To increase the security of your Lansweeper site, you can enable multi-factor authentication (MFA). This extra layer on top of your regular login protects the asset and user data stored in Lansweeper Platform.
There are two ways to implement MFA. You can enable SSO and use the MFA options offered by your identity provider, or you can use the MFA configuration built into Lansweeper Platform.
If you enable both, you need to provide a one-time password (OTP) from your authenticator app twice when you log in with SSO: one OTP for the MFA in Lansweeper Platform, and another for the MFA in your identity provider.
Enable MFA through SSO
With SSO enabled, you log in to Lansweeper Platform using your preferred identity provider, for example Microsoft Entra ID. You can then enable and enforce MFA through that identity provider.
For how to configure SSO, see Set up an SSO connection.
Enable MFA through Lansweeper Platform
If you don't want to enable MFA through SSO, you can enable it in Lansweeper Platform itself. You enable MFA per account, and you can configure your site to require it.
Enable MFA for your individual account before you enforce it for your site.
Enable MFA for an individual account
Before you start, install an authenticator app such as Microsoft Authenticator or Google Authenticator on your mobile phone.
To enable MFA for the logged-in account:
- Select your profile picture in the top-right corner, then select Account settings.
- Toggle Multi-factor authentication. A QR code appears. Scan it with your authenticator app.
- Your authenticator app adds the account and generates a time-based one-time password (TOTP code).
- Enter the TOTP code from the app underneath the QR code and continue.
- A new window shows your recovery key. Save it in a safe place.
MFA is now enabled for your account. Alongside your regular credentials, you generate a TOTP code with the authenticator app each time you log in.
You can also log in with your recovery key. If you do, Lansweeper generates a new key to replace the previous one.
Enforce MFA for all accounts linked to a site
To enforce MFA for all accounts that have access to your site:
- Go to Site settings > General > Authentication.
- Enable Require MFA for this site.
- Select Confirm in the pop-up window.
MFA is now enforced for the site. Any user who tries to access the site must enable MFA first. Each user configures MFA in their own account settings, as described earlier in this article.