Skip to main content

Configure Multifactor Authentication for MSP Administrators

Multifactor Authentication (MFA) provides an additional layer of security by verifying an administrator's identity using a combination of two authentication steps. To ensure the highest level of security across centralized management environments and protect against single points of failure, MFA is mandated for all commercial Managed Service Provider (MSP) accounts accessing the Managed Services Center (MSC).

At every login, administrators across your organization must enter a One Time Password (OTP) in addition to their standard login password.


Notes:

  • Administrative Access: Only an MSP Admin can configure organization-wide MFA settings or reset MFA for other administrators. Tenant Admins and Read-only Admins do not have access to these capabilities.

  • Evaluation (Eval) Accounts: Evaluation MSP accounts have the option to disable MFA post-login. However, once an Eval MSP is converted to a commercial account, MFA becomes strictly mandated upon the next login, and the administrator will be prompted to configure it immediately.


Supported Multifactor Authentication Methods

The MSC supports the following modern MFA methods:

Method

Description

Authenticator App (TOTP)

The OTP is generated by the administrator's linked Authenticator app.

The following Authenticator Apps are certified by Druva:

  • Microsoft Authenticator

  • Google Authenticator

  • Authy

  • Duo

  • LastPass

  • Symantec VIP

First-Time Login and Mandated Configuration

Upon your first login, you will be guided through a mandatory configuration process. You will not be able to access the MSC until this step is complete. During this process, you will be required to set up a new password that meets the new Strong Password Policy requirements.

Switch Between Authenticator App and SMS

MSP Admins can seamlessly switch their authentication mechanism between an Authenticator App and SMS.


Note: This action updates the required authentication method for the entire organization, not just your personal account.


  1. From the MSC console, click the settings gear icon in the top right corner and navigate to Access Settings.

  2. Under the Multifactor Authentication section, select Authenticator App-based Multi-Factor Authentication.

  3. Scan the displayed QR code using your authenticator app, then enter the 6-digit code it generates to verify the setup.

Upon successful verification, your authentication method will be updated. For all subsequent logins, administrators will be required to authenticate using the OTP generated by their linked app.

Reset Multifactor Authentication

If an administrator changes their mobile device, uninstalls their authenticator app, or loses access to their phone, an MSP Admin can reset their MFA configuration from the MSC.

  1. From the MSC dashboard, navigate to the administrator management section.

  2. Locate and click on the specific administrator whose authentication needs to be reset.

  3. Select the option to Reset MFA for that user.

4. Confirm the action in the dialogue box.

What happens after a reset?

During their very next login attempt, the affected Admin will be treated as a first-time setup and will be prompted to link their authenticator app again using a new QR code.

Did this answer your question?