Multi-factor authentication (MFA) requires an end user to provide a second security factor — a dynamic password or a verification code — in addition to a username and password when the end user logs on to a . This topic describes how to enable MFA for each supported scope and how to delete a virtual MFA device that an end user has bound.
How MFA works
After you enable MFA for an office network or for an organization ID, the system verifies two security factors each time an end user logs on:
First factor — The username and password of the end user.
Second factor — The dynamic password generated by a virtual MFA device, or the verification code that the end user receives in an email.
Virtual MFA devices
The Time-based One-Time Password algorithm (TOTP) is a widely adopted multi-factor authentication protocol. Applications that support TOTP on a mobile phone or another device, such as Google Authenticator, and Microsoft Authenticator, are called virtual MFA devices.
After you enable MFA and an end user binds a virtual MFA device, Alibaba Cloud requires the end user to enter the six-digit dynamic password generated by the application at each logon. This prevents unauthorized logons that result from a stolen password.
A WUYING Terminal supports software-based virtual MFA devices. You can install a TOTP application on a smartphone and use it as a virtual MFA device.
Supported MFA methods
EDS Enterprise Edition supports the following MFA methods. The enablement scope that you choose determines which methods are available and which end users are affected.
Authentication method | Supported enablement scope | Supported client types | Supported account types |
TOTP dynamic password | Organization ID and office network | No limit | No limit |
Email verification code | Organization ID |
| Convenience accounts and Active Directory (AD) accounts (an email address must be configured) |
Prerequisites
Virtual MFA devices — For TOTP dynamic passwords, end users have an application that supports TOTP installed on a mobile phone or another device.
Contact information — For email verification codes, an email address is configured for each account. An end user whose account lacks this information cannot complete the verification.
Client versions — For email verification codes, end users have a client that meets the minimum version listed in the Supported MFA methods section of this topic.
Enable MFA for an office network
Enable MFA at this scope to require a dynamic password from the end users who use one specific office network to log on.
Log on to the EDS enterprise console.
In the top navigation bar, select a region.
In the left-side navigation pane, choose Networks & Storage > Office Network.
On the office network page, click the office network ID of the target office network.
In the More Information section at the bottom of the page, turn on the MFA switch, and then click OK in the confirmation dialog box.
NoteMake sure that client logon verification and the SSO settings are disabled.
After MFA is enabled, end users must enter a dynamic password when they use this office network to log on to a WUYING Terminal.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the left-side navigation pane, choose Networks & Storage > Office Network.
Enable MFA for an organization ID
Enable MFA at this scope to require a second security factor from every end user who uses the organization ID to log on. In the confirmation dialog box, you select one of the following authentication methods:
TOTP dynamic password — End users enter the dynamic password generated by the Alibaba Cloud app or another common OTP app, such as Google Authenticator.
Email verification code — End users enter the verification code that they receive in an email.
Log on to the EDS enterprise console.
In the left-side navigation pane, choose Users > Logon.
On the Security tab of the Logon page, set MFA to Enabled.
In the confirmation dialog box, select the authentication method that you want to use.
After MFA is enabled, end users must enter the dynamic password or verification code that the selected authentication method requires when they use this organization ID to log on to a WUYING Terminal.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
Delete a virtual MFA device
End users bind a virtual MFA device the first time they log on after you enable MFA with TOTP dynamic passwords. If an end user replaces the virtual MFA device, delete the device that is bound to the account of the end user in the console.
Select the procedure that matches the account type of the end user. For an enterprise AD account, also select the sub-procedure that matches the scope at which MFA is enabled.
Convenience account
Log on to the EDS enterprise console.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Users > User Management.
On the User tab of the User Management page, find the target user, click the ⋮ icon in the Actions column, and then select Manage MFA Device.
In the Manage MFA Device dialog box, find the virtual MFA device that you want to delete, click Delete in the Actions column, and then click OK.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
In the left-side navigation pane, choose Users > User Management.
Enterprise AD account
Enterprise AD accounts in an office network
Log on to the EDS enterprise console.
In the top navigation bar, select a region.
In the left-side navigation pane, choose Resources > Cloud Computers.
On the Cloud Computer Enterprise Edition page, find the cloud computer that is assigned to the enterprise AD user, click More in the Actions column, and then select Manage MFA Device.
In the Manage MFA Device panel, follow the on-screen instructions to delete the virtual MFA device.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the top navigation bar, select a region.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
Enterprise AD accounts under an organization ID
Log on to the EDS enterprise console.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Users > Logon.
On the Security tab of the Logon page, find the target AD domain name and click Manage MFA Device next to it.
In the Manage MFA Device panel, follow the on-screen instructions to delete the virtual MFA device.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
Log on to the EDS enterprise console.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Resources > Cloud Computers.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
In the left-side navigation pane, choose Users > Logon.
After you delete the virtual MFA device, the end user must bind a virtual MFA device again at the next logon.
Unlock a locked virtual MFA device
If MFA is enabled for an office network and an end user uses an enterprise AD account to log on to a WUYING Terminal and binds a virtual MFA device, the system locks the virtual MFA device for one hour when the end user enters an incorrect dynamic password more than 10 consecutive times.
To let the end user log on during the lockout period, call the UnlockVirtualMFADevice operation to unlock the device. Alternatively, call the DeleteVirtualMFADevice operation to delete the device, and then have the end user bind a new virtual MFA device.