebar, click General > Users.
- Click the Username of the User you want to disable 2FA for.
- Click Edit.
- Disable the Require Two-Factor Authentication (TOTP) toggle.
- Click Save.
To reset 2FA for an Account, follow these steps:
- From the Sidebar, click General > Users.
- Click the Name of the Account you want to disable 2FA for.
- Click Edit.
- Disable the Require Two-Factor Authentication (TOTP) toggle.
- Click Save.
2FA Reset
If a User or Account loses access to their authenticator app (for example, due to a lost or replaced device), an Admin must reset their 2FA enrollment. Resetting the 2FA clears the stored TOTP secret and enrollment status, allowing the User or Account to re-enroll at their next login.
- Users
- Accounts
To reset 2FA for a User, follow these steps:
- From the Sidebar, click General > Users.
- Click the Username of the User you want to reset 2FA for.
- Click Reset TOTP.
- The User will be prompted to re-enroll in 2FA the next time it logs in to the UDMG Admin UI.
To reset 2FA for an Account, follow these steps:
- From the Sidebar, click Configuration > Accounts.
- Click the Name of the Account you want to reset 2FA for.
- Click the Reset TOTP.
- The Account will be prompted to re-enroll in 2FA the next time it logs in to the Web Transfer Client (WTC).
Only System Administrators or Domain Administrators can reset 2FA.