跳到主内容

Require multi-factor authentication

This guide explains how to offer multi-factor authentication (MFA) methods to the users of an organization and how to require them.


Learning outcomes​

  • Add MFA methods to an organization.
  • Make a method optional, prompted, or required.
  • Let users skip MFA on a trusted device for a period.

What you need​

  • Administrator access to the organization in the Casdoor admin console

Add MFA methods​

  1. In the Casdoor admin console, open the edit page of the organization.

  2. In MFA items, add the MFA methods that the organization offers.

    MFA items of an organization

  3. Select a rule for each method:

    RuleBehavior
    OptionalUsers can set up the method or leave it
    PromptCasdoor prompts users who haven't set up the method after they sign in
    RequiredUsers must set up the method before they can complete the sign-in

    Rules of the MFA items

  4. Save the organization.

Users then set up and manage their methods on their account page. See Multi-factor authentication.

With the Prompt rule, users see the following prompt after sign-in:

Prompt to set up MFA

With the Required rule, users go through the setup before the sign-in completes:

Recording of the required MFA setup

Remember MFA on a device​

Users can choose to be remembered on a device, so that Casdoor doesn't ask for the second factor again for a period.

Remember option during MFA

Set the length of the period, for example 12 hours, in MFA remember time on the organization edit page.

MFA remember time of an organization

See also​