You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 8 Current »

The MFA Policy controls whether MFA is enabled or not in the following 3 scenarios:

  • Boot Login
  • Screen Unlock
  • Elevated Access  (UAC)

It also controls the frequency of the MFA requirement.

The Computer Login MFA solution provides a highly flexible and granular policy control system, enabling you to define MFA policies across multiple levels.

You can set the MFA Policy on the following levels:

  1. System Policy
    1. Online
    2. Offline
  2. Domain Policy
    1. Local
    2. Entra ID
      1. Online
      2. Offline
    3. On-Prem AD
      1. Online
      2. Offline

The domain policy has priority over the equivalent system policy. For a given policy option, the software will always search for the domain policy first. If the domain policy is found, then the software will use it. Otherwise, the software will find and use the system policy. 

In total, there are 7 scenarios where you can define the MFA Policy. Namely

ScenarioLocationComment
1.aSystem Policy\Online
1.bSystem Policy\Offline
2.aDomain Policy\Local\Online
2.b.iDomain Policy\Entra ID\Online
2.b.iiDomain Policy\Entra ID\Offline
2.c.iDomain Policy\On-Prem AD\Online
2.c.iiDomain Policy\On-Prem AD\Offline

To edit the MFA Policy, navigate to the specific location in the Deepnet Configuration Editor. For example, Domain Policy\Entra ID\Online

  • No labels