Machine-based MFA

Machine-based MFA is a setting intended to protect business-critical machines in an organization by preventing them from being compromised.

Note: Machine-based MFA requires the Professional Edition of ADSelfService Plus with Endpoint MFA. If you do not have these, machine-based MFA will not be enforced.

How does Machine-based MFA work?

When machine-based MFA is enforced for a particular machine, any user accessing the machine has to prove their identity using MFA to log in successfully. The MFA authenticators in the prompt will be based on the authenticators configured for the user in the MFA for Machine Login section. These settings differ from policy-based machine MFA settings, as these are meant to secure sensitive machines under any circumstance, i.e., MFA will be enforced on the selected machines irrespective of the enrollment status of the user attempting to log in or the availability of the ADSelfService Plus server.

Note: To set up policy-based settings that apply to users not machines, please click here.

When this setting is enabled, users will not be allowed to log in to the machine on which machine-based MFA is enforced if:

However, users who have selected the Trust this machine setting on the login screen will be allowed to log in to the machine without performing MFA for the specified duration after their initial identity verification.

Note: Make sure to update the login agent to the following latest versions for proper enforcement of MFA: Windows 5.10, macOS 1.7, or Linux 2.4 and above. If an older version of the login agent is installed on the machine, and the ADSelfService Plus server is not reachable, the user will be allowed to access the machine if the Skip MFA when ADSelfService Plus server is down or unreachable option is enabled.

Steps to enforce Machine-based MFA

  1. Navigate to Configuration > Administrative Tools > GINA/Mac/Linux (Ctrl+Alt+Del) > GINA/Mac/Linux Installation > Installed Machines.

    Machine-based MFA

  2. Select the required domain from the drop-down list.
  3. Select the machines on which you want to enforce machine-based MFA.

    Machine-based MFA

  4. Click Manage MFA and select Enforce.

    Machine-based MFA

Steps to exempt a machine from Machine-based MFA

  1. Navigate to Configuration > Administrative Tools > GINA/Mac/Linux (Ctrl+Alt+Del) > GINA/Mac/Linux Installation > Installed Machines.
  2. Select the required domain from the drop-down list.
  3. Select the machine that you want to exempt from machine-based MFA.
  4. Click Manage MFA drop-down and select Exempt.

    Machine-based MFA

Advanced Machine MFA Settings

ADSelfService Plus allows admins to enable MFA during specific usage scenarios for Windows machines. To request this feature for Mac or Linux, click here.

The authenticators in the prompts for the enabled scenarios will be based on the MFA factors configured in the MFA for Machine Login section. The settings enabled here will be applied to all Windows machines where the ADSelfService Plus login agent is installed.

Note: These settings pertain only to Windows machines. Advanced Machine MFA settings ensure that the machine will be secured with MFA under any circumstance, i.e., MFA will be enforced regardless of the enrollment status of the user who attempts to log in to the machine or when the ADSelfService Plus server is unreachable. Users who attempt to log in to the machine will be prompted for MFA based on the authenticators they have enrolled in as per their policy.

Windows MFA settings

Your request has been submitted to the ADSelfService Plus technical support team. Our technical support people will assist you at the earliest.

 

Need technical assistance?

  • Enter your email ID
  • Talk to experts
  •  
     
  •  
  • By clicking 'Talk to experts' you agree to processing of personal data according to the Privacy Policy.

Don't see what you're looking for?

  •  

    Visit our community

    Post your questions in the forum.

     
  •  

    Request additional resources

    Send us your requirements.

     
  •  

    Need implementation assistance?

    Try OnboardPro

     

On this page

Copyright © 2025, ZOHO Corp. All Rights Reserved.