2fa support with AD

Options
Omniasrl
Omniasrl Posts: 6 image  Freshman Member
First Comment Friend Collector

Goodmornig,

it's possible to configure 2fa with Active directory authentication?

Thanks

Accepted Solution

  • Zyxel_Tina
    Zyxel_Tina Posts: 471 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers First Comment
    Answer ✓

    Hi @Omniasrl,

    The 2FA authentication support for external AD/LDAP by Email will be available in the upcoming uOS firmware version 1.38, scheduled for release in April 2026.

    Please refer to the official release notes for more details once the firmware is available. Thank you!

    Zyxel Tina

All Replies

  • Zyxel_Tina
    Zyxel_Tina Posts: 471 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers First Comment

    Hi @Omniasrl,

    To implement 2FA/MFA for external users, please use SMS or Email-based MFA. This method is supported for AD/LDAP users. For configuration details, please refer to p.584 in our handbook.

    Also, please ensure that the mobile number and/or Email address is filled in your AD server so that the SMS/Email authentication codes can be delivered properly.

    Zyxel Tina

  • Omniasrl
    Omniasrl Posts: 6 image  Freshman Member
    First Comment Friend Collector

    We are operating on a Usg flex 500H in HA. Does the same guide apply?
    Our tests show that it does not work.

  • Zyxel_Tina
    Zyxel_Tina Posts: 471 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers First Comment

    Hi @Omniasrl,

    I apologize for the confusion. Currently, USG FLEX H series devices (uOS) only support 2FA (Google Authenticator) for local users and do not support 2FA for AD/external users.

    Zyxel Tina

  • Omniasrl
    Omniasrl Posts: 6 image  Freshman Member
    First Comment Friend Collector

    is there an ETA?

  • Zyxel_Tina
    Zyxel_Tina Posts: 471 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers First Comment
    Answer ✓

    Hi @Omniasrl,

    The 2FA authentication support for external AD/LDAP by Email will be available in the upcoming uOS firmware version 1.38, scheduled for release in April 2026.

    Please refer to the official release notes for more details once the firmware is available. Thank you!

    Zyxel Tina