> For the complete documentation index, see [llms.txt](https://docs.defguard.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.defguard.net/2.1/using-defguard-for-end-users/desktop-client/using-multi-factor-authentication-mfa.md).

# Using Multi-Factor Authentication (MFA)

MFA is configured per location, and administrators choose whether a location uses internal MFA or an external OIDC/SSO provider.

Depending on location settings, you may use:

* Internal MFA - You must have at least one MFA method configured in your profile. For a detailed tutorial, [check out this article](/2.1/using-defguard-for-end-users/setting-up-2fa-mfa.md).
* External MFA - You will be redirected to an external site, where authentication is handled by your OIDC provider, for example Google/Microsoft.

## External MFA

### Desktop client in tray view mode

1. Click **Connect VPN** on the location with the **OpenID** label

<figure><img src="/files/DvNxiBPyOZu4cSp6UlyQ" alt=""><figcaption></figcaption></figure>

2. Click **Auth with OpenID**, you will be redirected to a secure site where you will need to log in in order to confirm your identity. (Google, Microsoft, Okta, etc.)

<figure><img src="/files/3YgUcFrS27XecnQ4803j" alt=""><figcaption></figcaption></figure>

3. After confirming your identity (logging in) you will see the "Authentication Completed" message.

<figure><img src="/files/57XoTVoDBIqQzYIJ4y8h" alt=""><figcaption></figcaption></figure>

4. Now you can close this window and go back to the Defguard Client. Your connection will be established immediately.

<figure><img src="/files/IYuKeGodWWXY69wIVepo" alt="" width="375"><figcaption></figcaption></figure>

### Desktop client in full view mode

1. Click **Connect VPN** on the location with the **OpenID** label

<figure><img src="/files/ngmHlfjHKqstAAMp5fUY" alt=""><figcaption></figcaption></figure>

2. Click **Auth with OpenID**, you will be redirected to a secure site where you will need to log in in order to confirm your identity. (Google, Microsoft, Okta, etc.)

<figure><img src="/files/46s7d7ROybQr3rJz9afh" alt=""><figcaption></figcaption></figure>

3. After confirming your identity (logging in) you will see the "Authentication Completed" message.

<figure><img src="/files/57XoTVoDBIqQzYIJ4y8h" alt=""><figcaption></figcaption></figure>

4. Now you can close this window and go back to the Defguard Client. Your connection will be established immediately.

<figure><img src="/files/krK5bkrVrVi788U0hrtD" alt="" width="375"><figcaption></figcaption></figure>

## Internal MFA

### Desktop client in tray view mode

1. If you are connecting to a location for the first time, click the pen icon on the right side of the panel. If not, skip to step 3.

<figure><img src="/files/AyWBOhCOgziASMLl3jDP" alt=""><figcaption></figcaption></figure>

2. Choose the MFA method configured in your profile and click **Save changes**. If you haven't configured any of them, do it as described in [this guide](/2.1/using-defguard-for-end-users/setting-up-2fa-mfa.md#setting-up-2famfa).

{% hint style="info" %}
If you need a guide explaining how to use Mobile Client as your MFA method, please [scroll down](#multi-factor-authentication-via-mobile-biometry).
{% endhint %}

<figure><img src="/files/bQnlXiNPi0etbK84Zb00" alt=""><figcaption></figcaption></figure>

3. Click the **Connect VPN** button on the location.

<figure><img src="/files/lr1x14yiwA5Jkbxiw97S" alt=""><figcaption></figcaption></figure>

4. Enter the code from your Authenticator app or Email (depending on your choice in step 2) and click **Verify**.

<figure><img src="/files/OdhsgjrpDBfjEGXeVeri" alt=""><figcaption></figcaption></figure>

5. Your VPN connection will be established immediately.

<figure><img src="/files/SdIDWimtAMnlqL77p7mX" alt=""><figcaption></figcaption></figure>

### Desktop client in full view mode

1. If you are connecting to a location for the first time, click the pen icon on the right side of the panel. If not, skip to step 3.

<figure><img src="/files/Kx8PnGwogNN11I2gv7w3" alt=""><figcaption></figcaption></figure>

2. Choose the MFA method configured in your profile and click **Save changes**. If you haven't configured any of them, do it as described in [this guide](/2.1/using-defguard-for-end-users/setting-up-2fa-mfa.md#setting-up-2famfa).

{% hint style="info" %}
If you need a guide explaining how to use Mobile Client as your MFA method, please [scroll down](#multi-factor-authentication-via-mobile-biometry).
{% endhint %}

<figure><img src="/files/59DApfNRLV6KvLEC4JHC" alt=""><figcaption></figcaption></figure>

3. Click the **Connect VPN** button on the location.

<figure><img src="/files/oSgOlG5nIiaf1wSq7UN5" alt=""><figcaption></figcaption></figure>

4. Enter the code from your Authenticator app or Email (depending on your choice in step 2) and click **Verify**.

<figure><img src="/files/E7TrIUpUlJzFUFaF2F19" alt=""><figcaption></figcaption></figure>

5. Your VPN connection will be established immediately.

<figure><img src="/files/v63PBn0lIyML8pjOLUtf" alt=""><figcaption></figcaption></figure>

## Multi-Factor Authentication via Mobile Biometry

After configuring VPN on your mobile device and [enabling Biometry](/2.1/using-defguard-for-end-users/mobile-client/using-biometry-as-mfa-method.md#setting-up-biometry), we not only enable Biometry based connecting on a mobile device, but add an extra security layer to have the most secure/sophisticated MFA method available.

After enabling Biometry we create an additional private/public key pair, with the private key stored in hardware/secure storage, and indicate in the UI that this device can now be used for MFA using Biometry on a desktop client:

<figure><img src="/files/EQqo2LUUHSaf2upsFvqc" alt="" width="563"><figcaption></figcaption></figure>

When you connect via desktop client to a location that has Internal MFA requirement, you can choose **“Mobile Client”** for MFA Method.

<figure><img src="/files/w3BEGvlUhsRIollkDpzo" alt=""><figcaption></figcaption></figure>

After selecting this method, before each connection you will see a QR code.

<figure><img src="/files/g16ydUNsKXv3V8Pg9BSP" alt="" width="375"><figcaption></figcaption></figure>

This QR code must be scanned on the mobile device for additional MFA steps:

1. Biometry authentication, that enables access to device secure storage
2. Additional validation with private/public key pair between mobile/desktop/core server. After that, our “normal” MFA flow (with session keys, WireGuard private/public keys) takes place.

Here is a video showcasing this process:

{% embed url="<https://www.youtube.com/watch?v=b-XC76k4KVU>" %}

And here you can see the whole flow done with multiple steps including the user, desktop (and mobile) the Edge and Defguard Core and gateway in the final step:

<figure><img src="/files/jaC6lspKMmMp05HFp9s2" alt=""><figcaption></figcaption></figure>
