For the complete documentation index, see llms.txt. This page is also available as Markdown.

Configure MFA for PAM checkout in Devolutions Cloud

Administrators can enforce multifactor authentication for all users on Devolutions Cloud, or require it specifically when a privileged entry is checked out.

Before you begin, users must have MFA enabled in the Devolutions Portal, under Sign-in & security, for MFA to be enforced on checkout. To enforce multifactor verification for all users on Devolutions Cloud, go to AdministrationAccess & authenticationGeneralEnforce multifactor verification on Devolutions Account.

MFA on PAM checkout

MFA can be required on privileged accounts through a checkout policy. The MFA on checkout setting can be set to Default, None, Mandatory, or Mandatory on JIT elevation only.

  1. Go to AdministrationPrivileged access management (PAM)Checkout policies.

  2. Select an existing checkout policy to edit, or create a new one.

  3. Set MFA on checkout to Default, None, Mandatory, or Mandatory on JIT elevation only, depending on when MFA should be enforced.

  4. To apply this policy automatically to every entry and folder, enable Is default. Otherwise, apply it to specific entries or folders by editing them, then going to PropertiesCheckout policies.

  5. Select Update to save. The requirement applies the next time the entry is checked out.

See also

Last updated

Was this helpful?