Skip to content

Multi-Factor Authentication ​

WebWorkstationMobile

Multi-factor authentication, or MFA, adds an extra verification step after a user's primary sign-in method. ZynoSuite supports organization-managed MFA through SSO and local browser security settings when the account's login policy permits them.

ZynoSuite presents these user-visible security paths:

MethodWhere It Applies
Provider MFAMicrosoft Entra or Google Workspace SSO, configured in your identity provider
Sign-in passkeyBrowser sign-in through a PRF-capable WebAuthn authenticator, when the organization allows local passkeys
Authenticator codeThe Two-factor Personal Security tab for eligible local browser accounts that do not use a sign-in passkey
Fingerprint loginZynoWorkstation installations with a supported fingerprint reader
ZynoRMM hardware authenticatorsZynoRMM secure operations, where that module is enabled

Provider MFA ​

If your organization uses SSO, configure MFA rules in Microsoft Entra or Google Workspace. ZynoSuite sends the user to the provider during sign-in, and the provider handles its own MFA prompts.

This is the recommended MFA path for organizations already using a central identity provider.

Fingerprint login ​

Fingerprint login is available only on ZynoWorkstation when the workstation has a supported fingerprint reader and the user has permission to manage fingerprints.

Fingerprint login is not the same as a general web MFA prompt. It is a Workstation sign-in method for shared or hardware-connected workstation environments.

See Fingerprint Login.

Passkeys and authenticator codes ​

Open the user menu, select Personal Security, and choose Passkey to manage an eligible sign-in passkey. The web login page also offers Sign in with a passkey for discoverable sign-in.

A sign-in passkey is the account's local browser sign-in method, not an additional code requested after the password. Setting one turns off browser password and authenticator-code sign-in for that account. Organizations that require SSO do not permit local browser passkey setup or sign-in.

For a local browser account without a sign-in passkey, the Two-factor tab can manage authenticator-code MFA when the organization allows it. The tab shows why it is unavailable when SSO policy, the sign-in method, or account policy excludes it.

See Passkeys.

What to tell users ​

For most organizations:

  • Web users should follow the Microsoft Entra or Google Workspace MFA process when their organization requires SSO.
  • Eligible local browser users can choose the Personal Security path their organization allows: a sign-in passkey or authenticator codes.
  • Workstation users can use fingerprint login when their workstation supports it.
  • ZynoRMM technician prompts protect RMM operations and are separate from account sign-in.

Still need help?

Can’t find what you’re looking for? Our support team is happy to help.