> For the complete documentation index, see [llms.txt](https://docs.defguard.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.defguard.net/1.4/features/wireguard/multi-factor-authentication-mfa-2fa/external-sso-based-mfa.md).

# External SSO based MFA

{% hint style="warning" %}
Since [version 1.5.0 ](/1.5/features/wireguard/multi-factor-authentication-mfa-2fa.md)we support MFA based on external OIDC/SSO.
{% endhint %}

You can use [Internal OIDC/SSO](/1.4/features/openid-connect.md) - called [Internal MFA ](#internal-mfa)- to force Desktop & Mobile clients to authenticate with **TOTP & Email codes** and after that with **session keys based on WireGuard Pre-Shared Keys** (PSK). For more details about this, please refer to the [architecture section](/1.4/in-depth/architecture/architecture.md).
