Appearance
Multi-Factor Authentication
WebWorkstationMobileMulti-factor authentication, or MFA, adds an extra verification step after a user's primary sign-in method. ZynoSuite supports organization-managed MFA through SSO and local browser security settings when the account's login policy permits them.
ZynoSuite presents these user-visible security paths:
| Method | Where It Applies |
|---|---|
| Provider MFA | Microsoft Entra or Google Workspace SSO, configured in your identity provider |
| Sign-in passkey | Browser sign-in through a PRF-capable WebAuthn authenticator, when the organization allows local passkeys |
| Authenticator code | The Two-factor Personal Security tab for eligible local browser accounts that do not use a sign-in passkey |
| Fingerprint login | ZynoWorkstation installations with a supported fingerprint reader |
| ZynoRMM hardware authenticators | ZynoRMM secure operations, where that module is enabled |
Provider MFA
If your organization uses SSO, configure MFA rules in Microsoft Entra or Google Workspace. ZynoSuite sends the user to the provider during sign-in, and the provider handles its own MFA prompts.
This is the recommended MFA path for organizations already using a central identity provider.
Fingerprint login
Fingerprint login is available only on ZynoWorkstation when the workstation has a supported fingerprint reader and the user has permission to manage fingerprints.
Fingerprint login is not the same as a general web MFA prompt. It is a Workstation sign-in method for shared or hardware-connected workstation environments.
See Fingerprint Login.
Passkeys and authenticator codes
Open the user menu, select Personal Security, and choose Passkey to manage an eligible sign-in passkey. The web login page also offers Sign in with a passkey for discoverable sign-in.
A sign-in passkey is the account's local browser sign-in method, not an additional code requested after the password. Setting one turns off browser password and authenticator-code sign-in for that account. Organizations that require SSO do not permit local browser passkey setup or sign-in.
For a local browser account without a sign-in passkey, the Two-factor tab can manage authenticator-code MFA when the organization allows it. The tab shows why it is unavailable when SSO policy, the sign-in method, or account policy excludes it.
See Passkeys.
What to tell users
For most organizations:
- Web users should follow the Microsoft Entra or Google Workspace MFA process when their organization requires SSO.
- Eligible local browser users can choose the Personal Security path their organization allows: a sign-in passkey or authenticator codes.
- Workstation users can use fingerprint login when their workstation supports it.
- ZynoRMM technician prompts protect RMM operations and are separate from account sign-in.