Search Results :

×

Security should change based on the actual risk of a login, rather than applying the same strict rules to everyone. Context-aware authentication does this by checking the details of each login attempt in real time and adjusting the security requirements automatically.

The miniOrange MFA plugin for Joomla handles this by checking the user's network. If an employee logs in from a trusted office network, they get in quickly. However, if a login comes from an unknown or risky location, the plugin immediately asks for extra authentication to keep the site secure.

To set up context-aware adaptive authentication for remote workers, this use case uses the following miniOrange plugin. You will need to install it on your Joomla instance:

usecase card logo

Multi-Factor Authentication (MFA) Plugin

Download Extension

A financial company using a Joomla portal needed better security for employees working from different locations. In the office, staff used secure computers on a private network. In this safe environment, asking for a second login step every time was frustrating and slowed down their work.

However, the risk increased when employees worked from home or used public Wi-Fi. In these places, the company couldn't control the network or who might be using the device. Without extra security, it was hard to prove that the person logging in was actually the employee and not a hacker.

The company's old security rules couldn't tell the difference between these two situations. Turning on extra security for everyone annoyed office workers, but leaving it off made remote access dangerous. They needed a system that could check where a user was and only ask for extra proof when the risk was higher.

Using the Adaptive Authentication feature of the miniOrange MFA plugin, the company set up a location-aware rule (IP-aware policy). This rule only asks for a second security step based on where the login comes from, without changing the experience for employees working from the office.


Step 1: Install and start the miniOrange Multi-Factor Authentication plugin on Joomla.


Step 2: Go to the Adaptive Authentication section in the plugin's admin panel and turn on IP-Based Access Control.


Step 3: Enter the company's office network IP addresses into the Trusted IP Whitelist. Any login from these addresses is seen as low-risk and will skip the second security step automatically.


Step 4: For all other IP addresses (remote or unknown), set the policy to Mandatory MFA (required second security step). This ensures every login from an external network triggers the second security challenge.


Step 5: Choose the approved second-factor methods for remote login. The company enabled Google Authenticator (TOTP) as the main method and SMS OTP as a backup.


Step 6: Optionally, turn on Device Recognition to improve the rule. This checks if the login is coming from a device that was previously trusted, adding an extra layer of context beyond just the IP address.


Step 7: Set the MFA Session Persistence (how long the session lasts) to decide how long a verified remote session remains trusted on a device before the user must verify their identity again. This balances security with ease of use.


Step 8: Test the setup by trying to log in from both the trusted corporate IP and an external IP address. Confirm that the office login goes through without problems and the remote login correctly asks for the extra security step.

By implementing Adaptive Authentication, the company successfully transitioned to an intelligent security model that prioritises the actual context of a login attempt over rigid, universal policies. Staff working within the office continue to access the Joomla portal with ease, maintaining their productivity without unnecessary friction.

Meanwhile, those logging in from remote locations are prompted for a mandatory second-factor challenge, effectively preventing attackers from using compromised credentials to gain unauthorised external access. For a financial organisation managing critical data, this approach significantly lowers the risk associated with remote working while preserving a seamless experience for those on the trusted office network.

  1. Multi-Factor Authentication (MFA) Plugin for Joomla
  2. Check out our documentation

We'll Reach Out to You at the Earliest

mo-form

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

Table of Contents

Hello there!

Need Help? We are right here!

support