The need to protect remote access

Remote access is the most targeted attack surface in enterprise environments. Coalition's Cyber Threat Index 2025 states that remote desktop products served as the entry point for 18% of ransomware attacks in 2024. In most organizations, a username and password or an SSH key pair is the only credential protecting RDP sessions, SSH logins, and file transfers over Secure Copy Protocol (SCP) and SSH File Transfer Protocol (SFTP).

Coverage gaps in existing tools compound the problem. Native Linux systems have no MFA capabilities for Linux machines that are not domain-joined. Legacy MFA agents only intercepted GUI-based login flows, leaving SSH, SCP, SFTP, and headless CLI sessions unprotected. VPN MFA Integration secures the network tunnel but not the destination, once a user is on the network, RDP sessions, SSH logins, and file transfers proceed without any further identity challenge.

Zero Trust Network Access requires that every authentication event is verified against identity regardless of network position. Remote access without MFA at the session layer is incompatible with a genuine Zero Trust posture.

MFA for remote access and CLI with Identity Access

ManageEngine Identity Access extends MFA for every remote access session: RDP connections, SSH logins, SCP and SFTP file transfers, and headless CLI sessions, across Windows, Linux, and macOS, from a single unified deployment.

With the solution, for Windows RDP sessions, enforcement is applied through the Remote Desktop Gateway. For Linux and macOS, a native pluggable authentication module (PAM) module intercepts authentication at the OS layer, covering SSH, SCP, SFTP, and headless CLI sessions regardless of whether a display manager is present. Non-domain Linux machines authenticate via RADIUS Authentication Protocol, with no Active Directory domain membership required.

Identity Access' Conditional Access engine evaluates session context, IP address, geolocation, and device type, in real time, applying MFA requirements selectively based on who is connecting, from where, and under what conditions.

Identity Access conditional access policy enforcing MFA for RDP, SSH, UAC, and CLI elevation across computer devices.
Figure 1: Remote Access and CLI MFA configuration

How remote access and CLI MFA works

MFA for RDP

Enforce MFA on every inbound RDP session to Windows servers and desktops. The IdSecurity login agent intercepts the authentication request before the session is established, requiring a verified second factor from every connecting user.

Here's the step-by-step MFA flow.

  1. A user initiates an RDP connection to a Windows server or desktop.
  2. The IdSecurity login agent installed on the machine intercepts the authentication request before the session is established.
  3. The agent attempts to contact the IdentityAccess server. If the server is unreachable, Offline MFA applies, the user is challenged using locally cached credentials, ensuring enforcement continues without server availability.
  4. If the IdentityAccess server is reachable, the agent evaluates the active Conditional Access policy for the connecting user—scoping MFA requirements based on user identity, group membership, device, and IP address.
  5. If primary credentials are valid and the session falls within a policy that requires MFA, the agent triggers a second-factor authentication challenge.
  6. The user completes the MFA challenge through their enrolled authenticator.
  7. Upon successful verification, the RDP session is established.

MFA for SSH, SCP, SFTP, and CLI

Enforce MFA across every Linux and macOS remote access session type:

  • Inbound SSH connections covering both password-based and public key authentication.
  • SCP and SFTP file transfers treated as independent authentication events
  • Headless CLI sessions on servers with no display manager or graphical interface.

Here's the step-by-step MFA flow.

  • A user initiates an SSH session, SCP or SFTP file transfer, or headless CLI connection.
  • The IdSecurity agent installed on the machine intercepts the authentication request through its native PAM module at the OS layer.
  • The agent attempts to contact the IdentityAccess server. If the server is unreachable, Offline MFA applies—the user is challenged using locally cached credentials, ensuring enforcement continues without server availability.
  • If the IdentityAccess server is reachable, the agent evaluates the active Conditional Access policy for the connecting user—scoping MFA requirements based on user identity, group membership, device, and IP address.
  • If primary credentials are valid and the session falls within a policy that requires MFA, a second-factor authentication challenge is triggered.
  • The user completes the MFA challenge through their enrolled authenticator.
  • Upon successful verification, the session or file transfer is permitted.

Supported authentication methods

Identity Access provides authenticators for remote access MFA, including:

  • FIDO2 authentication
  • Biometric authentication
  • Hardware TOTP
  • Software TOTP
  • DUO Security
  • Smartcard authentication
  • SAML authentication
  • SMS verification
  • Email verification
  • HOTP

Key capabilities of Identity Access' CLI and remote access MFA

  • Granular policy configuration

    Configure MFA requirements for particular users or groups, and apply stricter authentication to privileged accounts and administrators while standard users follow a separate policy.

  • Adaptive authentication

    Context-aware MFA challenge logic adjusts verification requirements in real time based on session type, endpoint recognition, user behavior, and risk signals, enforcing step-up authentication for high-risk sessions while reducing friction for routine access, solving MFA fatigue prevention without reducing coverage.

  • Offline MFA

    Maintain MFA enforcement when the machine cannot reach the Identity Access server, ensuring coverage continues during network interruptions, maintenance windows, and in air-gapped environments.

  • Non-domain Linux and macOS support

    Enforce consistent MFA policy on machines outside Active Directory, no domain membership required for Linux or macOS endpoints.

  • Real-time audit reports

    View detailed reports on RDP sessions, SSH logins, SCP and SFTP file transfers, and authentication failures, including login time, authentication method, user identity, and outcome.

Benefits of Identity Access' remote access and CLI MFA

  • Prevent credential-based attacks

    Stolen RDP passwords and SSH keys are no longer sufficient for unauthorized access, an attacker cannot complete authentication without the enrolled second factor, regardless of how credentials were obtained.

  • Enforce Zero Trust at the session layer

    MFA is enforced at the point of remote access itself, every RDP, SSH, SCP, and SFTP session, extending the Zero Trust boundary beyond the network perimeter to where access actually occurs.

  • Complete the remote access security chain

    VPN MFA Integration secures the network tunnel. Identity Access secures the session layer, covering RDP, SSH, and file transfers once a user is on the network.

  • Achieve regulatory compliance

    Support compliance with authentication requirements across PCI DSS 4.0 (Requirements 8.4.2 and 8.4.3), Cyber Essentials v3.3, NIST SP 800-63B-4, ISO 27001:2022, and SOC 2 Type II—and position for the proposed HIPAA Security Rule update—with every remote session logged against a verified identity.

  • Manage all platforms from one console

    Enforce consistent MFA policy across Windows RDP, Linux SSH and CLI, and macOS remote sessions, unified reporting and a single enrolment experience for end users, including non-domain machines authenticating via RADIUS Authentication Protocol.

Protect every remote and privileged session with MFA for SSH, RDP, and CLI logins using ADSelfService Plus.

Other features

MFA  

Add a second authentication factor to endpoint, application, VPN, OWA, and CLI logins. with authentication factors ranging from FIDO2 security keys to smartcards.

SSO  

Give users one-click entry to every cloud application using a single set of credentials.

Passwordless authentication  

Replace passwords with FIDO2 security keys and platform biometrics, removing the credential most often phished and replayed.

Conditional access policy  

Evaluate every access request against user, device, IP address, geolocation, time, and operating system, then allow, deny, or challenge it accordingly.

Device authentication  

Authenticate Windows, macOS, and Linux machines on cloud without Active Directory or Entra ID.

MFA for enterprise apps  

Set MFA and access rules for each application on its own terms, so that critical applications carry a stronger challenge and routine ones stay quick.

Privacy and security controls protecting access data

Our commitment
to privacy and security

  • Zoho Corporation is certified with ISO/IEC 27001 (information security management systems), ISO/IEC 27017 (security controls for cloud services), and ISO/IEC 27018 (protection of personally identifiable information) and is compliant with SOC 2 Type II (security, confidentiality, processing integrity, availability, and privacy).

  • The data of our SaaS applications users resides in our data centers, which are also compliant with SOC 1 Type II and SOC 2 Type II as well as certified with ISO/IEC 27001 (information security management systems) and ISO 22301 (business continuity management systems).

Security compliance badges including ISO and SOC certifications

Explore our access
management solution

SIGN UP