> For the complete documentation index, see [llms.txt](https://docs.defguard.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.defguard.net/features/wireguard/multi-factor-authentication-mfa-2fa/external-sso-based-mfa.md).

# External SSO based MFA

In order to enable the External MFA authentication:

1. Your instance **must have** [external OIDC/SSO configured](/features/external-openid-providers.md).
2. Choose **External MFA** during location configuration or edit the desired location from **Locations** list.

<figure><img src="https://content.gitbook.com/content/tIboBQe0Rz5YT3cHdNlh/blobs/SbdgYGM19g0PabcPeWMj/image.png" alt=""><figcaption></figcaption></figure>

#### Client disconnect threshold

When MFA is enabled on a location, Defguard periodically (currently every **1 minute**) checks statistics if a client is connected and if the period of inactivity (defined in this option) is met, a client is disconnected.

Thus, the gateway needs to be configured to send statistics in that period.

{% hint style="info" %}
We recommend to set:

* Gateway to send statistics every 30sec
* Client disconnect threshold we recommend it to be min. 300 (5 min)
  {% endhint %}

### Testing MFA on Defguard client

When a location has External MFA enabled, after clicking Connect in the Desktop client ([here you can find information about Mobile Client External MFA](/using-defguard-for-end-users/mobile-client/instance-connect.md#external-mfa)), there will be information displayed about authentication requirement:

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-042d50986f78d4d614a1634043ff1a7ed7142cfe%2Fauth-with-openid-modal.png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

In order to authenticate the user will be prompted to click on Authenticate with your configured OIDC (like Authenticate with Google) - which will open the browser and start the authentication session with your OIDC/SSO provider by the [Defguard Enrollment ](/using-defguard-for-end-users/enrollment.md)service (which is the only public component).

After successful authentication, the user will be informed by the enrollment service like so:

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-ed5fe73c4dbbbefa29d43719d16d2dfcc45fe74d%2Fauth-completed-openid.png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

And the VPN connection will be established immediately.

Video describing whole process:

{% embed url="<https://www.youtube.com/embed/81MH7VXmHR0>" %}

## Biometry as an internal MFA method

Users can use biometry as an internal MFA method on their mobile devices. If a device has configured biometry as an MFA method, you will see fingerprint icon, next to the device name on devices list within user's profile.

<figure><img src="https://content.gitbook.com/content/tIboBQe0Rz5YT3cHdNlh/blobs/9FsulWINGhXI01G6dRqp/image.png" alt="" width="337"><figcaption></figcaption></figure>
