Is it possible to configure multi-factor authentication to access Plesk?

Follow

Comments

9 comments

  • Avatar
    Dennis Am

    Could you please update this article, mentioning that multi-factor authentication only applies to the web interface, and not to the REST API + Plesk Mobile App? Thanks in advance :)

    0
    Comment actions Permalink
  • Avatar
    Denis Bykov

    @Dennis Am

    Thank you for noticing! The article was updated.

    1
    Comment actions Permalink
  • Avatar
    Ehud Ziegelman

    MFA is not supported on mobile, ability to add this we consider as a feature request. But since MFA is not supported we do confirm as a bug the fact that MFA screen shown at all, it should be disabled. Request ID to hide it is PMBL-562. 

    Mobile application uses XML-RPC API requests to communicate with Plesk server. If you want to enhance security you may either disable API at all or limit it to specific IP addresses. To do so, add the following entries to the panel.ini file.

    • To prohibit all connections via XML API:

      [api]
      enabled = off

    • To allow connections via XML API only from specific IP addresses:

      [api]

      allowedIPs = 203.0.113.2,192.0.2.2

    0
    Comment actions Permalink
  • Avatar
    Shawn Carron

    How do we enable this just for the Admin account on plesk and not for customer access?

    0
    Comment actions Permalink
  • Avatar
    Chris Mayer

    With the Plesk Web Admin version it works for the admin but for other users if they login normally and than push the button Google Authenticator they get an Error: Error: Permission denied.

    So how to enable 2FA on a Web Admin edition not only to the admin user?

    0
    Comment actions Permalink
  • Avatar
    Yaroslav Tarasov

    Hello Shawn Carron, 

    When Google Authenticator is used MFA will be enabled both for Plesk Admin and the customers' accounts. This is how the extension was developed.

    I've added a note to the article to avoid any confusion in the future.

    0
    Comment actions Permalink
  • Avatar
    Yaroslav Tarasov

    Hello @Chris Mayer,

    On Web Admin, there are no customers, only Plesk Admin. By the other users, I suppose you mean the additional users in the left sidebar. Google Authenticator is not supposed to work with such users - they can still log in to Plesk as usual. These users have limited rights, so there is nothing to worry about.

    0
    Comment actions Permalink
  • Avatar
    JP Andino

    I enabled Google Authenticator on Plesk Web Pro Edition, there are Customers and only the Plesk Admin have Google Authenticator feature available. 

    0
    Comment actions Permalink
  • Avatar
    JP Andino

    To enable it on the Customers, login as a Customer, on the Search bar, type Google Authenticator.

     

    0
    Comment actions Permalink

Please sign in to leave a comment.

Have more questions? Submit a request