Configuring Multi-Factor Authentication
Multi-factor authentication (MFA) provides an additional layer of security for Veeam ONE user accounts. When MFA is enabled, users confirm their identity with a one-time password (OTP) generated in a mobile authenticator application, in addition to their user name and password. On the Multi-Factor Authentication tab of the Access Management section, you can enable or disable MFA for all users, enable or disable MFA for individual users, and reset MFA for a user.
MFA applies when users log in to Veeam ONE through both Veeam ONE Web Client and Veeam ONE Client. For details, see Accessing Veeam ONE Components.
Required Permissions
To configure MFA, a user must have the Veeam ONE Administrator role. For details on user roles, see Security.
Enabling or Disabling MFA for All Users
To enable or disable multi-factor authentication for all Veeam ONE users:
- Open Veeam ONE Web Client.
For details, see Accessing Veeam ONE Components.
- At the top right corner of the Veeam ONE Web Client window, click Configuration.
- In the configuration menu on the left, click Access Management.
- On the Multi-Factor Authentication tab at the top of the user list, click Configuration.
- In the MFA Configuration window, set the Multi-factor authentication (MFA) toggle to enable or disable MFA for all users.
- Click OK.
Note |
When you enable MFA for all users, each user is prompted to set up MFA in a TOTP authenticator application at the next login. |
Enabling or Disabling MFA for Individual Users
The MFA status you set for an individual user overrides the global MFA setting. For example, if MFA is enabled for all users, you can disable it for a specific user so that this user can log in without MFA.
To enable or disable multi-factor authentication for an individual user:
- Open Veeam ONE Web Client.
For details, see Accessing Veeam ONE Components.
- At the top right corner of the Veeam ONE Web Client window, click Configuration.
- In the configuration menu on the left, click Access Management.
- On the Multi-Factor Authentication tab, select the user whose MFA status you want to change.
- At the top of the user list, click Enable or Disable.
- Click Confirm.
Resetting MFA
If the user can no longer pass multi-factor authentication — for example, the user lost access to the authenticator app or replaced the device — you can reset MFA for this user.
To reset multi-factor authentication for a user:
- Open Veeam ONE Web Client.
For details, see Accessing Veeam ONE Components.
- At the top right corner of the Veeam ONE Web Client window, click Configuration.
- In the configuration menu on the left, click Access Management.
- On the Multi-Factor Authentication tab, select the user whose MFA you want to reset.
- At the top of the user list, click Reset.
- Click OK.
After you reset MFA, the current MFA setup for the user is cleared. At the next login, the user is prompted to set up MFA again.
