Multi-Factor Authentication

Doug Chanin
Doug Chanin
  • Updated

Topic

This article describes how to implement NinjaOne SaaS Backup's advanced multi-factor authentication (MFA) features.

Environment

NinjaOne SaaS Backup

Description

Multi-factor authentication (MFA) is available to enhance your account’s security with stronger login protection and is a required step when logging in.

Activate Personal MFA

MFA requires an authenticator app for activation and login. Ensure that you have downloaded a third-party authenticator app on your device. You can use any authenticator app available on the Apple App Store or Google Play Store.

If you have not yet set up MFA, you will be directed to the MFA setup page after logging in. This page walks you through the activation process and cannot be skipped or closed. Click Set Up MFA to begin

Open your third-party authenticator app. Scan the QR code or enter the setup key provided, then enter the verification code generated by your authenticator app and click Verify to activate MFA.

fig1.png
Figure 1: Setup MFA (click to enlarge)

Once activation is successful, NinjaOne SaaS Backup will redirect you to the NinjaOne SaaS Backup dashboard.

Once MFA has been activated, it cannot be deactivated.

Log in when MFA is already activated

After completing MFA activation, on your next login, NinjaOne SaaS Backup will prompt you to enter the code from your authenticator app to access the dashboard.

Reset Your MFA

You can reset MFA if you lose access to your authenticator app, for example, if your phone is lost or damaged. If you can access the Security Settings page, you can reset MFA on your own. If you are unable to access this page, you will need to ask your organization administrator to reset MFA for your account.

Reset your MFA for End User Portal Users

If you still can access the Security Settings page, you can reset your MFA using the following steps:

  1. Navigate to the Two-Factor Authentication page under your profile.
  2. Select Reset Two-Factor Authentication to start the MFA reset process.
fig2.png
Figure 2: Two-Factor Authentication (click to enlarge)
  1. A Reset Multi-Factor Authentication confirmation prompt will appear. Click Yes, Continue to proceed.
fig3.png
Figure 3: Reset Two-factor Authentication (click to enlarge)
  1. Enter your login password to verify your identity, then click Continue.
fig4.png
Figure 4: Password Required (click to enlarge)

NinjaOne SaaS Backup will send a Reset Two-Factor Authentication (2FA) email to your mailbox. Open the reset email and click the link provided to confirm the MFA reset.

Reset your MFA for Partner Portal Users

If you can access the Security Settings page, you can reset your MFA using the following steps:

  1. Navigate to the Security Settings page and select Reset Multi-Factor Authentication (MFA).
fig5.png
Figure 5: Security Settings (click to enlarge)
  1. A Reset MFA for your account prompt will appear. Enter your login password to verify your identity, then click Continue to proceed with the reset.
fig6.png
Figure 6: Reset MFA for your account (click to enlarge)
  1. NinjaOne SaaS Backup will send a reset Two-Factor Authentication (2FA) email to your mailbox. After receiving the reset email, click the link provided to confirm the reset.
fig7.png
Figure 7: Reset Two-Factor Authentication (click to enlarge)

NinjaOne SaaS Backup will redirect you to the login page and prompt you to activate MFA. You must set up your new MFA before you can access the dashboard.

Administrators Reset MFA for Partner Users

When a partner user experiences MFA access issues, administrators can reset the user's MFA. This ability is limited to those with the owner, super admin, or administrator role within the partner.

To reset a partner user's MFA, follow these steps:

  1. Log in to the NinjaOne SaaS Backup Partner Portal.
  2. From the dashboard, navigate to Settings → User Management.

The MFA Status column will display one of two possible statuses:

  • Active: User has successfully activated MFA
  • Inactive: User has not activated the MFA
fig8.png
Figure 8: User Management (click to enlarge) 
  1. For the user whose MFA you want to reset, click the actions menu at the end of the row and select Reset MFA.
  2. A confirmation pop-up will appear. Click Yes, Continue to complete the reset.
fig9.png
Figure 9: Reset Multi-factor Authentication (click to enlarge)

A reset confirmation email will be sent to the user, prompting them to set up Multi-Factor Authentication again on their next login.

The reset email is valid for 24 hours only. If the link expires, you will need to request another MFA reset.

Administrators Reset MFA for Organization Users

When an organization user experiences MFA access issues, administrators can reset the user's MFA. This ability is limited to those with the owner, super admin, or administrator role within the partner.

To reset an organization user's MFA, follow these steps:

  1. Log in to the NinjaOne SaaS Backup Partner Portal.
  2. Navigate to the Organizations page.
  3. Locate the organization where the user resides.
  4. Click the actions menu.
  5. Click View Details.
  6. Select the Login Accounts tab.
  7. Locate the user in the accounts list.
  8. For the user whose MFA you want to reset, click the actions menu at the end of the row and select Reset MFA.

Skip MFA for users with enforced SSO login via Azure or Google

Single sign-on (SSO) allows users to log in to the portal using a trusted external identity provider, such as Azure AD, without needing to remember a separate email and password. This helps simplify access while keeping authentication managed through your organization’s existing security policies.

When Enforce Azure AD SSO for Partner Accounts is activated, all partner accounts in your organization are required to log in through Azure AD SSO. Users will no longer be able to sign in using their portal email and password.

If your organization enforces SSO through Azure or Google, admins can enable the Skip MFA toggle in NinjaOne SaaS Backup. This helps prevent double MFA prompts by allowing users to complete MFA only through their SSO provider. Once activated, NinjaOne SaaS Backup MFA is skipped for all users in the organization.

This option is only available if your organization has enabled SSO login enforcement.

To skip MFA for users with enforced SSO login, follow these steps:

  1. Log in to the Partner Portal, select your account, then navigate to the Security Settings page.
  2. In the Organization-Wide SSO Enforcement section, activate Enforce Azure AD SSO for Partner Accounts.
The organization-wide SSO enforcement section is only available to Admin, Super Admin, and Owner roles.
  1. After the SSO enforcement toggle is enabled, the Skip MFA option will become available. You can activate or deactivate it based on your organization’s needs.
fig10.png
Figure 10: Organization-Wide SSO Enforcement (click to enlarge)
  1. A confirmation dialog will appear. Enter your MFA authentication code to confirm the process, then select Yes, continue to proceed.
fig11.png
Figure 11: Skip MFA for SSO User (click to enlarge)

The Skip MFA toggle has been successfully enabled. A confirmation notification will display.

fig12.png
Figure 12: Skip MFA is successfully enabled (click to enlarge)

Partner Portal Audit Log

The Audit Log in the NinjaOne SaaS Backup Partner Portal helps partners track MFA-related user activities within their organization. NinjaOne SaaS Backup will record all logins, including those where the user skips the MFA setup prompt.

To access the Audit Log page, follow these steps:

  1. Log in to the NinjaOne SaaS Backup Partner Portal.
  2. From the dashboard, navigate to Audit Logs. The Audit Log page will display all user activities within the NinjaOne SaaS Backup Partner Portal.
auditlogs.png
Figure 13: Audit Log (click to enlarge)

You can use the filter options to make it easier to track MFA-related activity. Activate the filter Activities Login & Accessibility and select all MFA activity types listed in the audit log.

Frequently-Asked Questions (FAQs)

The following information represents questions frequently asked by our partners and their answers, provided by our product teams.

What happens if I don't enable MFA?

You won’t be able to complete the login process or access your account until MFA is set up. It’s a required step to keep your information secure.

Can I deactivate my MFA after activating it?

No. Once MFA has been set up, it cannot be deactivated. MFA becomes mandatory to provide stronger protection for your account. You can still reset your MFA if needed, for example, if you switch to a new authenticator app or device.

Can I use the same MFA code if I use my email address for multiple accounts?

No. Each account will have its own authentication code, even if you use the same email address across different partners. This policy ensures that every account remains secure.

My account already has MFA enabled through Microsoft or Google Single Sign-On. Do I still need to enable MFA in NinjaOne SaaS Backup?

It depends on the settings set by your partner or organization admins. If your admin activates the ‘Skip MFA for SSO User toggle, you don't need to enable your NinjaOne SaaS Backup MFA.

When you have two MFAs enabled (one from Microsoft or Google and one from NinjaOne SaaS Backup), you will have two layers of MFA, which means you will need to complete MFA verification twice. This additional security layer provides stronger protection by reducing the risk of unauthorized access, even if one MFA layer is compromised, and helps better safeguard your account and sensitive data.

What happens if I enter the wrong MFA code multiple times?

You will not be able to log in if you continue entering an incorrect MFA code. If you need help, such as switching to a new authenticator app or device, you can ask your organization administrator to reset MFA for your account or contact our support team.

What should I do if my authenticator app is not working or my phone is lost or damaged?

If you cannot access your authenticator app, you can ask your organization administrator to reset MFA for your account. Once they have completed the reset, you will receive an MFA reset email. Click the link in the email to access the steps to set up MFA again for your account.

I did not receive the MFA reset email. What should I do?

Check your spam or junk folder to ensure the email is not there. Wait a few minutes, and if the email still hasn't arrived, contact our support team.

If I have the Support role, can I reset MFA in my organization?

No. Currently, only owners, super admins, or admins can reset and enforce MFA policies. If you require this access level, you may request a role change from your organization's administrator.

Can I use more than one third-party authenticator app?

Yes. You may install and use multiple authenticator apps on your device. However, you can only link an account to one authenticator app at a time. You can use different authenticator apps for other accounts as needed.

Can I use any third-party authenticator app?

Yes. You can use any authenticator app available on the Apple App Store or Google Play Store on your phone.

Related to

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request