All Products
Search
Document Center

Elastic Desktop Service:Configure MFA

Last Updated:Apr 01, 2026

Multi-factor authentication (MFA) adds a second verification step to the logon process. After you enable MFA, end users must provide their username, password, and a dynamic code each time they log on to WUYING Workspace terminals.

How it works

When an end user logs on to a WUYING Workspace terminal, the logon flow has two stages:

  1. First stage: The end user enters a username and password.

  2. Second stage: MFA triggers immediately after the first stage succeeds. The end user must enter a six-digit dynamic code from a virtual MFA device, or a verification code sent to their email address.

A virtual MFA device is an app that supports Time-based One-Time Password (TOTP), such as Google Authenticator or Microsoft Authenticator, installed on a mobile phone or other device.

Alibaba Cloud Workspace terminals support software-based virtual MFA devices. You can install TOTP-based virtual MFA devices, such as Google Authenticator and Microsoft Authenticator, on your mobile phones.

Supported MFA methods

Elastic Desktop Service (EDS) Enterprise supports two MFA methods:

MFA methodApplicable logon methodApplicable client typeApplicable account type
TOTPOrganization ID and office network IDAll clientsAll accounts
Email verification codeOrganization ID onlyWindows and macOS clients (version 7.6 or later); Android and iOS clients (version 7.3 or later)Convenience accounts and AD accounts with a configured email address

Prerequisites

Before you begin, make sure that:

  • You have administrator access to the EDS Enterprise console

  • For office network MFA: the Client Logon Verification and SSO switches are turned off on the target office network

  • For email verification code: end users have an email address associated with their account

Enable MFA for an office network

  1. Log on to the EDS Enterprise console.

  2. In the left-side navigation pane, choose Networks & Storage > Office Networks.

  3. In the top navigation bar, select a region.

  4. On the Office Networks page, find the office network you want to manage and click its ID.

  5. In the Other Information section, turn on the MFA switch. In the dialog box that appears, click OK.

After MFA is enabled, end users must enter a dynamic MFA code every time they log on to terminals in this office network.

Enable MFA for an organization ID

  1. Log on to the EDS Enterprise console.

  2. In the left-side navigation pane, choose Users > Logon Settings.

  3. On the Security tab, set MFA to Enable.

  4. In the confirmation dialog box, select an authentication method:

    • TOTP: Uses the Alibaba Cloud app or other TOTP-compatible apps such as Google Authenticator for two-factor authentication.

    • Email verification code: Sends a verification code to the end user's email address. Applies to desktop clients version 7.6 or later and mobile clients version 7.3 or later. Supports convenience accounts and Active Directory (AD) accounts with a configured email address. > Note: If an account has no email address, the user cannot complete verification. Associate an email address with the account before enabling this method.

After MFA is enabled, end users who log on with the organization ID must enter a dynamic MFA code.

Delete a virtual MFA device

When end users change their virtual MFA devices, delete the original device in the console first. After you turn on the MFA switch in the EDS Enterprise console, end users must bind virtual MFA devices to their convenience accounts the first time they log on to WUYING Workspace terminals. The next time they log on after a device is deleted, end users are prompted to bind a new device.

Delete a virtual MFA device for a convenience user

  1. In the left-side navigation pane, choose Users > Users.

  2. On the User tab of the Users & Organizations page, find the user, click the icon in the Actions column, and then click Manage MFA Device.

  3. In the Manage MFA Device dialog box, find the device and click Delete in the Actions column. In the message that appears, click OK.

Delete a virtual MFA device for an enterprise AD user

The procedure differs depending on whether MFA is enabled at the office network level or the organization ID level.

From an office network

  1. In the left-side navigation pane, choose Resources > Cloud Computers.

  2. In the top navigation bar, select a region.

  3. On the cloud computers page, find the cloud computer assigned to the AD user, click the icon in the Actions column, and then click Manage MFA Device.

  4. In the Manage MFA Device panel, delete the device as prompted.

From an organization ID

  1. In the left-side navigation pane, choose Users > Logon Settings.

  2. On the Security tab of the Logon Settings page, find the AD domain and click Manage MFA Device to the right of the domain name.

  3. In the Manage MFA Device panel, delete the device as prompted.

MFA device lock policy

If an end user enables MFA for an office network and binds a virtual MFA device to their enterprise AD account, the system locks the virtual MFA device for 1 hour after 10 consecutive failed verification attempts. To restore access before the lock expires, you can: