This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

MFA on Global User Account

I am trying to figure out how to add MFA to global users.  

I was able to get mfa to work on domain accounts using the ldap servers.  

Does anyone now a way to ldap authentication of Global accounts or simple prevent global user authentication on the domain accounts I just trying to lockdown MFT with MFA for public access thanks

Parents Reply Children
  • I have 2 global accounts for the administration of all domains.  I have 3 domains account set up for customers, internal employees, and testing.  

    2 global admins have complex passwords and have alerts when logged in to my email.

    Customer domains are setup to an LDAP server configured for customers we have

    Employee domain are setup with duo LDAP for file sharing and SFTP access

    The testing account is used for configuration changes I test before moving to production. 

  • Thanks for the info, have you created your global administrators at the Server level or Domain level. It is possible to have 'Global Administrators' within a domain rather than specifying them at the global level in Serv-U. Maybe this will help you use the same MFA method you have in place for domain users?

  • The problem I have is LDAP users can not have admin privileges. MFA only works on LDAP users currently.  Not on domain users as it authenticates via MFT not DUO.

  • Ahh I understand now. One option you could do as a workaround is to add IP Access rules on the domain users, then they cannot login even if the password was used.

    Or, create a separate domain for admin users and only have a listener on a local LAN IP, and optionally add IP Access rules at the domain level.

  • Thanks for the idea I test this with the Test domain for the use case and let you know.