Skip to main content

Two-Factor Authentication

OneFirewall supports two-factor authentication (2FA) across cloud, on-premises, and hybrid deployments, and for personal user accounts. 2FA requires a second verification factor in addition to the password.

Service Accounts and OTP

Service accounts, used for automation, integrations, and non-interactive access, authenticate without an OTP challenge. This keeps API integrations and CI/CD pipelines from being disrupted by 2FA. Scope service accounts tightly and protect them with strong credentials and network controls.

OTP Lockout Policy

After 10 consecutive unsuccessful OTP attempts, the account is automatically locked. While locked, login is denied even with correct credentials. An administrator must manually reset the OTP status via the OneFirewall portal to restore access.

Recommendation

Enable 2FA on personal accounts, particularly for administrators and users with access to logs, rules, policy configuration, or API/integration permissions.