Secure Authentication | Endpoint Central MSP
Endpoint Central MSP provides secure authentication settings to protect console access and reduce the risk of compromised credentials. This document explains how to enable Two-Factor Authentication (TFA), manage TFA for individual users, and recover access if an administrator is locked out. It also covers how to configure User Account Policies and Password Policies to control login attempts, sessions, and password strength.
Two-Factor Authentication (TFA)
In response to increasing cybersecurity threats, Endpoint Central MSP incorporates Two-Factor Authentication (TFA) to enhance security. TFA adds a layer of authentication beyond the standard username and password, ensuring that only authorized users can access the console.
TFA is configured at the organization level. It applies to all users and takes effect from their next login.
To enable Two-Factor Authentication (TFA), follow these steps:
Step 1: Open Two-Factor Authentication Settings
Navigate to Admin → User Administration → Secure Authentication → Two-Factor Authentication.
By default, Authentication is set to Disable.

Step 2: Enable Authentication
Click the Enable radio button next to Authentication. Two additional settings appear:
Step 3: Choose the Mode of Authentication
Mode 1: Email

Email is selected by default when TFA is enabled. When a user logs in, an OTP is sent to their registered email address. The user enters this OTP on the login screen to complete authentication.
Mode 2: Authenticator App

When Authenticator App mode is enabled, a QR code is sent to the user's registered email address. The user scans this QR code with an authenticator app on their smartphone to register their account. On every subsequent login, the app generates a time-based OTP, which the user enters to complete authentication.
The following authenticator apps are supported:
Step 4: Set the Browser OTP Save Duration
The Allow browser to save the OTP for field controls how long a browser can remember a successful OTP verification before prompting the user again. You can set this duration up to a maximum of 180 days.
Step 5: Save the Configuration
Click Save to apply the settings.
What Happens After TFA Is Enabled
Email Mode
- On the next login, after entering the username and password, the user sees an OTP entry screen.
- An OTP is sent to the user's registered email address.
- The user enters the OTP to complete the login.
- If a browser save duration is set, the user is not prompted again until that duration expires.
Authenticator App Mode
- On the next login, after entering the username and password, the user is prompted to set up the authenticator app.
- A QR code is sent to the user's registered email address.
- The user scans the QR code with a supported authenticator app.
- The app shows a 6-digit time-based OTP that refreshes every 30 seconds.
- The user enters the current OTP to complete the login.
- On all subsequent logins, the user opens the app and enters the OTP shown.
Managing TFA for Individual Users
Regenerating the QR Code (User Changed Phone or Lost Device)
This applies only when the mode is Authenticator App. If a user changes their phone or loses the device that has the authenticator app, an administrator must regenerate the user's QR code.
- Go to Admin → User Administration → Users.
- Find the user.
- Click the three-dot action menu (⋮) next to the user's name.
- Select Regenerate QR Code.
- A new QR code is sent to the user's registered email address.
- The user scans the new QR code on their new device.
What Administrators Cannot Do for Individual Users
- Disable TFA for a single user. TFA is an organization-wide setting.
- Set a different TFA mode for individual users. The selected mode applies to all users.
- Bypass TFA for service accounts or automation accounts.
Disable TFA Temporarily
If an administrator cannot complete TFA (for example, the mail server is unreachable, the device is lost, or the authenticator app is deleted), you can disable TFA temporarily from the server.
- Access the Endpoint Central MSP server directly, either through Remote Desktop (RDP) or by physical access.
- Open Run, type
services.msc, and stop the ManageEngine UEMS - Central Server service.

- Open a Command Prompt as an administrator and navigate to the
<Install_Dir>\bindirectory. - Run the following command:
disableTFA.bat TempDisable
- When prompted, enter the administrator username and password.
- When prompted for the domain name, enter it if the user is an Active Directory user. Press Enter if the user is a local user.
- TFA is now temporarily disabled. TFA enforcement is applied again after a grace period of 2 days (48 hours).

- Start the ManageEngine UEMS - Central Server service from Services.
- Log in to the console, then reconfigure TFA or regenerate the affected user's QR code.
User Account Policy
Endpoint Central MSP user account policies let administrators regulate how user accounts are managed, based on login attempts, inactivity, and session expiry.
To configure the User Account Policy, follow these steps:
- Log in to the Endpoint Central MSP console.
- Navigate to Admin → User Administration → Secure Authentication → User Account Policy.

Configuration Options
Invalid Login Attempts
This setting controls what happens after repeated unsuccessful login attempts.
- Specify the number of failed login attempts allowed before action is taken.
- Choose whether to disable or temporarily lock the account.
- Define the lockout duration to prevent repeated unauthorized login attempts.

Domain Settings
These settings manage how users authenticate.
- Enable Hide Domain List to require users to enter the domain name manually during login.
- Set the Default Domain for Authentication, for example, Local Authentication or an Active Directory domain.

Account Inactivity
Accounts can be disabled automatically after a specified period of inactivity. This helps prevent the misuse of dormant accounts and ensures that only active users have access to the console.
- Enable automatic account disablement after a specified period of inactivity.

Session Expiry Settings
These settings define how long a user session remains active before re-authentication is required.
- Define the session expiration duration.
- Enable Idle Session Timeout to sign out inactive users automatically.
- Allow users to configure their own session expiration settings within the limits you define.

Click Save to apply the changes, or Cancel to discard them.
Password Policy
A password policy helps prevent unauthorized access by enforcing strong password requirements. Endpoint Central MSP lets administrators enforce these requirements across user accounts.
To configure the Password Policy, follow these steps:
- Log in to the Endpoint Central MSP console.
- Navigate to Admin → User Administration → Secure Authentication → Password Policy.
Configuration Options
- Minimum Password Length: Define the minimum number of characters required.
- Minimum number of special characters: Specify the required number of special characters for password complexity.
- Users cannot reuse last: Specify the number of previous passwords that users cannot reuse.
- Enforce password change: Enforce periodic password changes by specifying an update interval.
Click Save to apply the changes.