Setup Zoho OneAuth Authenticator as 2FA/MFA for Drupal
Overview
Two Factor Authentication - TFA adds a layer of security on top of basic Drupal authentication. This increase site's security from unwanted hacks and unauthorized login attempts. By following this document you can configure Zoho OneAuth Authenticator as a Two Factor Authentication - MFA method for Drupal account. The Drupal Two Factor Authentication - 2FA / Passwordless Login is available for Drupal 7, Drupal 8, Drupal 9 and Drupal 10, and Drupal 11.
Installation Steps
- Using Composer
- Using Drush
- Manual Installation
Configuration Steps
Configure Zoho OneAuth Authenticator as a 2FA method:
- After installing the module, click on the Configuration tab in the admin dashboard of Drupal site and click on miniOrange Second Factor Authentication under People section. (/admin/config/people/miniorange_2fa)
- Register/Login with your miniOrange account.
- Click on the Setup Two-Factor tab and scroll down to the TOTP based 2FA methods section.
- Click on the Configure button next to Zoho OneAuth.
- Open the Zoho OneAuth app in your mobile and scan the displayed QR code.
- Now, enter the code generated in your Zoho OneAuth app in textfield labeled Passcode and click on the Verify button.
You have successfully configured Zoho OneAuth as a 2FA method.
Verify 2FA:
- Open a new browser/private window and navigate to the login page of the Drupal site.
- Try Login with the Drupal credentials.
- You will be asked to authenticate using the Zoho OneAuth Authenticator passcode.
- Enter the code generated in your Zoho OneAuth Authenticator app and click on the Verify button.
- If the authentication is successful you will be logged in to the Drupal site.
Additional Features:
Explore the advanced features offered by the module with full-featured trial. You can initiate the trial request using Request 7-day trial button under Register/Login tab of the module or reach out to us at drupalsupport@xecurify.com for one-on-one assistance from Drupal expert.
- Passwordless Login
- Role Based 2FA (Enable 2FA for specific roles)
- Domain Based 2FA
- Remember My Device