> For the complete documentation index, see [llms.txt](https://docs.defguard.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.defguard.net/using-defguard-for-end-users/desktop-client/using-multi-factor-authentication-mfa.md).

# Using Multi-Factor Authentication (MFA)

MFA is configured per location, and administrators choose whether a location uses internal MFA or an external OIDC/SSO provider.

Depending on location settings, you may use:

* Internal MFA - You must have at least one MFA method configured in your profile. For a detailed tutorial, [check out this article](/using-defguard-for-end-users/setting-up-2fa-mfa.md).
* External MFA - You will be redirected to an external site, where authentication is handled by your OIDC provider, for example Google/Microsoft.

## External MFA

### Desktop client in tray view mode

1. Click **Connect VPN** on the location with the **OpenID** label

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-47f59190016b72a56696610b8af90560ea3e7d76%2Fopenid-label-marked-tray-view.png?alt=media" alt=""><figcaption></figcaption></figure>

2. Click **Auth with OpenID**, you will be redirected to a secure site where you will need to log in in order to confirm your identity. (Google, Microsoft, Okta, etc.)

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-b8abd1513790087499d0a5af42c94fa118439cdb%2Fauth-with-openid-tray-view.png?alt=media" alt=""><figcaption></figcaption></figure>

3. After confirming your identity (logging in) you will see the "Authentication Completed" message.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-ed5fe73c4dbbbefa29d43719d16d2dfcc45fe74d%2Fauth-completed-openid.png?alt=media" alt=""><figcaption></figcaption></figure>

4. Now you can close this window and go back to the Defguard Client. Your connection will be established immediately.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-fe0c3a31e2b7d26331776ff057d1e5ba5dd78c73%2Ftray-view-openid-location-connected.png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

### Desktop client in full view mode

1. Click **Connect VPN** on the location with the **OpenID** label

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-5a41f9e28bbd86cfa6d86bd166177c8af07c907e%2Fopenid-marked-fullview.png?alt=media" alt=""><figcaption></figcaption></figure>

2. Click **Auth with OpenID**, you will be redirected to a secure site where you will need to log in in order to confirm your identity. (Google, Microsoft, Okta, etc.)

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-9261bd2db12495ab4b9a22632a8db22e0cb4c05b%2Fauth-with-openid.png?alt=media" alt=""><figcaption></figcaption></figure>

3. After confirming your identity (logging in) you will see the "Authentication Completed" message.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-ed5fe73c4dbbbefa29d43719d16d2dfcc45fe74d%2Fauth-completed-openid.png?alt=media" alt=""><figcaption></figcaption></figure>

4. Now you can close this window and go back to the Defguard Client. Your connection will be established immediately.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-2ca0ed0bdc465d4dac7eda5fd2a09460e325e0f3%2Fconnected-openid.png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

## Internal MFA

### Desktop client in tray view mode

1. If you are connecting to a location for the first time, click the pen icon on the right side of the panel. If not, skip to step 3.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-9543827cb7ab125383eba89d371f238a4ccb391d%2Fpen-icon-mfa-tray-view.png?alt=media" alt=""><figcaption></figcaption></figure>

2. Choose the MFA method configured in your profile and click **Save changes**. If you haven't configured any of them, do it as described in [this guide](/using-defguard-for-end-users/setting-up-2fa-mfa.md#setting-up-2famfa).

{% hint style="info" %}
If you need a guide explaining how to use Mobile Client as your MFA method, please [scroll down](#multi-factor-authentication-via-mobile-biometry).
{% endhint %}

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-10d715018a3ee7491c5c703bd543a127a554d6e1%2Fmfa-methods-tray-view.png?alt=media" alt=""><figcaption></figcaption></figure>

3. Click the **Connect VPN** button on the location.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-a5d56a7e350d6b748145f4e41ef296dce6f1aacd%2Fconnect-vpn-internal-mfa.png?alt=media" alt=""><figcaption></figcaption></figure>

4. Enter the code from your Authenticator app or Email (depending on your choice in step 2) and click **Verify**.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-f1a514467261e7309bae4466ad219520be3ac97f%2Fcode-internal-mfa-tray-view.png?alt=media" alt=""><figcaption></figcaption></figure>

5. Your VPN connection will be established immediately.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-0bbcf3d0fbb694cfe7c5cccb60151075f9502a0b%2Fconnected-mfa-tray-view.png?alt=media" alt=""><figcaption></figcaption></figure>

### Desktop client in full view mode

1. If you are connecting to a location for the first time, click the pen icon on the right side of the panel. If not, skip to step 3.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-fb52e8706cdde8375788841469b7b6c9c5d01503%2Ffull-view-pen-icon.png?alt=media" alt=""><figcaption></figcaption></figure>

2. Choose the MFA method configured in your profile and click **Save changes**. If you haven't configured any of them, do it as described in [this guide](/using-defguard-for-end-users/setting-up-2fa-mfa.md#setting-up-2famfa).

{% hint style="info" %}
If you need a guide explaining how to use Mobile Client as your MFA method, please [scroll down](#multi-factor-authentication-via-mobile-biometry).
{% endhint %}

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-449602add74a5f26075ef6fe0145de682226d39a%2Fmfa-methods-full-view.png?alt=media" alt=""><figcaption></figcaption></figure>

3. Click the **Connect VPN** button on the location.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-40a4b68296a93099b7834e29991937aebb44d0fa%2Fconnect-mfa-vpn-full-view.png?alt=media" alt=""><figcaption></figcaption></figure>

4. Enter the code from your Authenticator app or Email (depending on your choice in step 2) and click **Verify**.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-65663e8d0b9a83b685709400e9a9a30fee8bd68c%2Fcode-internal-mfa-full-view.png?alt=media" alt=""><figcaption></figcaption></figure>

5. Your VPN connection will be established immediately.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-35cbf16f982cd1b060d7ff331ad869b35a324e3f%2Fconnected-mfa-full-view.png?alt=media" alt=""><figcaption></figcaption></figure>

## Multi-Factor Authentication via Mobile Biometry

After configuring VPN on your mobile device and [enabling Biometry](/using-defguard-for-end-users/mobile-client/using-biometry-as-mfa-method.md#setting-up-biometry), we not only enable Biometry based connecting on a mobile device, but add an extra security layer to have the most secure/sophisticated MFA method available.

After enabling Biometry we create an additional private/public key pair, with the private key stored in hardware/secure storage, and indicate in the UI that this device can now be used for MFA using Biometry on a desktop client:

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-4def4b6f7c02bf1d978223e3b1e4b581a76697b0%2Ffingerprint-icon.png?alt=media" alt="" width="563"><figcaption></figcaption></figure>

When you connect via desktop client to a location that has Internal MFA requirement, you can choose **“Mobile Client”** for MFA Method.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-d0532c7dd995f38bb0d596dde3dd48875b8e1f42%2Fmobile-client-method.png?alt=media" alt=""><figcaption></figcaption></figure>

After selecting this method, before each connection you will see a QR code.

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-13e28edc7ef9c937588d42d3dcad6a84968771bd%2Fqr-code-for-mobile-auth.png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

This QR code must be scanned on the mobile device for additional MFA steps:

1. Biometry authentication, that enables access to device secure storage
2. Additional validation with private/public key pair between mobile/desktop/core server. After that, our “normal” MFA flow (with session keys, WireGuard private/public keys) takes place.

Here is a video showcasing this process:

{% embed url="<https://www.youtube.com/watch?v=b-XC76k4KVU>" %}

And here you can see the whole flow done with multiple steps including the user, desktop (and mobile) the Edge and Defguard Core and gateway in the final step:

<figure><img src="https://464489758-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtIboBQe0Rz5YT3cHdNlh%2Fuploads%2Fgit-blob-b4febc38a18446ad5f12c537d3977893ffbed3a9%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>
