Topic
This article describes how to implement NinjaOne SaaS Backup's advanced multi-factor authentication (MFA) features.
Environment
NinjaOne SaaS Backup
Description
Multi-factor authentication (MFA) is available to enhance your account’s security with stronger login protection and is a required step when logging in.
Activate Personal MFA
MFA requires an authenticator app for activation and login. Ensure that you have downloaded a third-party authenticator app on your device. You can use any authenticator app available on the Apple App Store or Google Play Store.
If you have not yet set up MFA, you will be directed to the MFA setup page after logging in. This page walks you through the activation process and cannot be skipped or closed. Click Set Up MFA to begin
Open your third-party authenticator app. Scan the QR code or enter the setup key provided, then enter the verification code generated by your authenticator app and click Verify to activate MFA.
Once activation is successful, NinjaOne SaaS Backup will redirect you to the NinjaOne SaaS Backup dashboard.
Log in when MFA is already activated
After completing MFA activation, on your next login, NinjaOne SaaS Backup will prompt you to enter the code from your authenticator app to access the dashboard.
Reset Your MFA
You can reset MFA if you lose access to your authenticator app, for example, if your phone is lost or damaged. If you can access the Security Settings page, you can reset MFA on your own. If you are unable to access this page, you will need to ask your organization administrator to reset MFA for your account.
Reset your MFA for End User Portal Users
If you still can access the Security Settings page, you can reset your MFA using the following steps:
- Navigate to the Two-Factor Authentication page under your profile.
- Select Reset Two-Factor Authentication to start the MFA reset process.
- A Reset Multi-Factor Authentication confirmation prompt will appear. Click Yes, Continue to proceed.
- Enter your login password to verify your identity, then click Continue.
NinjaOne SaaS Backup will send a Reset Two-Factor Authentication (2FA) email to your mailbox. Open the reset email and click the link provided to confirm the MFA reset.
Reset your MFA for Partner Portal Users
If you can access the Security Settings page, you can reset your MFA using the following steps:
- Navigate to the Security Settings page and select Reset Multi-Factor Authentication (MFA).
- A Reset MFA for your account prompt will appear. Enter your login password to verify your identity, then click Continue to proceed with the reset.
- NinjaOne SaaS Backup will send a reset Two-Factor Authentication (2FA) email to your mailbox. After receiving the reset email, click the link provided to confirm the reset.
NinjaOne SaaS Backup will redirect you to the login page and prompt you to activate MFA. You must set up your new MFA before you can access the dashboard.
Administrators Reset MFA for Partner Users
When a partner user experiences MFA access issues, administrators can reset the user's MFA. This ability is limited to those with the owner, super admin, or administrator role within the partner.
To reset a partner user's MFA, follow these steps:
- Log in to the NinjaOne SaaS Backup Partner Portal.
- From the dashboard, navigate to Settings → User Management.
The MFA Status column will display one of two possible statuses:
- Active: User has successfully activated MFA
- Inactive: User has not activated the MFA
- For the user whose MFA you want to reset, click the actions menu at the end of the row and select Reset MFA.
- A confirmation pop-up will appear. Click Yes, Continue to complete the reset.
A reset confirmation email will be sent to the user, prompting them to set up Multi-Factor Authentication again on their next login.
Administrators Reset MFA for Organization Users
When an organization user experiences MFA access issues, administrators can reset the user's MFA. This ability is limited to those with the owner, super admin, or administrator role within the partner.
To reset an organization user's MFA, follow these steps:
- Log in to the NinjaOne SaaS Backup Partner Portal.
- Navigate to the Organizations page.
- Locate the organization where the user resides.
- Click the actions menu.
- Click View Details.
- Select the Login Accounts tab.
- Locate the user in the accounts list.
- For the user whose MFA you want to reset, click the actions menu at the end of the row and select Reset MFA.
Skip MFA for users with enforced SSO login via Azure or Google
Single sign-on (SSO) allows users to log in to the portal using a trusted external identity provider, such as Azure AD, without needing to remember a separate email and password. This helps simplify access while keeping authentication managed through your organization’s existing security policies.
When Enforce Azure AD SSO for Partner Accounts is activated, all partner accounts in your organization are required to log in through Azure AD SSO. Users will no longer be able to sign in using their portal email and password.
If your organization enforces SSO through Azure or Google, admins can enable the Skip MFA toggle in NinjaOne SaaS Backup. This helps prevent double MFA prompts by allowing users to complete MFA only through their SSO provider. Once activated, NinjaOne SaaS Backup MFA is skipped for all users in the organization.
To skip MFA for users with enforced SSO login, follow these steps:
- Log in to the Partner Portal, select your account, then navigate to the Security Settings page.
- In the Organization-Wide SSO Enforcement section, activate Enforce Azure AD SSO for Partner Accounts.
- After the SSO enforcement toggle is enabled, the Skip MFA option will become available. You can activate or deactivate it based on your organization’s needs.
- A confirmation dialog will appear. Enter your MFA authentication code to confirm the process, then select Yes, continue to proceed.
The Skip MFA toggle has been successfully enabled. A confirmation notification will display.
Partner Portal Audit Log
The Audit Log in the NinjaOne SaaS Backup Partner Portal helps partners track MFA-related user activities within their organization. NinjaOne SaaS Backup will record all logins, including those where the user skips the MFA setup prompt.
To access the Audit Log page, follow these steps:
- Log in to the NinjaOne SaaS Backup Partner Portal.
- From the dashboard, navigate to Audit Logs. The Audit Log page will display all user activities within the NinjaOne SaaS Backup Partner Portal.
You can use the filter options to make it easier to track MFA-related activity. Activate the filter Activities → Login & Accessibility and select all MFA activity types listed in the audit log.
Frequently-Asked Questions (FAQs)
The following information represents questions frequently asked by our partners and their answers, provided by our product teams.
What happens if I don't enable MFA?
You won’t be able to complete the login process or access your account until MFA is set up. It’s a required step to keep your information secure.
Can I deactivate my MFA after activating it?
No. Once MFA has been set up, it cannot be deactivated. MFA becomes mandatory to provide stronger protection for your account. You can still reset your MFA if needed, for example, if you switch to a new authenticator app or device.
Can I use the same MFA code if I use my email address for multiple accounts?
No. Each account will have its own authentication code, even if you use the same email address across different partners. This policy ensures that every account remains secure.
My account already has MFA enabled through Microsoft or Google Single Sign-On. Do I still need to enable MFA in NinjaOne SaaS Backup?
It depends on the settings set by your partner or organization admins. If your admin activates the ‘Skip MFA for SSO User toggle, you don't need to enable your NinjaOne SaaS Backup MFA.
When you have two MFAs enabled (one from Microsoft or Google and one from NinjaOne SaaS Backup), you will have two layers of MFA, which means you will need to complete MFA verification twice. This additional security layer provides stronger protection by reducing the risk of unauthorized access, even if one MFA layer is compromised, and helps better safeguard your account and sensitive data.
What happens if I enter the wrong MFA code multiple times?
You will not be able to log in if you continue entering an incorrect MFA code. If you need help, such as switching to a new authenticator app or device, you can ask your organization administrator to reset MFA for your account or contact our support team.
What should I do if my authenticator app is not working or my phone is lost or damaged?
If you cannot access your authenticator app, you can ask your organization administrator to reset MFA for your account. Once they have completed the reset, you will receive an MFA reset email. Click the link in the email to access the steps to set up MFA again for your account.
I did not receive the MFA reset email. What should I do?
Check your spam or junk folder to ensure the email is not there. Wait a few minutes, and if the email still hasn't arrived, contact our support team.
If I have the Support role, can I reset MFA in my organization?
No. Currently, only owners, super admins, or admins can reset and enforce MFA policies. If you require this access level, you may request a role change from your organization's administrator.
Can I use more than one third-party authenticator app?
Yes. You may install and use multiple authenticator apps on your device. However, you can only link an account to one authenticator app at a time. You can use different authenticator apps for other accounts as needed.
Can I use any third-party authenticator app?
Yes. You can use any authenticator app available on the Apple App Store or Google Play Store on your phone.
Related to