Skip to content

Multi-Factor Authentication

WebWorkstationMobile

Multi-factor authentication, or MFA, adds an extra verification step after a user's primary sign-in method. ZynoSuite supports organization-managed MFA through SSO and local browser security settings when the account's login policy permits them.

ZynoSuite presents these user-visible security paths:

MethodWhere It Applies
Provider MFAMicrosoft Entra or Google Workspace SSO, configured in your identity provider
Sign-in passkeyBrowser sign-in through a PRF-capable WebAuthn authenticator, when the organization allows local passkeys
Authenticator codeThe Two-factor Personal Security tab for eligible local browser accounts that do not use a sign-in passkey
Fingerprint loginZynoWorkstation installations with a supported fingerprint reader
ZynoRMM hardware authenticatorsZynoRMM secure operations, where that module is enabled

Provider MFA

If your organization uses SSO, configure MFA rules in Microsoft Entra or Google Workspace. ZynoSuite sends the user to the provider during sign-in, and the provider handles its own MFA prompts.

This is the recommended MFA path for organizations already using a central identity provider.

Fingerprint login

Fingerprint login is available only on ZynoWorkstation when the workstation has a supported fingerprint reader and the user has permission to manage fingerprints.

Fingerprint login is not the same as a general web MFA prompt. It is a Workstation sign-in method for shared or hardware-connected workstation environments.

See Fingerprint Login.

Passkeys and authenticator codes

Open the user menu, select Personal Security, and choose Passkey to manage an eligible sign-in passkey. The web login page also offers Sign in with a passkey for discoverable sign-in.

A sign-in passkey is the account's local browser sign-in method, not an additional code requested after the password. Setting one turns off browser password and authenticator-code sign-in for that account. Organizations that require SSO do not permit local browser passkey setup or sign-in.

For a local browser account without a sign-in passkey, the Two-factor tab can manage authenticator-code MFA when the organization allows it. The tab shows why it is unavailable when SSO policy, the sign-in method, or account policy excludes it.

See Passkeys.

What to tell users

For most organizations:

  • Web users should follow the Microsoft Entra or Google Workspace MFA process when their organization requires SSO.
  • Eligible local browser users can choose the Personal Security path their organization allows: a sign-in passkey or authenticator codes.
  • Workstation users can use fingerprint login when their workstation supports it.
  • ZynoRMM technician prompts protect RMM operations and are separate from account sign-in.

Still need help?

Can’t find what you’re looking for? Our support team is happy to help.