Advanced Settings

The Advanced tab under Configuration > Multi-Factor Authentication contains important settings that you can configure to further control the behavior of the MFA process for password resets, ADSelfService Plus logins, and endpoint logins.

About backup codes

CAPTCHA Settings

Hide CAPTCHA in: Hide the CAPTCHA on second-factor authentication pages by selecting it from the drop-down.

MFA Recovery

Enable MFA Backup Verification Codes: Select this setting to enable the generation of the MFA backup codes that let end users prove their identity when their MFA device or authenticator is unavailable.

About backup codes

These one-time-use backup codes allow users to prove their identities in case their MFA device is not reachable or they are unable to use their enrolled MFA methods of authentication. Once the Enable MFA Backup Verification Codes setting is enabled, the backup codes can be generated and end-users can enter them to authenticate themselves during machine or VPN logon, ADSelfService Plus portal login, or self-service actions. Backup codes can be generated in two ways:

Note:
  • Users can deploy backup codes during VPN logins only when RADIUS-challenge response-based authentication methods are used for VPN MFA login.
  • During VPN MFA, the generated backup code can be entered in the field provided for one-time passcodes at the VPN client.
  • When identity verification is performed using backup codes, the Trust this browser and Trust this machine options will not be considered.

About backup codes

MFA for password resets
MFA for account unlocks

Machine Login MFA

Note: MFA for machine logins requires the Professional edition of ADSelfService Plus with endpoint MFA.

These are policy-based settings and will be enforced when a user under the policy attempts to log into a machine on the domain. Based on this configuration, MFA might be bypassed on machines if the user is not enrolled. To enforce MFA on machines irrespective of the enrollment status of the user, please configure machine-based MFA.

The Machine Login MFA section gives admins granular control over MFA prompts for machines on the network.

About backup codes

OWA Login MFA

Note: MFA for OWA logins requires the Professional edition of ADSelfService Plus with Endpoint MFA.

About backup codes

VPN Login MFA

Note: MFA for VPN logins requires the Professional Edition of ADSelfService Plus with Endpoint MFA.

Configuring additional attributes

  1. If you try to enable this feature before configuring the attributes, you will be shown a pop-up to configure them. Click OK. You can also click the Configure Attributes link.
  2. You can configure RADIUS's Standard or Vendor-specific attributes and corresponding values to be sent to the VPN providers (other RADIUS endpoints).

    MFA for OWA Login

  3. Enter the Vendor ID by clicking on the Edit [ Edit ] button. The Vendor ID is the unique number that denotes your VPN provider. For example, if using Fortigate, the Vendor ID is 12356.
  4. Choose the Type of attribute and enter the Attribute Number, Format, and Value in the fields displayed.

    For attributes in the string format, the values should be in characters, and for the attributes in the int format, the values should be in integers.

    For enum attributes, which contain multiple predefined values, provide the desired value in terms of their associated integers. For example, if you wish to use Login as the service-type attribute, enter 1 in the Value field.

    In case attributes are in the IPv4 or IPv6 address formats, please provide a valid IP address in the Value field.

    For example, your IPv4 address can look like 10.1.1.1, and your IPv6 address can look like 2001:0db8:85a3::8a2e:0370:7334.

  5. Click OK after configuring all the attributes you require.
  6. Once successfully configured, the Send additional attributes as a response to the VPN server after successful completion of MFA setting will be enabled.

Cloud Applications Login MFA

Others backup codes

ADSelfService Plus Login MFA

About backup codes

Question Settings

Others backup codes

Answer Settings

Answer Strengtheners (for Security Q&A only)

Others backup codes

Mail/Mobile Attributes

Others backup codes

Secondary Email/ Mobile Number

Others backup codes

Others

Others backup codes

Your request has been submitted to the ADSelfService Plus technical support team. Our technical support people will assist you at the earliest.

 

Need technical assistance?

  • Enter your email ID
  • Talk to experts
  •  
     
  •  
  • By clicking 'Talk to experts' you agree to processing of personal data according to the Privacy Policy.

Don't see what you're looking for?

  •  

    Visit our community

    Post your questions in the forum.

     
  •  

    Request additional resources

    Send us your requirements.

     
  •  

    Need implementation assistance?

    Try OnboardPro

     

On this page

Copyright © 2025, ZOHO Corp. All Rights Reserved.