All Products
Search
Document Center

CloudSSO:Manage MFA

Last Updated:Jun 02, 2026

Multi-factor authentication (MFA) adds an extra verification step beyond username and password to secure console logons.

Overview

MFA is enabled by default when you enable username and password logon for CloudSSO users. CloudSSO supports using a virtual MFA device for authentication. The following table outlines the setup process.

Step

Description

Operator

References

1

Configure MFA.

The administrator enables MFA globally or per user based on business requirements.

CloudSSO administrator

Enable MFA for all CloudSSO users and Enable MFA for a CloudSSO user

2

Bind an MFA device.

On first logon to the CloudSSO user portal, users must bind an MFA device and complete MFA verification.

CloudSSO users

Bind the first MFA device

The following sections describe how to enable MFA for all CloudSSO users, enable MFA per user, and unbind MFA devices. These operations require CloudSSO administrator privileges. Bind or unbind MFA devices.

Enable MFA for all CloudSSO users

  1. Log on to the CloudSSO console.

  2. In the left-side navigation pane, click Settings.

  3. On the User Setting tab, in the Username-password Login section, click Edit next to MFA Requirement for Logon.

  4. In the Edit MFA Verification Settings dialog box, configure the following settings.

    1. Whether to Enable MFA When Logon

      • Enable: Enables MFA for all CloudSSO users.

        If you select this option, users must bind an MFA device on their first logon. Bind the first MFA device.

      • Custom configuration: Enables per-user MFA configuration.

        Enable MFA for a CloudSSO user.

      • Required Only for Unusual Logon: Enforces MFA only for unusual logons, such as when the logon environment is untrusted due to a change in location or device. Otherwise, MFA is not required.

      • Disable: Disables MFA for all users.

    2. If you select Custom configuration or Required Only for Unusual Logon, configure the MFA verification policy for unusual logons.

      • Allow to skip binding MFA: During unusual logons, users are prompted for MFA verification but can skip it.

      • Must bind or verify MFA: During unusual logons, users must complete MFA verification.

  5. Click OK.

Enable MFA for a CloudSSO user

If you select Custom configuration when you configure global MFA, you must configure MFA for each CloudSSO user.

  1. Log on to the CloudSSO console.

  2. In the left-side navigation pane, choose User Management > User.

  3. Click the name of the user that you want to manage.

  4. On the Details tab, in the MFA Settings section, click Edit next to MFA Requirement for Logon.

  5. In the Edit MFA Verification Settings dialog box, configure MFA.

    • Enable: Enables MFA for the current user.

      If you select this option, users must bind an MFA device on their first logon. Bind the first MFA device.

    • Required Only for Unusual Logon: Enforces MFA only for unusual logons, such as when the logon environment is untrusted due to a change in location or device. Otherwise, MFA is not required.

    • Disable: Disables MFA for the current user.

  6. Click OK.

Unbind an MFA device

Both CloudSSO administrators and users can unbind MFA devices. This section covers the administrator workflow.

Warning

Unbinding MFA devices removes identity verification for the affected users, reducing account security.

  1. Log on to the CloudSSO console.

  2. In the left-side navigation pane, choose User Management > User.

  3. Click the name of the user that you want to manage.

  4. On the Details tab, in the MFA Devices section, find the desired MFA device and click Delete in the Actions column.

  5. In the Unbind Virtual MFA Device dialog box, click OK.

References

Bind or unbind MFA devices