Multi-factor authentication (MFA) - Sophos Firewall (2024)

Page permalink

Always use the following permalink when referencing this page. It will remain unchanged in future help versions.

https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/index.html?contextId=MFA

You can implement multi-factor authentication using hardware or software tokens.

For software tokens, users must scan the QR code on the user portal using an authenticator application on their mobile devices, such as the authenticator feature in Intercept X for Mobile.

Warning

Sophos Authenticator reached End of Life (EOL) on July 31, 2022.

We recommend that users migrate to another authenticator app, such as the authenticator feature in Intercept X for Mobile, Google Authenticator, or other apps. See Migrate to another authenticator application.

Multi-factor authentication (MFA) settings

You can configure MFA and apply it to users signing in to certain firewall services, such as the user portal and remote access VPN. The settings determine whether users can use software or hardware tokens.

You can also set the timestep (time period) for which passcodes remain valid.

See Multi-factor authentication (MFA) settings.

Issued tokens

You can manually configure tokens and see the list of users who've used the token.

Manually configure the secret

To manually configure the secret, click Add token (for hardware tokens) and configure the settings.

You can use the secret for software tokens if you turn on Generate OTP token with next sign-in under MFA settings.

Types of users and tokens

The list shows the issued tokens and their users as follows:

  • Tokens you've manually configured without adding a user. You can add the user later.
  • Users for whom you've manually configured a token. Example: newuser
  • Users and administrators who've scanned the QR code. Example: admin and testadministrator

    Note

    Other administrators can't change the status, edit, or delete the default admin's (admin) tokens. The default admin can turn on MFA for the account on Administration > Device access.

    Multi-factor authentication (MFA) - Sophos Firewall (1)

Actions

  • Turn the status on or off to temporarily prevent the user from signing in.
  • To manually generate passcodes for a user on the list, click the edit button Multi-factor authentication (MFA) - Sophos Firewall (2). For Additional codes, click the add button Multi-factor authentication (MFA) - Sophos Firewall (3).
  • To check the authenticator app or hardware token's time offset and synchronize it with the firewall, do as follows:

    1. Click the Synchronize token time offset button Multi-factor authentication (MFA) - Sophos Firewall (4).
    2. Enter the generated passcode and click Check.

    The time offset synchronizes. Synchronizing the token time between the app and the firewall corrects time drifts.

Note

If you use the API to import MFA settings or tokens, you must include a blank <tokenid/> attribute.

Migrating to another app or losing account access

If a user loses a hardware token, delete the issued token and add a new token for the user.

If you want users to move to another authenticator app, or if they lose their mobile device, losing access to their account in the app, do as follows:

  1. Under Issued tokens, delete these users. The firewall will generate the QR code again.
  2. Users must scan the QR code again on the user portal.

See Migrate to another authenticator application.

More resources

Multi-factor authentication (MFA) - Sophos Firewall (2024)
Top Articles
Databricks vs Snowflake - 2024 take - Blueprint Technologies
TALIC - Assessment Resource Centre
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Eusebia Nader

Last Updated:

Views: 6156

Rating: 5 / 5 (60 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Eusebia Nader

Birthday: 1994-11-11

Address: Apt. 721 977 Ebert Meadows, Jereville, GA 73618-6603

Phone: +2316203969400

Job: International Farming Consultant

Hobby: Reading, Photography, Shooting, Singing, Magic, Kayaking, Mushroom hunting

Introduction: My name is Eusebia Nader, I am a encouraging, brainy, lively, nice, famous, healthy, clever person who loves writing and wants to share my knowledge and understanding with you.