Configure MFA for PAM checkout in Devolutions Cloud
Administrators can enforce multifactor authentication for all users on Devolutions Cloud, or require it specifically when a privileged entry is checked out.
Before you begin, users must have MFA enabled in the Devolutions Portal, under Sign-in & security, for MFA to be enforced on checkout. To enforce multifactor verification for all users on Devolutions Cloud, go to Administration – Access & authentication – General – Enforce multifactor verification on Devolutions Account.
MFA on PAM checkout
MFA can be required on privileged accounts through a checkout policy. The MFA on checkout setting can be set to Default, None, Mandatory, or Mandatory on JIT elevation only.
MFA enforced at login through an external identity provider (Entra ID, PingOne, Okta, etc.) does not automatically satisfy the MFA on checkout requirement. These are two separate verifications.
Even if MFA is already enforced at login, the user still needs an MFA method configured for MFA on checkout to work. This method does not need to be enforced at login, only available for use at checkout.
Go to Administration – Privileged access management (PAM) – Checkout policies.
Select an existing checkout policy to edit, or create a new one.
Set MFA on checkout to Default, None, Mandatory, or Mandatory on JIT elevation only, depending on when MFA should be enforced.
To apply this policy automatically to every entry and folder, enable Is default. Otherwise, apply it to specific entries or folders by editing them, then going to Properties – Checkout policies.
Select Update to save. The requirement applies the next time the entry is checked out.
See also
Last updated
Was this helpful?