×
×
×
×

Secure Authentication | Endpoint Central MSP

Endpoint Central MSP provides secure authentication settings to protect console access and reduce the risk of compromised credentials. This document explains how to enable Two-Factor Authentication (TFA), manage TFA for individual users, and recover access if an administrator is locked out. It also covers how to configure User Account Policies and Password Policies to control login attempts, sessions, and password strength.

Two-Factor Authentication (TFA)

In response to increasing cybersecurity threats, Endpoint Central MSP incorporates Two-Factor Authentication (TFA) to enhance security. TFA adds a layer of authentication beyond the standard username and password, ensuring that only authorized users can access the console.

TFA is configured at the organization level. It applies to all users and takes effect from their next login.

Note
A mail server must be configured for TFA to work in both modes. In Email mode, the OTP is sent by email. In Authenticator App mode, the QR code is sent by email. Users must also have a registered email address. Refer to the Mail Server Configuration document for detailed setup instructions.

To enable Two-Factor Authentication (TFA), follow these steps:

Step 1: Open Two-Factor Authentication Settings

Navigate to Admin → User Administration → Secure Authentication → Two-Factor Authentication.

By default, Authentication is set to Disable.

Two-Factor Authentication settings page

Step 2: Enable Authentication

Click the Enable radio button next to Authentication. Two additional settings appear:

  • Mode of Authentication: Choose Email or Authenticator App. See Step 3.
  • Allow browser to save the OTP for: Set how long a browser can remember a successful OTP verification. See Step 4.

Step 3: Choose the Mode of Authentication

Mode 1: Email

Email mode selected for Two-Factor Authentication

Email is selected by default when TFA is enabled. When a user logs in, an OTP is sent to their registered email address. The user enters this OTP on the login screen to complete authentication.

Mode 2: Authenticator App

Authenticator App mode selected for Two-Factor Authentication

When Authenticator App mode is enabled, a QR code is sent to the user's registered email address. The user scans this QR code with an authenticator app on their smartphone to register their account. On every subsequent login, the app generates a time-based OTP, which the user enters to complete authentication.

The following authenticator apps are supported:

Step 4: Set the Browser OTP Save Duration

The Allow browser to save the OTP for field controls how long a browser can remember a successful OTP verification before prompting the user again. You can set this duration up to a maximum of 180 days.

Step 5: Save the Configuration

Click Save to apply the settings.

What Happens After TFA Is Enabled

Email Mode

  1. On the next login, after entering the username and password, the user sees an OTP entry screen.
  2. An OTP is sent to the user's registered email address.
  3. The user enters the OTP to complete the login.
  4. If a browser save duration is set, the user is not prompted again until that duration expires.

Authenticator App Mode

  1. On the next login, after entering the username and password, the user is prompted to set up the authenticator app.
  2. A QR code is sent to the user's registered email address.
  3. The user scans the QR code with a supported authenticator app.
  4. The app shows a 6-digit time-based OTP that refreshes every 30 seconds.
  5. The user enters the current OTP to complete the login.
  6. On all subsequent logins, the user opens the app and enters the OTP shown.

Managing TFA for Individual Users

Regenerating the QR Code (User Changed Phone or Lost Device)

This applies only when the mode is Authenticator App. If a user changes their phone or loses the device that has the authenticator app, an administrator must regenerate the user's QR code.

  1. Go to Admin → User Administration → Users.
  2. Find the user.
  3. Click the three-dot action menu (⋮) next to the user's name.
  4. Select Regenerate QR Code.
  5. A new QR code is sent to the user's registered email address.
  6. The user scans the new QR code on their new device.

What Administrators Cannot Do for Individual Users

  • Disable TFA for a single user. TFA is an organization-wide setting.
  • Set a different TFA mode for individual users. The selected mode applies to all users.
  • Bypass TFA for service accounts or automation accounts.

Disable TFA Temporarily

If an administrator cannot complete TFA (for example, the mail server is unreachable, the device is lost, or the authenticator app is deleted), you can disable TFA temporarily from the server.

  1. Access the Endpoint Central MSP server directly, either through Remote Desktop (RDP) or by physical access.
  2. Open Run, type services.msc, and stop the ManageEngine UEMS - Central Server service.
    Windows Services window showing the Central Server service
    Stopping the Central Server service in Windows Services
  3. Open a Command Prompt as an administrator and navigate to the <Install_Dir>\bin directory.
  4. Run the following command: disableTFA.bat TempDisable
    Command prompt running disableTFA.bat with the TempDisable argument
  5. When prompted, enter the administrator username and password.
  6. When prompted for the domain name, enter it if the user is an Active Directory user. Press Enter if the user is a local user.
  7. TFA is now temporarily disabled. TFA enforcement is applied again after a grace period of 2 days (48 hours).
    Two-Factor Authentication enforcement settings with grace period
  8. Start the ManageEngine UEMS - Central Server service from Services.
  9. Log in to the console, then reconfigure TFA or regenerate the affected user's QR code.
Note
To disable Two-Factor Authentication permanently, contact Support.

User Account Policy

Endpoint Central MSP user account policies let administrators regulate how user accounts are managed, based on login attempts, inactivity, and session expiry.

To configure the User Account Policy, follow these steps:

  1. Log in to the Endpoint Central MSP console.
  2. Navigate to Admin → User Administration → Secure Authentication → User Account Policy.
    User Account Policy configuration page

Configuration Options

Invalid Login Attempts

This setting controls what happens after repeated unsuccessful login attempts.

  • Specify the number of failed login attempts allowed before action is taken.
  • Choose whether to disable or temporarily lock the account.
  • Define the lockout duration to prevent repeated unauthorized login attempts.
    Invalid Login Attempts and lockout duration settings

Domain Settings

These settings manage how users authenticate.

  • Enable Hide Domain List to require users to enter the domain name manually during login.
  • Set the Default Domain for Authentication, for example, Local Authentication or an Active Directory domain.
    Hide Domain List and Default Domain for Authentication settings

Account Inactivity

Accounts can be disabled automatically after a specified period of inactivity. This helps prevent the misuse of dormant accounts and ensures that only active users have access to the console.

  • Enable automatic account disablement after a specified period of inactivity.
    Account Inactivity settings

Session Expiry Settings

These settings define how long a user session remains active before re-authentication is required.

  • Define the session expiration duration.
  • Enable Idle Session Timeout to sign out inactive users automatically.
  • Allow users to configure their own session expiration settings within the limits you define.
    Session Expiry settings

Click Save to apply the changes, or Cancel to discard them.

Password Policy

A password policy helps prevent unauthorized access by enforcing strong password requirements. Endpoint Central MSP lets administrators enforce these requirements across user accounts.

To configure the Password Policy, follow these steps:

  1. Log in to the Endpoint Central MSP console.
  2. Navigate to Admin → User Administration → Secure Authentication → Password Policy.

Configuration Options

  • Minimum Password Length: Define the minimum number of characters required.
  • Minimum number of special characters: Specify the required number of special characters for password complexity.
  • Users cannot reuse last: Specify the number of previous passwords that users cannot reuse.
  • Enforce password change: Enforce periodic password changes by specifying an update interval.

Click Save to apply the changes.